Trust & safety

How we review

Every build runs the same automated gates, visible to the developer in real time. Human review only touches what the machine flags — and every rejection cites the rule and the fix.

The gates
  1. Signature chain — Developer ID, chaining to the Apple root
  2. Notarization — a stapled Apple ticket
  3. Malware scan — ClamAV · VirusTotal · YARA, all clean
  4. Entitlements diff — expanded capabilities are flagged for a human
  5. SBOM + publish gate — recorded, then cleared for distribution

Trusted developers (T2+) with an all-green build are approved automatically. Everyone else enters a human queue with a 24-hour service level. Rejections name the failed gate and the remediation; you can appeal with a 2 business day response.