Skip to content

Code signing policy

Editions: OSS, Cloud, Enterprise. Unless stated otherwise, everything on this page ships in OSS.

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Signed release provenance

Since v0.15.0, GitHub release assets carry Sigstore build provenance generated with the Release workflow's GitHub OIDC identity. This covers all attached CLI binaries, Python packages, Helm charts, installers, Compose configuration, SBOMs, and the checksum manifest. See release verification for verification commands and coverage limits.

Windows Authenticode

Windows CLI release binaries published on GitHub Releases:

  • preloop-windows-amd64.exe
  • preloop-windows-arm64.exe

These artifacts are built by GitHub Actions from this repository on version tags (v*). When SignPath credentials and policy are configured, they are submitted for Authenticode signing before attachment to the release. Otherwise the workflow warns and publishes them without Authenticode signatures. macOS and Linux binaries use the Sigstore provenance above, not Authenticode.

See also windows-code-signing.md for CI wiring and maintainer setup.

Team roles

Per SignPath Foundation conditions for Open Source projects:

Role Members
Authors preloop organization members trusted to modify source in this repository
Reviewers preloop organization members who review pull requests
Approvers preloop organization owners who approve SignPath signing requests

Privacy policy

CLI and self-hosted instance telemetry (optional, opt-out) is documented in SECURITY.md ยง Telemetry. Set PRELOOP_DISABLE_TELEMETRY=true to disable it.

For Preloop Cloud / hosted services, see https://preloop.ai/privacy.