Flowviant Sign in Start free
← Back to home

Code signing policy

Which Flowviant programs are signed, by whom, and from what source.

Last updated September 29, 2026

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

What is signed

  • The Windows installer of Flowviant Machines, Flowviant-Machines-<version>-setup.exe.
  • The app it installs, flowviant-desktop.exe.

Windows names the publisher of both as SignPath Foundation. Nothing else carries this certificate. The uninstaller the installer writes (uninstall.exe) is not signed.

The installer also carries the Flowviant daemon's Linux build, which it copies into WSL. That file is not a Windows program and is not signed with this certificate; it comes from the daemon's own public release, and the build checks its origin and its SHA-256 before bundling it.

Where it comes from

The app, its installer and the daemon are open source under the MIT license, built from public repositories:

A release is built only by the repository's GitHub Actions workflow (.github/workflows/release.yml), on GitHub-hosted runners, from a version tag. The workflow sends each program to SignPath, which checks that it came from that workflow run of that repository before anything is signed, and an approver approves each signing request. Nothing built on a personal computer is signed. Every signed installer is attached to a GitHub Release beside its SHA-256.

Team

RoleWho
Committers (authors)William
ReviewersWilliam
ApproversWilliam

Committers change the source without another review. A change from anyone else is reviewed by a reviewer before it is merged. Approvers approve each signing request. Everyone on the team signs in to GitHub and to SignPath with multi-factor authentication.

Privacy

The Windows app transfers information to other computers only when you ask it to, with one exception: it checks for updates. A minute after it starts, then hourly, and when you open its window or tray card if it hasn't checked in the last ten minutes, it downloads https://api.flowviant.com/dl/desktop/latest.json. That request carries nothing about you or your projects, only what any web request carries (your IP address, and the updater's name and version). A newer installer is downloaded in the background and installed only when nothing is running on this computer (no agent turn, Terminal turn, ship or deploy), or when you press Restart now.

Everything else starts with a press of yours:

What the installer changes

  • It installs for the current Windows user, without administrator rights, and registers an uninstaller in Settings › Apps.
  • It starts when you sign in to Windows only if you turn on Start Flowviant when I sign in to Windows, a switch in its window and the same item in its tray menu. That adds the app to your Windows startup apps, and turning it off removes it. It is off on a new install. Versions 0.0.15 and earlier turned it on the first time they ran; an install updated from one of them keeps it on until you turn it off.
  • When you connect a project, it puts the daemon at ~/.flowviant/bin/flowviant in that WSL distro and keeps the project's login in ~/.flowviant.

Uninstalling

Settings › Apps removes the app, stops its daemons in WSL and removes their binaries. It keeps project logins in ~/.flowviant for a later install; flowviant uninstall --purge inside WSL removes those too.

Reporting a problem

If you believe a program signed under this policy does something it should not, email security@flowviant.com. We answer, investigate, and tell SignPath Foundation.