I use PGP. Very nearly all emails I send are digitally signed. Many Git and Mercurial commits and tags I produce are digitally signed.

In 2015, I started doing triennial key rotations. (Someday, I’ll write up the process here.)