Code signing policy
Last updated 23 September 2026
Who signs VRX3D
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
Windows shows the publisher of signed VRX3D programs as SignPath Foundation. Signing lets Windows check that a file is exactly what this project built, and lets Smart App Control run it. Signed releases are being set up now; releases up to v1.7.9 are not signed.
What is signed, and how it is built
- VRX3D's own programs:
VRX.Desktop.exe,VRX.Desktop.dllandengine\xrplayer.exe, plus the installerVRX-Setup-<version>.exeand its uninstaller. - They are built by GitHub Actions from the public source code, never on a personal PC. Every input is pinned, and the depth models are rebuilt from their upstream sources and checked against known hashes.
- Every signing request is approved by hand before it is signed.
- The other components VRX3D ships (the .NET runtime, ONNX Runtime, DirectML, the Visual C++ runtime, the HLSL shader compiler and the OpenXR loader) are not re-signed: they keep their own publishers' signatures from Microsoft and Valve.
Team roles
Contributions from anyone else are reviewed by a committer before they are merged. All team members use multi-factor authentication for GitHub and SignPath.
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. See the privacy policy.
Reporting a problem
If you think a signed VRX3D file is not what it should be, or has been misused, please open an issue on GitHub, or contact SignPath Foundation through signpath.org.