Trust & safety
How we review
Every build runs the same automated gates, visible to the developer in real time. Human review only touches what the machine flags — and every rejection cites the rule and the fix.
The gates
- Signature chain — Developer ID, chaining to the Apple root
- Notarization — a stapled Apple ticket
- Malware scan — ClamAV · VirusTotal · YARA, all clean
- Entitlements diff — expanded capabilities are flagged for a human
- SBOM + publish gate — recorded, then cleared for distribution
Trusted developers (T2+) with an all-green build are approved automatically. Everyone else enters a human queue with a 24-hour service level. Rejections name the failed gate and the remediation; you can appeal with a 2 business day response.