Blog

Notarized, Updated, Boring: The Trust Stack You Never See

A verified checkmark, the quiet stamp that makes software from the internet trustworthy
Photo by Franck on Unsplash

When you download a Mac app from a website instead of the App Store, your Mac does a quiet background check before it lets you open it. It looks at who signed the app, whether Apple vouches for that signature, and whether the app has been tampered with since it was signed. Most people never see this check. They just see "this app is from the internet, are you sure," or they don't see it at all, because the app opened fine.

That invisible check is the trust stack, and it's the most boring, most important part of shipping software outside the App Store. I want to walk you through what it is, because you're trusting it every time you install a tool like the one I make, and you should know what you're actually trusting.

The three layers

There are three separate things that have to be true for a Mac app to be safe to install, and they're easy to confuse.

1
It is signed by a real developer
The app carries a digital signature from a Developer ID that Apple issued to a real person or company. Tamper with the app and the signature breaks.
2
Apple notarized it
The developer sends the signed app to Apple, Apple scans it for malware, and issues a stamp. Your Mac checks the stamp before first launch.
3
Updates are signed too
When the app updates itself, the update is signed and verified, so a compromised update server cannot push you a fake version.

Layer one answers "who made this." Layer two answers "did Apple check it." Layer three answers "is the thing I'm updating to really from the same person." None of these make an app safe in the sense that it can't do anything bad, and no signature can promise that. What they do is close the specific holes that let malware pretend to be a real app, and that's a real protection.

Why I bothered

Here's the honest version of why this stack exists in my world. WriteAmp isn't on the App Store, because the App Store's rules don't fit how I want to sell and update a tool like this, so I distribute it directly, which means I have to earn the trust the App Store would have provided by other means. The way you do that is notarization and signing, the exact same machinery Apple built so that software from outside the App Store doesn't have to be a leap of faith.

The practical effect is what you see when you install it. Your Mac recognizes the signature, checks the notarization stamp, and lets the app open without you having to fight Gatekeeper or dig through System Settings to allow it. That frictionless install isn't luck. It's the trust stack working, and I've seen what it looks like when it's missing, which is why I don't cut the corner.

The honest note

A signed, notarized app is not a guarantee the app is good, private, or bug-free. It is a guarantee about provenance: this is genuinely from the developer it claims to be from, and it has not been tampered with. Those are different promises, and I do not want to blur them.

The update channel nobody thinks about

The third layer is the one most people never consider, and it's the one I care about most. When an app updates itself, that's a moment of trust, because you're running new code from the internet. If the update mechanism isn't secured, an attacker who compromises the update server can push malware to everyone who installed the app, and that's how a lot of real-world attacks happen, not through the original download, but through a later update.

WriteAmp updates through Sparkle, the standard update framework for Mac apps outside the App Store. Every update is signed with a key that only I hold, and the app verifies that signature before it installs anything. The update server could be compromised tomorrow, and the worst case is the app refuses to update, because the fake update wouldn't carry my signature. That's the boring protection, and it's the one that keeps a tool you trust from becoming a tool that betrays you six months after you installed it.

A new version of WriteAmp is available. This update is signed and verified, and will not touch your data.

What it does not cover

I'm going to keep this honest, because the trust stack has edges. Signing and notarization don't protect you from a developer who turns malicious, because a real developer can sign malicious software too. They don't protect you from bugs, because a signed app can still crash. They protect one specific thing, provenance, and the integrity of updates, and that's the thing worth protecting when you're downloading a tool that asks for permissions and reads your typing.

That last part is why I think about this stack as part of the privacy story, not separate from it. A tool that watches your writing is only worth installing if you can be sure it's really the tool it claims to be, from the developer it claims to be from, updated by that same developer. The signature is what makes that true, and it's the foundation the privacy promises stand on. I wrote about the network ledger and the encrypted history file elsewhere, and the signature is the thing that ties them to a real person you could hold accountable.

The honest close

None of this is exciting, and that's the point. The trust stack is at its best when you never notice it, when the app opens without a fight, when updates arrive quietly and install safely, when the whole machinery of verification happens behind the scenes while you just use the tool. I'd rather ship boring, signed, verifiable software than exciting software you have to take on faith.

The trial is free for 30 days if you want to see what a properly signed, notarized, self-updating Mac app feels like, the kind that opens without a system-settings battle and updates without drama. The press page has the technical details if you want to verify the signing yourself, because you should be able to check the things you're trusting. Boring is a feature, and it's the one I'm proudest of.


Sources

On macOS 26+ Macs, Apple Intelligence mode stays free even after the trial ends — you always keep a working path to suggestions.

Written by Amit Ashwini, who builds WriteAmp and runs its marketing. More: why the Tab key beats the chat box · mini, midi, and max compared · benchmark methodology.