Proton PGP Keys signing & verifying all *nix/Windows/Android/iPhone apps. I think users should be able to verify their download.
Many other applications are signed and verified by their makers. Proton should have PGP keys referenced on their website, that sign and verify the applications for download are legitimate and verifiably Proton Products. Think Veracrypt/TAILS/Linux Mint. All those those OSes & software have PGP keys that you can check, in order to make sure what you're downloading is from who it says its from. If I'm using PGP keys within Proton to sign my email for this same purpose; I think Proton should also use these same keys to verify/sign its own products.
Thanks.
1
vote