I will sign notarize and add auto updates to your desktop app


About this gig
Your installer works. Then Windows says "unknown publisher", macOS says it "cannot be opened because Apple cannot check it for malicious software", and half your users stop right there.
I fix that.
WHAT I DO
- Windows: Authenticode signing with timestamping, so your app stays trusted after the certificate expires
- macOS: Developer ID signing, hardened runtime and entitlements, notarization with notarytool, and stapling so it verifies offline
- Verification on a clean machine, so you see for yourself the warning is gone
- Auto-updates wired to GitHub Releases, S3, or your own server
- A pipeline that builds, signs and publishes both installers on every tag
WORKS WITH
Electron, Tauri, .NET, Qt, Python (PyInstaller), and most other desktop stacks.
WHAT YOU NEED
Your own certificates: an Apple Developer account, and a Windows code signing certificate. Windows certificates now have to live on a hardware token or a cloud signing service, which is where most people get stuck. I will walk you through it.
Send me your repo or your unsigned build and I will tell you exactly what is missing, before you order.
Get to know Maneet Goyal
Desktop apps for Windows and Mac, built to ship
- FromIndia
- Member sinceJul 2025
- Avg. response time1 hour
- Last delivery3 weeks
Languages
English, Hindi
My Portfolio
FAQ
Do I need to buy my own certificates?
Yes, and you should. Certificates are tied to your company identity, so they have to be issued to you, not to me. That is an Apple Developer account for macOS and a code signing certificate for Windows. If you have not bought them yet, message me first and I will tell you exactly which to get.
Why is the Windows certificate so complicated now?
Since 2023 the private key has to be stored on a hardware token or a cloud signing service, so you can no longer just drop a .pfx file into your build. It is the single most common reason a signing setup fails. I set this up regularly and will handle the CI side of it.
Will the SmartScreen warning disappear immediately?
With a standard certificate, not straight away. SmartScreen builds trust as more people download your signed app, so the warning fades over the first weeks. An EV certificate gets you that trust on day one. I will tell you honestly which is worth i
Can you do this without my source code?
Often yes. For signing alone I can usually work from your build output and build configuration. Auto-updates and CI/CD need repository access.
What if it still shows a warning after you deliver?
Then it is not finished, and I keep working on it. Every package includes verification on a clean machine before I hand it over.
Which frameworks do you support?
Electron and Tauri most often, but the same work applies to .NET, Qt, PyInstaller and anything else that produces a Windows or macOS binary.
Do you handle the Mac App Store or Microsoft Store?
Store submission is different work with its own review process. Message me and I will quote it separately.

