Release boundary / Developer preview

Download only what Strust has verified.

Strust is a behavioral verifier for existing software and its AI-written replacement. This page stays fail closed until a package has source provenance, clean-machine evidence, signing, security documentation, and release-owner approval.

See how verification works
PROMOTION PATHWINDOWS X64
  1. SourceTagged
  2. BuildAuthenticated
  3. AcceptanceClean machine
  4. ReleaseOwner approved
Not promoted
Version
0.9.0-rc.1
Download
Not promoted
Format
Portable ZIP
Install
Extract and run
SHA-256

No digest is advertised until an approved promotion record names the exact artifact.

CHOOSE YOUR PLATFORM

Strust highlights your detected operating system without starting a download. Every platform remains visible.

Native builds / one evaluator contract
Not promoted

Windows

Windows x64

Portable ZIP after signing, clean-machine acceptance, release-owner approval, and the remaining GA gates.

Not promoted

macOS

Apple silicon + Intel

Universal tarball after Developer ID signing, notarization, two-architecture acceptance, and the remaining GA gates.

Not promoted

Linux

Linux x64

Native tarball after Sigstore authentication, clean-machine and container acceptance, and the remaining GA gates.

A platform listed as Not promoted has no public artifact here. Local product work and public release are separate states.

Promotion boundary

Eight gates. One download decision.

A URL or checksum cannot activate a Strust download. Each platform needs a checked-in promotion record after the release workflow verifies source, signatures, SBOM, provenance, acceptance evidence, operational ownership, and customer proof.

0 of 3 platforms promoted
PROMOTION GATES
G1Clean tagged source
G2Authenticated artifact set
G3Clean-machine first success
G4Untrusted-target confinement
G5Platform signing
G6Hostile-condition recovery
G7Public security and support
G8Paying-customer proof

No platform has a GA promotion record. Download routes, checksums, and release-evidence redirects remain closed.

First run

The Windows build runs from its folder.

When promoted, the portable package includes the verifier, runtime, offline demo, licenses, and release evidence. It does not install a service or write to the registry.

POWERSHELLWINDOWS
Expand-Archive .\strust-0.9.0-rc.1-windows-x86_64.zip .\strust
cd .\strust\strust-0.9.0-rc.1-windows-portable
.\strust.exe

On first launch, choose ChatGPT sign-in, an API key, or another configured model provider.

One download, two judgments

The agent can change the code. It cannot certify itself.

VERIFIER PACKAGE

Paired execution

Run an approved reference and candidate replacement against the same declared inputs and observations.

Independent verdict

Return MATCH, DIVERGE, or INCONCLUSIVE without letting the candidate-writing actor control acceptance.

Agent-facing evidence

Retain the first difference, receipts, and rerun history for the coding agent and human reviewer.

Strust runs commands declared by the project on your machine. Use code you trust; a copied workspace is not a hostile-code sandbox.