Security transparency
Updated September 30, 2026. This notice covers the Leather Client 1.0.4 Windows release and the sandbox results available at that time.
Leather NEVER requires you to disable your antivirus. Keep security protections enabled. We do not ask you to add antivirus exclusions or turn off Windows security features.
Important: Windows may show an unrecognized app warning
The current Windows release does not have an Authenticode publisher certificate. When opening a downloaded installer or launcher, Windows SmartScreen may display “Windows protected your PC” or an “unrecognized app” warning. An “Unknown publisher” label can also appear in the Windows permission prompt.
A SmartScreen unrecognized-app warning is a reputation check, not the same as an antivirus identifying a named threat. Missing code signing and limited download reputation can trigger it. This distinction does not mean every security warning should be ignored. Read Microsoft's explanation of SmartScreen reputation.
Leather's updater signatures verify update authenticity, but they are separate from Windows publisher code signing and do not remove SmartScreen warnings. If Windows blocks the app or you are unsure about a prompt, leave protections enabled and contact us with the exact warning.
What was tested
View the standalone binary's Triage report. This test runs Leather Client.exe, not the bootstrap/full installer downloaded through the website. The standalone run received a 6/10 behavioral score. The separate installer runs we reviewed received 10/10.
The standalone file's SHA-256 is 6e2fb2c0232062c666c16350758f8b430411517a12b428bd37f9ec776dadc07d. It matches our local release build. A matching hash establishes file identity, not proof of safety.
Why the standalone binary still has detections
Leather uses Microsoft WebView2 to render its interface. Running the standalone executable still starts browser, renderer, GPU, network, and utility processes. The sandbox observes these child processes as well as the launcher. Microsoft documents this process model.
The report lists checks of UAC settings, system and network information, file writes, blocking non-Microsoft binaries during process creation, and 13 WriteProcessMemory events. Behavioral rules can flag legitimate operations as well as malicious ones. Their presence is not, by itself, proof of a virus.
Sandbox scores describe observed behavior, not an antivirus verdict. The report is linked here so you can see what was tested and compare it with the launcher's normal operation.
Installer results are different
The website's Windows WebSetup downloads and launches the full installer. That installer extracts NSIS plugins and may install WebView2 if needed. These add behaviors absent from the standalone test. The flagged System.dll in the installer report matches our NSIS plugin, and the downloaded installer matches our release build.
The listed standalone network activity includes the GitHub update manifest and browser requests.
If your antivirus reports Leather
- Keep your antivirus enabled and leave the file blocked or quarantined.
- Report the detection name, antivirus product, Leather version, file SHA-256, and a report link through the community link on our home page.
- Do not include passwords, session tokens, or other private information in a public report.
We will update this notice as signing status and verified report details change.