Code signing policy

September 17, 2026 ยท View on GitHub

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

What is signed

  • Windows MSIX from GitHub releases and Zenodo: Authenticode-signed through SignPath.io with a certificate issued to SignPath Foundation, from v1.5.0 on. Earlier builds are unsigned.
  • Microsoft Store: packages are signed by Microsoft as part of Store publishing.
  • Flathub: Flatpak packages carry no Authenticode signature; integrity is handled by Flathub's build and distribution infrastructure.

Signing runs in the release workflow (.github/workflows/release.yml) on a tagged commit. Every signing request is approved manually by an approver before the certificate is applied.

How to check a downloaded release against the published checksums and this signature: Verifying a release.

Roles

Privacy

aTrain processes recordings and transcripts locally and does not upload them. The application transfers data to other systems only in these cases:

  • Machine-learning models that are not included in your installation package are downloaded from Hugging Face when a model is first used, or when you download one on the Models page. Hugging Face's privacy policy applies to those requests.
  • Installations from the Microsoft Store are subject to Microsoft's Store telemetry, see the Microsoft privacy statement.

aTrain itself sends no usage data or telemetry. The full privacy policy (German) is published by the University of Graz: https://business-analytics.uni-graz.at/en/research/atrain/privacy-policy/