Last updated: August 12, 2026. Rudder is applying to the SignPath Foundation program for Windows Desktop release artifacts. Until the application is accepted and the release pipeline is configured, released binaries are not represented as SignPath-signed. Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Scope

  • Source repository: Undertone0809/rudder
  • License: Apache-2.0 at the project level, with third-party notices and component licenses recorded in the repository
  • Build system: GitHub Actions
  • Signing scope: Windows Desktop artifacts built by the repository’s automated release workflow from reviewed source and build scripts
  • Upstream binaries are not signed as if they were Rudder-owned source
Every signing request requires manual approval. The project does not use the certificate to sign unrelated software, local development builds, or artifacts that cannot be traced to the public source repository and release workflow.

Team roles

Project members with source or signing access must use multi-factor authentication. Changes from contributors without direct commit access are reviewed before merge. Release and signing changes receive the review required by repository ownership rules.

User privacy and security

Rudder’s privacy policy describes local workspace data, optional account and analytics data, and third-party runtime boundaries. Rudder does not intentionally include malware, unwanted software, or features whose purpose is to identify or exploit security vulnerabilities or circumvent the security controls of the execution environment. Installation and uninstallation instructions are published with the download path. Security or signing concerns can be reported privately to zeeland4work@gmail.com.