The Windows builds on this site are signed, so Windows can name the publisher instead of warning about an unknown one. This page says who is behind that signature and what has to happen before one is applied.
Last updated September 21, 2026
Who is trusted with what
Ventic is a small project and says so plainly: the roles below are held by one person. What keeps that honest is that none of it happens privately - the source is public, the build is a public workflow run, and the signature records which commit it came from.
Committers and reviewers
Tilen Pirih. Ventic is a one-maintainer project: every commit on the release branch is written or reviewed by that account, and no one else can push to it. Outside contributions arrive as pull requests and are reviewed before they are merged.
Approvers
Tilen Pirih. Every signing request has to be approved by hand in SignPath before a certificate is applied to anything, and an unapproved build is never signed.
Account security
Multi-factor authentication is required on both accounts that matter here - GitHub, which holds the source, and SignPath, which holds the approval.
The private key is not in this project and never has been. It lives on SignPath's hardware security module, and nothing here can sign anything on its own - a build can only ask, and the answer is a person's.
1
A release starts as a tag pushed to the public repository. Nothing else triggers one.
2
GitHub Actions builds the installers on GitHub-hosted runners, from that commit, with no step that runs on anyone's own machine.
3
SignPath fetches the built installers from GitHub itself rather than being handed them, so it can verify which workflow run and which commit produced them. A file built anywhere else is refused.
4
The signing request waits for a human approval. Only then is the certificate applied.
5
The signed installers replace the unsigned ones on the release, and are re-signed for the in-app updater so an update still verifies.
The Linux, macOS and Android builds are signed by their own platforms' mechanisms and are not covered by this certificate. Anything you install from a package manager - apt, dnf, the AUR - is signed by whoever maintains that package.
What the signature does and does not tell you
It says the installer you downloaded is the one this project built, and that nobody changed it on the way to you. It is not a review of what the program does - for that, the source is public and this site's privacy policy lists every request the app makes.
Ventic contains no third-party installer, bundled toolbar or advertising component. It plays video with mpv on the desktop, which is bundled on Windows and carries its own licence.
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
The SignPath Foundation issues certificates to open source projects that meet its conditions, which is why an independent project can ship a signed installer at all. Ventic pays nothing for it and neither do you.