SIGF appCode signing policy
Code signing policy
Code signing through SignPath Foundation is not live yet. Until it is, releases are not signed: verify a download with its SHA-256 and build attestation (see the download page). This is the policy we follow once signing is live.
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
What we sign
- We sign only files built from the source code in SIGFAI/sigf-app: the SIGF app (
sigf-app.exe) and its Windows installer (SIGF_<version>_x64-setup.exe). - Every signed file is built by the release workflow in
.github/workflows/release.yml, on GitHub-hosted runners, from a tagged commit. Nothing built on a personal computer is ever signed. - Every release needs a manual approval in SignPath by one of the approvers below before it is signed.
- We do not sign third-party software. Mods and game files that the app downloads at run time are not signed by us and are not part of the signed installer.
Team roles
- Reviewers
- pejisdev. Every change from anyone else (pull requests from contributors) is reviewed before it is merged.
- Approvers
- pejisdev. An approver checks each release (tag, changes since the last release, build run) and approves its signing request in SignPath.
All committers, reviewers and approvers use multi-factor authentication on GitHub and on SignPath.
Privacy policy
The app collects no telemetry, analytics or crash reports and has no account. It sends information to other networked systems only for the features you use: sigf.ai (catalog, lobbies, live streams), GitHub and Modrinth's CDN (mashup downloads), Steam, Epic Games and Modrinth image servers (pictures, and the Steam store search for a game with no picture) and, on a PC without the WebView2 runtime, Microsoft (the installer downloads it). The installer shows the privacy text and asks whether to allow the requests you can turn off; the app asks again on its first start, and you can change your choices any time under Privacy in the app. The full list is on the privacy page.
System changes and uninstall
The app installs per user and never asks for administrator rights. It registers the sigf:// link type for your user account. It changes game files only when you install a mashup, after saving a copy of each original, and Restore vanilla puts the originals back.
To uninstall: first use Restore vanilla on each installed mashup, then remove SIGF from Settings > Apps > Installed apps (or run the uninstaller in its install folder, %LOCALAPPDATA%\Programs\SIGF by default). The uninstaller warns you if mashups are still installed. Uninstalling removes the app and keeps %LOCALAPPDATA%\SIGF, which holds the download cache, your privacy choices and the saved copies of original files, even when you tick "Delete the application data" (that removes only the app's window profile); you can delete it yourself once nothing is installed.