Free code signing provided by SignPath.io, certificate by SignPath Foundation.
What is signed
- The Windows installer of Flowviant Machines,
Flowviant-Machines-<version>-setup.exe. - The app it installs,
flowviant-desktop.exe.
Windows names the publisher of both as SignPath Foundation. Nothing else carries this
certificate. The uninstaller the installer writes (uninstall.exe) is not signed.
The installer also carries the Flowviant daemon's Linux build, which it copies into WSL. That file is not a Windows program and is not signed with this certificate; it comes from the daemon's own public release, and the build checks its origin and its SHA-256 before bundling it.
Where it comes from
The app, its installer and the daemon are open source under the MIT license, built from public repositories:
- Flowviant/desktop — the Windows app and its installer.
- Flowviant/cli — the daemon the installer carries.
A release is built only by the repository's GitHub Actions workflow
(.github/workflows/release.yml), on GitHub-hosted runners, from a version tag.
The workflow sends each program to SignPath, which checks that it came from that workflow
run of that repository before anything is signed, and an approver approves each signing
request. Nothing built on a personal computer is signed. Every signed installer is attached
to a GitHub Release beside its SHA-256.
Team
| Role | Who |
|---|---|
| Committers (authors) | William |
| Reviewers | William |
| Approvers | William |
Committers change the source without another review. A change from anyone else is reviewed by a reviewer before it is merged. Approvers approve each signing request. Everyone on the team signs in to GitHub and to SignPath with multi-factor authentication.
Privacy
The Windows app transfers information to other computers only when you ask it to, with one
exception: it checks for updates. A minute after it starts, then hourly, and when you open its
window or tray card if it hasn't checked in the last ten minutes, it downloads
https://api.flowviant.com/dl/desktop/latest.json. That request carries nothing
about you or your projects, only what any web request carries (your IP address, and the
updater's name and version). A newer installer is downloaded in the background and installed
only when nothing is running on this computer (no agent turn, Terminal turn, ship or deploy),
or when you press Restart now.
Everything else starts with a press of yours:
- Connect a project opens app.flowviant.com in your browser. From then on, the Flowviant daemon the app runs for that project talks to api.flowviant.com under that project's credential. What the service keeps is in the Privacy Policy.
- The setup checklist runs Windows' own
wsl --install, which downloads WSL from Microsoft; runs Anthropic's installer for Claude Code (claude.ai/install.sh) inside WSL; and opens Anthropic's sign-in page. - The coding CLI you sign in to inside WSL runs under its maker's terms: Anthropic for Claude Code, OpenAI for Codex, Google for Antigravity. WSL is under Microsoft's.
What the installer changes
- It installs for the current Windows user, without administrator rights, and registers an uninstaller in Settings › Apps.
- It starts when you sign in to Windows only if you turn on Start Flowviant when I sign in to Windows, a switch in its window and the same item in its tray menu. That adds the app to your Windows startup apps, and turning it off removes it. It is off on a new install. Versions 0.0.15 and earlier turned it on the first time they ran; an install updated from one of them keeps it on until you turn it off.
- When you connect a project, it puts the daemon at
~/.flowviant/bin/flowviantin that WSL distro and keeps the project's login in~/.flowviant.
Uninstalling
Settings › Apps removes the app, stops its daemons in WSL and removes their binaries. It keeps
project logins in ~/.flowviant for a later install; flowviant uninstall
--purge inside WSL removes those too.
Reporting a problem
If you believe a program signed under this policy does something it should not, email security@flowviant.com. We answer, investigate, and tell SignPath Foundation.