Skip to content

Code signing policy

Every Windows release of Project IGI Studio is built by GitHub Actions from the public source code of a tagged version, and nowhere else. This page says how releases are signed, who can approve that, and what the program does on the network.

Signing

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Not signed yet

Signing starts with the first release after SignPath Foundation accepts the project. Until then releases are unsigned, and Windows SmartScreen warns about them: see Installing for what to click.

What is signed

  • The installer, ProjectIGIStudio-Setup-<version>.exe.
  • The programs inside it and inside the portable zip: Project IGI Studio.exe, and the studio's own server, studio-server.exe.

Only files that the release workflow builds from the project's source code are signed. Nothing built on a personal computer is signed. Files that come from other open source projects, such as the Python runtime inside the server, keep their own publisher's signature, or none; this project does not sign them.

Team and roles

RoleWho
Committers and reviewersNouman Ahsan
ApproversNouman Ahsan
  • Changes from anyone outside the team are reviewed by a committer before they are merged.
  • Every release is approved by hand before it is signed.
  • Everyone in the team uses multi-factor authentication for GitHub and for SignPath.

Privacy

This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it.

In detail:

  • The AI designer sends what you ask it, and the parts of your mission it needs to answer, to the AI service set in Settings (OpenAI unless you change it), with your own key. It does this only when you use it.
  • The update check asks GitHub whether a newer version of the studio exists. It sends nothing about you, your game or your missions. You can turn it off in Settings.
  • Everything else stays on your computer. The studio's window talks only to its own server, on your computer, which reads your game folder and, when you apply a mission, writes it into the game: into its own mission slot, its texts into the game's language files, and the one line of the game's settings that lets its mission list reach it, after backing them up. Everything else stays in your own folder, %LOCALAPPDATA%\ProjectIGIStudio.
  • There is no telemetry, no analytics and no crash reporting.

Links to GitHub or to this site open in your web browser, and only when you click them.

Something wrong?

If a file you downloaded is not what this page says, or its checksum does not match the one listed with its release, do not run it. Open an issue and say where you got it.

An unofficial fan tool. Project I.G.I. is a trademark of its owners. The studio ships no game files.