Personal Jarvis
PluginsSkillsCLIsAgentsWhat changesStarsBuilt in publicOpen sourceDocs
Download

Code signing policy

Last updated 2 October 2026

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Status: the project has applied to the SignPath Foundation. Until the application is approved, the Windows installer is published unsigned, and Windows SmartScreen may warn before it runs.

What is signed

Only files built from this project's own source code by its public release workflow on GitHub Actions: the Windows installerPersonalJarvis-Setup-x64.exe and the program files it installs. They are built from thePersonalJarvis/PersonalJarvis repository at the tag of each release and published on the release page. Nothing built elsewhere, and nothing from another project, is signed with this certificate. Third-party open source libraries bundled in the installer keep their own signatures, or none.

macOS

Status: the macOS disk images are notsigned with an Apple Developer ID and are not notarized by Apple, because the project does not hold an Apple Developer membership yet. Apple’s signing programme is separate from the SignPath certificate above and cannot be covered by it.

The practical consequence is that macOS refuses the app on first launch, usually with the words “damaged and can’t be opened”. The download is not damaged; that is the message Gatekeeper shows for any unnotarized app. How to open it anywayexplains the override.

Until then, verify the disk image against the checksums published with each release on the release page. That is a weaker guarantee than notarization — it proves the file matches what the release workflow published, not that Apple scanned it — but it is checkable today.

Team roles

  • Committers and reviewers: members of thePersonalJarvis GitHub organization with write access to the repository. Every change reaches the release branch through the repository's pull request and required-check rules.
  • Approvers: owners of thePersonalJarvis GitHub organization. Each signing request is approved by hand, once per release.

Everyone in these roles must use multi-factor authentication for GitHub and for SignPath.

Privacy

Personal Jarvis contains no telemetry, analytics or crash reporting. It sends data only to services you connect yourself — for example the AI provider whose key or subscription you add, or a channel such as Telegram — and only when you use them. To offer updates it asks GitHub for the latest release. Nothing else is transferred to other networked systems unless you request it. This website's own data practices are in theprivacy policy.

Reporting a problem

If you believe a signed file was not built from this repository, or behaves in a way this page does not describe, report it through thesecurity policy.

Personal Jarvis

Free to use, modify and distribute, commercially included, with a patent grant from every contributor. Releases up to 1.6.0 remain MIT, permanently. Third-party names and logos belong to their owners.

This page sets no cookies and runs no analytics. It asks GitHub and Discord for its live counts, and contacts YouTube only when you press play on a video. Details in the privacy policy.

Project

  • Source
  • Docs
  • Blog
  • Security

Legal

  • Imprint
  • Privacy
  • Code signing policy
  • License
  • Notice
  • Trademarks
  • Licensing history

Follow

  • YouTube
  • X
  • Discord

© 2026 the Personal Jarvis contributors

Apache 2.0