Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Hardware, platform and safety / Security and privacy

Where does “Signed files” fit in Simca, with a focus on key ceremony not done?

Built in the repository (checked files or tested library code; not a product you can run yet) C0192

Everything the launcher installs is signed: packages, update manifests, entitlements, the catalog snapshot and price documents. A missing signature or an empty checksum is an error, never skipped. Ed25519 is used in the packaging code with test keys only; no production key exists in the repository and the key ceremony is not done. A revocation list and a trusted key set exist as code. Plan for: key ceremony not done; key loss; revocation travels with launcher updates. It exists only as a file in the repository, not as a product feature.

Go to the related page

How to read this

The tag above says how real the answer is. Answers describe the plan in the repository and design documents. No app is released. Where an answer touches tax or law, treat it as a theme to verify with a qualified local adviser.

More in Security and privacy