Notarized, Updated, Boring: The Trust Stack You Never See
When you download a Mac app from a website instead of the App Store, your Mac does a quiet background check before it lets you open it. It looks at who signed the app, whether Apple vouches for that signature, and whether the app has been tampered with since it was signed. Most people never see this check. They just see "this app is from the internet, are you sure," or they don't see it at all, because the app opened fine.
That invisible check is the trust stack, and it's the most boring, most important part of shipping software outside the App Store. I want to walk you through what it is, because you're trusting it every time you install a tool like the one I make, and you should know what you're actually trusting.
The three layers
There are three separate things that have to be true for a Mac app to be safe to install, and they're easy to confuse.
Layer one answers "who made this." Layer two answers "did Apple check it." Layer three answers "is the thing I'm updating to really from the same person." None of these make an app safe in the sense that it can't do anything bad, and no signature can promise that. What they do is close the specific holes that let malware pretend to be a real app, and that's a real protection.
Why I bothered
Here's the honest version of why this stack exists in my world. WriteAmp isn't on the App Store, because the App Store's rules don't fit how I want to sell and update a tool like this, so I distribute it directly, which means I have to earn the trust the App Store would have provided by other means. The way you do that is notarization and signing, the exact same machinery Apple built so that software from outside the App Store doesn't have to be a leap of faith.
The practical effect is what you see when you install it. Your Mac recognizes the signature, checks the notarization stamp, and lets the app open without you having to fight Gatekeeper or dig through System Settings to allow it. That frictionless install isn't luck. It's the trust stack working, and I've seen what it looks like when it's missing, which is why I don't cut the corner.
A signed, notarized app is not a guarantee the app is good, private, or bug-free. It is a guarantee about provenance: this is genuinely from the developer it claims to be from, and it has not been tampered with. Those are different promises, and I do not want to blur them.
The update channel nobody thinks about
The third layer is the one most people never consider, and it's the one I care about most. When an app updates itself, that's a moment of trust, because you're running new code from the internet. If the update mechanism isn't secured, an attacker who compromises the update server can push malware to everyone who installed the app, and that's how a lot of real-world attacks happen, not through the original download, but through a later update.
WriteAmp updates through Sparkle, the standard update framework for Mac apps outside the App Store. Every update is signed with a key that only I hold, and the app verifies that signature before it installs anything. The update server could be compromised tomorrow, and the worst case is the app refuses to update, because the fake update wouldn't carry my signature. That's the boring protection, and it's the one that keeps a tool you trust from becoming a tool that betrays you six months after you installed it.
What it does not cover
I'm going to keep this honest, because the trust stack has edges. Signing and notarization don't protect you from a developer who turns malicious, because a real developer can sign malicious software too. They don't protect you from bugs, because a signed app can still crash. They protect one specific thing, provenance, and the integrity of updates, and that's the thing worth protecting when you're downloading a tool that asks for permissions and reads your typing.
That last part is why I think about this stack as part of the privacy story, not separate from it. A tool that watches your writing is only worth installing if you can be sure it's really the tool it claims to be, from the developer it claims to be from, updated by that same developer. The signature is what makes that true, and it's the foundation the privacy promises stand on. I wrote about the network ledger and the encrypted history file elsewhere, and the signature is the thing that ties them to a real person you could hold accountable.
The honest close
None of this is exciting, and that's the point. The trust stack is at its best when you never notice it, when the app opens without a fight, when updates arrive quietly and install safely, when the whole machinery of verification happens behind the scenes while you just use the tool. I'd rather ship boring, signed, verifiable software than exciting software you have to take on faith.
The trial is free for 30 days if you want to see what a properly signed, notarized, self-updating Mac app feels like, the kind that opens without a system-settings battle and updates without drama. The press page has the technical details if you want to verify the signing yourself, because you should be able to check the things you're trusting. Boring is a feature, and it's the one I'm proudest of.
Sources
- Apple: notarizing macOS software: signing and notarization for apps distributed outside the App Store
- Apple Support: safely open apps on your Mac: what Gatekeeper checks at install
- Sparkle: the signed-update framework behind tamper-proof updates
On macOS 26+ Macs, Apple Intelligence mode stays free even after the trial ends — you always keep a working path to suggestions.
Written by Amit Ashwini, who builds WriteAmp and runs its marketing. More: why the Tab key beats the chat box · mini, midi, and max compared · benchmark methodology.