Code signing policy
Visual Dynamics is open source under the MIT License. Its installers are built from the public repository by GitHub Actions and signed so that your operating system can confirm where they came from.
Windows
The Windows installer is unsigned for now, and Windows SmartScreen
warns before running it. Check the file against the
SHA256SUMS attached to its release before you run it.
The SignPath Foundation signs open source projects at no cost, and Visual Dynamics applied in September 2026. The Foundation asks for public visibility first (users, contributors, references elsewhere), and a project a few weeks old did not have it yet; the license and the code were not the question. The project will apply again once it does. Until a certificate exists, the installer stays unsigned rather than signed under a name that is not the author's.
Only release builds are signed: the installer the release workflow builds from a version tag in the public repository, and the application inside it. Nothing built on a personal machine is submitted for signing.
macOS
The macOS disk images are signed with the author's Apple Developer ID and notarized by Apple.
Team roles
- Committers and reviewers: Brandon Zwink (@bzwink). Changes from anyone else arrive as pull requests and are reviewed before they are merged.
- Approvers: Brandon Zwink. Every signing request is approved by hand.
Everyone with these roles uses multi-factor authentication on GitHub and on any signing service the project uses.
Privacy policy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it.
The one request it can make is File → Check for Updates…, and only when you choose it from the menu. The full privacy policy says what that request carries.