CODE SIGNING POLICY · 10 OCTOBER 2026
Code signing policy
What we sign and with what, where it is built, who approves each signature, what the programs connect to, and how you can check all of it without trusting us.
How files are signed today
Every file we publish carries three proofs that it is ours and that nobody changed it on the way:
- A minisign signature next to each file (
.minisig), made with our key. The public key has been in the repository, atbuild/pubkey/minisign.pub, since before the first download, and it also ships inside the program:RWS+xz+N6DvnuDlJCAIOUEku8PLZ9pP1cUaoQnusfduLWpVIVmPXM16r(key idB8E73BE88D3FC7BE). - Its SHA-256 hash in the public ledger,
ledger.jsonl, in the GitHub repository, next to the commit of the code it was built from. It is written before the download exists. - That entry, signed and stamped in Rekor, Sigstore’s public transparency log: it proves the date, and nobody can rewrite it afterwards.
What the Windows programs do not carry today is a publisher signature (Authenticode), the one Windows reads: that is why, when you open them, Windows says “Unknown publisher” or “Windows protected your PC”. The install page explains why, what to do, and how to check the file before you open it. The macOS app is not notarized by Apple either, and the same page explains the macOS warning.
What is signed
Only what we make, from the code in our repository: the files published at guardianagroup.com/descargas.
- GUARDIANA: the Windows installers (
.msi, in Spanish, English and Portuguese), the Debian and Ubuntu package (.deb), the archive for other Linux systems (.tar.gz) and the macOS app (.app.zip). They are on the install page. - GUARDIANA ZERO, the browser: the Windows program (
.exe) and its installers (.msi, in Spanish, English and Portuguese). They are on its page.
We do not sign other people’s programs, nor any file that does not come out of this repository.
Where it is built
- Everything is built on GitHub Actions, on machines GitHub lends and that are not ours, from the public code at github.com/guardianagroup/guardiana, licensed under GPL-3.0 or later. GUARDIANA in the
candidato.ymlworkflow (Windows, Linux and a Mac); GUARDIANA ZERO inzero.yml(Windows). The same runs install and test the files on a clean machine before they are signed. - The minisign private key is never on GitHub or in continuous integration. Signing happens afterwards, on the owner’s computer, on the exact files that came out of GitHub Actions: before signing, their hashes are checked against the list (
SHA256SUMS) GitHub printed. - Reproducible builds, where they exist. The GUARDIANA binaries for Windows and Linux come from
build/repro.sh, with a container pinned by its digest: anyone can repeat the build and get the same hash, andrepro.ymldoes it on GitHub. The packages (.msi,.deb,.tar.gz, the macOS app) and GUARDIANA ZERO are not reproducible yet; the public ledger says so file by file ("reproducible": trueorfalse).
Who does what
GUARDIANA is the work of one person today. The three roles a signing policy asks for are all held by the same owner:
| Authors | Change the code without anyone else’s review.Francisco Salvatierra Sánchez |
|---|---|
| Reviewers | Review the changes someone from outside proposes before they go in.Francisco Salvatierra Sánchez |
| Approvers | Approve each signature, one by one, by hand.Francisco Salvatierra Sánchez |
Francisco Salvatierra Sánchez is the owner of GUARDIANA GROUP, in his own name: GUARDIANA GROUP is the brand and the domain, and there is no registered company yet (contact). Repository: github.com/guardianagroup/guardiana; GitHub account: github.com/guardianagroup.
Much of the code is written by Claude, an AI coding assistant made by Anthropic, in sessions the owner opens and directs; in the repository’s history those changes appear with the author “Claude”. It has no role of its own in this policy: it approves no signature, and every signature is made by the owner, with his password.
Privacy
The privacy policy tells it in detail. In short: the programs do not transfer any information to other networked systems unless the person installing or using them asks for it. There is no telemetry, no account and no server of ours. These are all of their connections, by name:
- Activating the licence (GUARDIANA and GUARDIANA ZERO): one connection to Dodo Payments, the payment gateway (
live.dodopayments.com), when you type your key. - Checking the licence: with the same gateway, 8 days after activating it and then once per billing period (every 30 days with the Founder licence); if it cannot be done, it is retried every hour. You agree to it when you subscribe: you do not press anything each time.
- Check for updates (GUARDIANA ZERO only, and only when you press the button): it reads the public ledger,
ledger.jsonl, on GitHub once (raw.githubusercontent.com). GUARDIANA does not look for updates: it has no such function. - What the program does for you: GUARDIANA, as a DNS guardian, forwards the name queries of your computer (and, with Home Mode, those of your Wi‑Fi) to the DNS server you already used; GUARDIANA ZERO opens the pages you open. That is what they are installed for.
Every licence and “Check for updates” connection is written down in the program, with its date and destination. The block lists ship inside the program and are renewed with each release: neither program downloads them on its own. GUARDIANA ZERO’s web engine, Microsoft’s WebView2, is updated by Windows, not by ZERO; if Windows lacks it, ZERO tells you and opens Microsoft’s download page in your browser.
The companies involved have their own privacy policies: Dodo Payments (the licence), GitHub (only if you check for updates) and Microsoft (GUARDIANA ZERO’s WebView2 engine).
How to check it yourself
You do not need to trust us. The install page explains, with the exact commands, how to take a file’s hash, compare it with the public ledger and check its minisign signature; GUARDIANA ZERO is checked the same way, with its download table. Once installed, guardiana verify repeats the check on your own machine.
If anything on this page stops being true, it is corrected here, with the date. To report a security issue: security.txt; for everything else, hola@guardianagroup.com.