Why the installer is not signed

Windows will say “unknown publisher”, and that is about the signature, not about the contents of the file. Here is why, how the integrity of a file is checked and what a SHA-256 sum does not replace.

What you will see when installing

Windows shows “Windows protected your PC” and the line “Unknown
publisher”. Edge may warn beforehand that the file is not commonly
downloaded.

Both say the same thing: the file carries no publisher signature.
Neither means anything was found in the file.

Why there is no Windows signature yet

A signature is not a checkbox in the build settings. It is a certificate
issued by a certificate authority for money and renewed every year. For
Windows it costs between two and six hundred euro a year, and the
warning disappears immediately only with the expensive variant — which
is issued to companies only.

For now that money goes into development. We say so plainly instead of
hiding behind “click More info”.

macOS is different

The Apple developer account is already paid for, and signing with
notarisation lands in the next macOS release. If your copy still
complains, that behaviour has days left.

How to check the file is ours

Next to every build on the download page we publish its SHA-256
checksum. It is computed from the contents of the file: change one byte
and the sum changes entirely. If the sum matches, the file you
downloaded is exactly the file published on the official Quasar site:
it did not break on the way and was not swapped between the site and
your machine.

Let us be plain about what a checksum does NOT do: it does not prove the
file was released by us. That is the work of a publisher's digital
signature, and a checksum does not replace it — it confirms the
integrity of the file, not its origin.

Check it yourself:

Windows — open a command prompt in the folder and run
certutil -hashfile filename.exe SHA256

macOS — shasum -a 256 filename.dmg

Linux — sha256sum filename.rpm

Compare the result with the sum published for your system. They must
match character for character.

If you want a stricter check

Upload the file to VirusTotal — it runs the file through dozens of
antivirus engines at once. That check is independent: we have no
influence over its result.

Our own measurement: Microsoft Defender with current definitions finds
no threat in the installer. But you do not have to take our word for it
— that is what the checksum and the independent check are for.

How to install anyway

In the warning window click “More info”, then “Run anyway”. In Edge, if
the download was stopped, open the downloads list, click the three dots
next to the file and choose “Keep”.

What happens next

On macOS the signature arrives with the next release. On Windows — when
we buy the certificate; that is not planned right now, and we do not
pretend otherwise.

Until then the SHA-256 checksum is what proves the file is ours, and we
publish it with every release.