Status: signing with SignPath is being set up. Until it is in place, the Windows programs are published unsigned; this page describes how they will be signed and will be updated when signing starts.
What is signed
- IngeTrazo's Windows executables,
ingetrazo.exe and ingetrazo-mcp.exe, and the installer ingetrazo-setup-<version>.exe.
- Only what is built from this project's public source code is signed. Third-party components shipped inside the package (Python, Qt/PySide6 and other free libraries) are not signed with our certificate.
- Every release is built on GitHub Actions from the public repository, by the "Build Windows" workflow; nothing that is published is built on anyone's own machine. Downloads are on the GitHub releases page.
Team roles
- Committers and reviewers: the code is written by the project maintainer and the contributors. Every change from a contributor comes in through a public pull request that the maintainer reviews before accepting it.
- Approvers: Marco Sumari Tellez (@tuxiasumari), project maintainer. Every release signature is approved manually.
- Accounts with access to the repository and to signing use two-factor authentication.
Privacy policy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. It has no telemetry and does not check for updates on its own. It only connects when you use a feature that needs it:
- Map and terrain tiles (OpenStreetMap, Esri, EOX, Sentinel-2, elevation models from AWS Open Data) and place search (Nominatim).
- The "Locate me" button, which estimates your city from your IP address (ipapi.co).
- The component library (ingetrazo.com) and the materials and models libraries (Poly Haven, ambientCG, Sketchfab).
- The AI assistant, which only talks to the provider you choose and configure with your own key (or to a local model such as Ollama).
How to check a file
- On Windows: right-click the
.exe ▸ Properties ▸ Digital Signatures tab.
- If an antivirus flags an IngeTrazo file, let us know on GitHub or by email.