Early Access
Verify your download
The Windows installer is code-signed by CedriX Solutions, so Windows shows our name rather than an unknown publisher. Here's what you'll see when you run it, and how to confirm the file is the one we published.
1. What Windows shows
When you run the installer, Windows asks for administrator permission and names the publisher as CedriX Solutions. That is the signature being checked, and it is what you should expect to see.
You may still meet “Windows protected your PC” from SmartScreen in the first weeks after a release. SmartScreen builds reputation for a publisher as downloads accumulate, so a recently-signed installer can still be flagged — the difference is that it now names us instead of calling the publisher unknown. To continue:
- Click More info
- Check the publisher reads CedriX Solutions
- Click Run anyway
If you'd rather confirm the file first, do step 2 before you run it.
2. Confirm the installer (recommended)
Every release is published with a SHA-256 checksum — a fingerprint of the exact file we built. If the checksum of your download matches the one we publish, you have the genuine installer, byte for byte. The signature already proves who built it; the checksum is a second, independent check, in a different channel from the one the download reached you in.
Download
Use the download link in your Night Agent welcome email. It always comes
from https://mynightagent.com/download — if a copy reaches you any
other way, don't trust it; check its checksum here first.
Check it, in PowerShell
In the folder where the installer downloaded, run:
Compare the SHA256 value it prints against the checksum we
publish for the current build:
They should be identical (the comparison is not case-sensitive). To have
PowerShell do the comparison for you, paste the published hash in place of
<published-hash>:
A result of True means the file is genuine and complete. If
it prints False, do not run the installer — re-download it
from your emailed link, and if it still doesn't match, email
hello@cedrixsolutions.com.
3. Inspecting the signature (optional)
Right-click NightAgent-Setup.exe →
Properties → Digital Signatures. You
should see CedriX Solutions, and under
Details, “This digital signature is OK.”
If you open the certificate itself, it will look expired — valid for only about three days from when we built the release. That is correct and expected. Night Agent is signed through Microsoft's Azure Artifact Signing service, which issues a short-lived certificate for each signing operation and keeps the private key in its own HSM, so there is no long-lived signing key for anyone to steal.
Every signature is timestamped, and Windows validates a signature against the moment it was made rather than the moment you check it — so the installer stays valid indefinitely. Windows itself ships this way: many of its own system files are signed with certificates that expired years ago and still verify.