Security · Release integrity

Code signing policy

VibeZ 2.0 uses a platform-specific release policy. Every official package is built by GitHub Actions from the public repository and accompanied by SHA-256 checksums.

Windows

The Windows x64 NSIS installer downloaded directly from GitHub is unsigned and can trigger Microsoft SmartScreen. Users should download it only from the official repository and verify its SHA-256 checksum.

The recommended trusted route is VibeZ Desktop in the Microsoft Store. The separate MSIX uses the Partner Center identity and is validated and signed by Microsoft.

macOS

VibeZ 2.0 macOS production builds use an Apple Developer ID Application certificate, Hardened Runtime and Apple notarization. The release workflow verifies the signature, Gatekeeper acceptance and stapled notarization before publication.

Project roles

Privacy

See the VibeZ Privacy Policy. VibeZ connects to the Mistral Vibe service at the user's request and to GitHub for release/update checks. VibeZ does not independently sell user data or operate an advertising network.

Release integrity

Official releases are built with GitHub Actions from the public repository. Release downloads include SHA-256 checksums. macOS artifacts are published only after signing and notarization checks succeed. An unsigned Windows artifact is never presented as signed.