GUARDIANAYour data, under your controlESENPTDownload

CODE SIGNING POLICY · 10 OCTOBER 2026

Code signing policy

What we sign and with what, where it is built, who approves each signature, what the programs connect to, and how you can check all of it without trusting us.

How files are signed today

Every file we publish carries three proofs that it is ours and that nobody changed it on the way:

What the Windows programs do not carry today is a publisher signature (Authenticode), the one Windows reads: that is why, when you open them, Windows says “Unknown publisher” or “Windows protected your PC”. The install page explains why, what to do, and how to check the file before you open it. The macOS app is not notarized by Apple either, and the same page explains the macOS warning.

What is signed

Only what we make, from the code in our repository: the files published at guardianagroup.com/descargas.

We do not sign other people’s programs, nor any file that does not come out of this repository.

Where it is built

Who does what

GUARDIANA is the work of one person today. The three roles a signing policy asks for are all held by the same owner:

AuthorsChange the code without anyone else’s review.Francisco Salvatierra Sánchez
ReviewersReview the changes someone from outside proposes before they go in.Francisco Salvatierra Sánchez
ApproversApprove each signature, one by one, by hand.Francisco Salvatierra Sánchez

Francisco Salvatierra Sánchez is the owner of GUARDIANA GROUP, in his own name: GUARDIANA GROUP is the brand and the domain, and there is no registered company yet (contact). Repository: github.com/guardianagroup/guardiana; GitHub account: github.com/guardianagroup.

Much of the code is written by Claude, an AI coding assistant made by Anthropic, in sessions the owner opens and directs; in the repository’s history those changes appear with the author “Claude”. It has no role of its own in this policy: it approves no signature, and every signature is made by the owner, with his password.

Privacy

The privacy policy tells it in detail. In short: the programs do not transfer any information to other networked systems unless the person installing or using them asks for it. There is no telemetry, no account and no server of ours. These are all of their connections, by name:

Every licence and “Check for updates” connection is written down in the program, with its date and destination. The block lists ship inside the program and are renewed with each release: neither program downloads them on its own. GUARDIANA ZERO’s web engine, Microsoft’s WebView2, is updated by Windows, not by ZERO; if Windows lacks it, ZERO tells you and opens Microsoft’s download page in your browser.

The companies involved have their own privacy policies: Dodo Payments (the licence), GitHub (only if you check for updates) and Microsoft (GUARDIANA ZERO’s WebView2 engine).

How to check it yourself

You do not need to trust us. The install page explains, with the exact commands, how to take a file’s hash, compare it with the public ledger and check its minisign signature; GUARDIANA ZERO is checked the same way, with its download table. Once installed, guardiana verify repeats the check on your own machine.

If anything on this page stops being true, it is corrected here, with the date. To report a security issue: security.txt; for everything else, hola@guardianagroup.com.