PRIVACY AND INSTALLATION AGREEMENT Agreement version: 2026.10.10.1 Effective date: October 10, 2026 Publisher: AI Creations Now Software Development Product: ArtifactTrust Pro GUI 3.1, 64-bit Windows edition Website: https://AICreateNow.com 1. Program purpose, publisher, and scope ArtifactTrust Pro GUI 3.1 is published by AI Creations Now Software Development, an independent software publisher. This Privacy and Installation Agreement explains what this Windows application does, the components it installs, the information it handles, and your choices. Publisher website and contact entry point: https://AICreateNow.com. Copyright © 2026 AI Creations Now Software Development. The application is a graphical interface for using your existing Microsoft Artifact Signing resources. It prepares the required local tools, authenticates through Microsoft, discovers resources accessible to your account, and signs files you select. Microsoft product names identify those external components and services; they are not the name of this independent application. The application is not sponsored, endorsed, or operated by Microsoft. A Store listing or a successful digital signature does not imply that Microsoft endorses your software or this verification report. This agreement covers the distributed desktop application and installer. The optional source builder is described separately below. Microsoft services, the Microsoft Store, your browser, Windows, and other vendors operate under their own applicable terms and privacy notices. This agreement does not replace their licenses or grant rights in their products. Mandatory consumer and privacy rights remain unaffected. 2. Installation, Administrator access, and first launch Setup installs the application, branding files, documentation, Windows uninstall registration, and shortcuts. A fresh installation defaults to C:\Program Files\ArtifactTrust Pro GUI. You can choose a dedicated alternative directory; an update may reuse the previously registered directory. Do not put unrelated files in that directory: successful uninstall removes its contents. Setup does not launch the application or install its Microsoft prerequisites. It does not add this application to Windows startup or create an application service or scheduled task. The same installer supports an interactive installation and deployment with /VERYSILENT /SUPPRESSMSGBOXES /SP- /NORESTART /RESTARTEXITCODE=3010. These switches control Setup. They do not bypass the application's first-use agreement or turn interactive Microsoft sign-in into unattended sign-in. Launch the installed desktop or Start Menu shortcut when ready. Both installation and application operation require Administrator access. Windows may display a User Account Control prompt before the application opens. If you supply credentials for a different Windows administrator, the program uses that administrator's Windows identity, profile, and saved session. After acceptance, System readiness inspects Windows, installed tools, component versions, registry information, and file locations. It then installs or repairs missing or unsuitable components as necessary. Existing suitable components are reused. The application requests no restart when running bundled prerequisite installers. Windows or a Microsoft installer may nevertheless report a restart requirement; the application reports that condition rather than promising every machine can finish preparation without a restart. Installers may create their own registry entries, package caches, installation records, environment settings, and logs as defined by Microsoft. 3. Microsoft components and bundled software The generated application includes six prerequisite package groups, collected and verified on the build computer: • Microsoft Azure CLI, including its supplied Python runtime and dependencies: authenticates the selected identity and queries existing subscriptions, accounts, profiles, and permissions. • Microsoft .NET 8 x64 Runtime: supports Microsoft's signing client components. The application also carries the .NET and Windows Desktop runtime files needed for its own self-contained executable. • Microsoft Visual C++ x64 Runtime: supports native Microsoft tools and their dependencies. • Microsoft Windows SDK Signing Tools, with the necessary offline MSI and cabinet files: supplies x64 SignTool for Authenticode signing and verification. This is the signing-tools subset, not a request to install the entire development SDK. • Microsoft Artifact Signing x64 client tools and client library: connects SignTool to Microsoft's signing service, including the native signing library and supplied managed dependencies. • The Microsoft Azure CLI Artifact Signing extension: adds resource-discovery commands. The bundled extension is version 1.0.0; a suitable newer installed extension can be reused. Other package versions are recorded by the builder when collected; they can differ between builds. Components retain their vendor identities, licenses, and original signatures where supplied. The builder verifies native Microsoft installers and records package file lengths and SHA-256 hashes. At first use the application extracts required packages to restricted temporary directories, checks the recorded bytes, and invokes the local installers. Missing, incomplete, or invalid bundled packages cause preparation to stop. There is no prerequisite-download fallback in this application. Local extension installation disables package-index access and automatic extension acquisition. Bundled preparation is not a claim that the complete product works offline: authentication, resource discovery, cloud signing, timestamping, and certificate validation need network services. Microsoft components can have their own network activity and privacy settings. Shared prerequisite installations, including the CLI extension, remain installed when this application is removed. You or your administrator may manage them separately with Microsoft or Windows tools; other applications may depend on them. 4. Microsoft authentication and account requirements You need an eligible Microsoft account or organizational identity, an appropriate Azure subscription, a configured Artifact Signing account, and an active certificate profile with signing permission. This release supports active Public Trust certificate profiles in the standard Azure public cloud. It does not target Private Trust profiles or sovereign-cloud endpoints, including Azure Government and Azure operated by 21Vianet. Microsoft determines regional availability, eligibility, identity validation, account restrictions, permissions, and service charges. The program opens Microsoft's normal browser sign-in through Azure CLI. Microsoft processes passwords, passkeys, MFA responses, security keys, and its browser cookies. The application does not provide a password-entry form or receive your Microsoft password or MFA code. It receives the resulting authorization and account/resource information through Microsoft's tools. A first connection can require two separate Microsoft browser sign-ins: initial directory discovery and a tenant-specific authentication or MFA retry. Complete all Microsoft prompts; a localhost success page is the CLI's local sign-in callback and can be closed after success. The program may read a non-secret tenant identifier from an existing ordinary Azure CLI profile or an abandoned product session to simplify directory selection. It does not import an ordinary CLI token cache. Its own browser-login settings and selected subscription are stored in an isolated application configuration. It does not create your subscription, signing account, certificate profile, or role assignment, and does not automatically grant itself signing permissions. 5. Persistent saved session and security boundaries By design, closing the application keeps its saved session for the current Windows account. Azure CLI manages access and refresh tokens, account metadata, and configuration in the application-owned cache. Microsoft's MSAL-based Azure CLI stores its token cache encrypted on Windows. Other metadata, such as tenant identifiers, profiles, configuration, logs, and acceptance records, is not all encrypted. The application additionally restricts its login directories to the relevant Windows security identifier, local Administrators, and SYSTEM through protected access-control lists. Encryption and access controls do not prevent every compromise. Someone using the same Windows account, malicious code with sufficient privileges, or an administrator may be able to use or access the authorization. Use persistent sign-in only on a trusted, secured computer. The application has no fixed seven-month or other guaranteed session lifetime: Microsoft, tenant policies, password or account changes, or an administrator can require sign-in again or revoke authorization at any time. Private certificate keys are managed by Microsoft's service; this application does not export a certificate private key or distribute a pre-authorized publisher account. Select Sign out of this program to delete the current application's authorization cache. Its non-secret remembered tenant may remain to simplify later sign-in. Use another account / directory also requests removal of that remembered tenant. These actions do not clear browser cookies, sign Windows or Office out, or delete a separate ordinary Azure CLI profile. They remove local application authorization; they are not a global Microsoft token-revocation command. Use Microsoft's account and tenant security controls when global revocation is needed. 6. Files, backups, hashes, and reports You explicitly choose one file or up to 50 files. A single file returns to review before signing. Confirming a multi-file selection starts ordered, sequential signing using the selected certificate profile, without per-file PDF reports. Supported selection filters include .exe, .dll, .msi, .msp, .msm, .cab, .cat, .sys, .ocx, .cpl, .efi, .scr, .appx, .appxbundle, .msix, .msixbundle, and .ps1. Selection does not guarantee that every format, package, driver, or service policy permits signing. Files of 4 GB or more, the running application itself, and files with an existing Authenticode signature status other than NotSigned are rejected. For each file, the program reads its bytes and metadata, calculates a SHA-256 fingerprint, creates an adjacent uniquely named _UNSIGNED_BACKUP_ copy, and verifies the backup hash. SignTool then changes the selected original in place. The program verifies the resulting signature, certificate chain, timestamp, and hashes. If signing or verification fails before completion and the original changed, it attempts recovery from the verified backup. Recovery can fail because of storage, permissions, locks, or concurrent changes; review any failure message and retain independent backups. Cancellation does not undo already completed files in a batch. A successfully verified single-file operation attempts to create a three-page PDF in the adjacent ArtifactTrust Pro GUI Signing Reports folder. The report includes file and backup paths, sizes, hashes, publisher and certificate information, timestamp details, selected signing resources, correlation information, and tool versions. A PDF-generation failure does not undo a successfully verified signature. Opening a report delegates to your Windows-associated PDF application; printing and its spool files are handled by your PDF viewer and Windows. Signed files, unsigned backups, and PDF reports remain until you remove them. They may contain personal names, organizational identity, paths, or commercially sensitive metadata. This application's public certificate signature makes the certificate's publisher identity and certificate information available to recipients of the signed file. Review that identity before distributing software. A report records checks at the time of operation; it is not an independent audit, a malware scan, or a guarantee of future certificate validity or software safety. 7. Network communications and recipients The signing workflow sends a digest through Microsoft's signing client rather than uploading the complete selected file to the publisher. Microsoft receives authentication requests, account and tenant context, subscription and signing-resource identifiers, selected certificate-profile information, signing digests, correlation identifiers, and necessary request data. Microsoft and network services can also observe connection information such as IP addresses and process service/security logs under their own policies. The application uses Microsoft authentication and resource-management services, configured HTTPS Artifact Signing endpoints ending in .codesigning.azure.net, and the Microsoft timestamp service at http://timestamp.acs.microsoft.com. The timestamp request uses Microsoft's published HTTP endpoint; its returned timestamp is cryptographically verified. Windows certificate-chain and revocation checks may contact certificate-authority services. Browser single sign-on and tenant security policies are controlled by Microsoft and your administrator, not by this application. This release includes no publisher-operated file-upload service, advertising SDK, behavioral analytics, usage telemetry, or automatic upload of application diagnostics to AI Creations Now Software Development. This does not mean Microsoft tools send no telemetry: Azure CLI supports Microsoft's own usage data collection, and this application does not disable that collection. Microsoft components, Windows, browsers, security software, and the Store may process their own diagnostics. Consult their privacy notices and settings. Microsoft service data can be processed in locations described by its applicable contracts; this application does not promise exclusive storage in your country. 8. Local storage and retention The following locations explain the actual implementation. Windows may resolve these environment-based paths differently on your computer. Some internal names retain an earlier product identifier for upgrade and cleanup compatibility; they do not change the current product name. • Application files and installed copies of this policy and third-party notices: the chosen application directory, with documents in Documentation. • Persistent product authorization: %ProgramData%\AICN-AzureSigning-Login-5F16685C-\AzureConfig; the parent also contains remembered-tenant.txt. Retained until Sign Out, uninstall, or local deletion; Microsoft can invalidate tokens earlier. • Product temporary work: %WINDIR%\Temp\AICN-AzureSigning-Session- and AICN-AzureSigning-Installer-. These can contain metadata, command diagnostics, and extracted prerequisite packages. Normal cleanup is best effort. • Consent record: %LOCALAPPDATA%\AI Creations Now\Azure Signing Program\privacy-installation-acceptance.txt. It contains the agreement version and hash, UTC acceptance time, Windows account name, and Windows security identifier. It is retained across uninstall and reinstall; it contains no selected file bytes, password, MFA response, or signing private key. • Shared CLI extension: the Windows profile used to run the application, under .azure\cliextensions. Ordinary CLI account configuration is separate from the product authorization above. • Backups and reports: beside selected files as described in section 6. Runtime extraction by the self-contained .NET host, Windows setup logs, and fatal-startup diagnostics may also remain in Windows or user temporary locations. Logs may include local paths, account/resource identifiers, errors, tool output, system versions, and timestamps. Not every diagnostic or third-party log is encrypted or automatically removed. Review and redact sensitive information before voluntarily sending a screenshot, report, or log for support. Do not send token caches, passwords, MFA codes, or private keys. The desktop program does not automatically send support material to the publisher. 9. Uninstall and limits of deletion Close all running copies before uninstalling through Windows Settings. Before deleting program files, the elevated uninstaller invokes the product cleanup helper. It verifies and removes the exact product-owned persistent caches for all recognized Windows security identifiers, the exact legacy %ProgramData%\AICN-AzureSigning-State-5F16685C directory, and recognized product temporary-session directories. It checks names, permissions, redirection, and live-session locks. If that cleanup cannot be verified, uninstall stops and reports the failure rather than claiming successful credential removal. Successful uninstall removes the dedicated application directory, registered shortcuts, and uninstall entry. It leaves Microsoft prerequisites and the shared CLI extension installed. It preserves ordinary .azure account caches, browser sessions, Windows/Office sign-ins, acceptance records, and signed files, backups, or reports outside the application directory. Abandoned prerequisite-extraction folders, runtime caches, system/setup logs, security-tool records, and third-party service records may remain. Uninstall is targeted local deletion, not secure disk erasure, remote deletion, or global account revocation. Backups and synchronization services may retain earlier copies independently. 10. Your choices, requests, and responsibilities You can decline before normal readiness checks or signing begins, choose which files to submit, cancel operations, sign out, stop using the service, or uninstall. Review local files and reports with your Windows tools and manage Microsoft's data or account permissions through Microsoft and your organization. Requests concerning the publisher or information you voluntarily supplied for support can be directed through the publisher contact information at https://AICreateNow.com or the product's Store support listing. Do not include credentials in a request. Applicable access, correction, deletion, objection, and complaint rights depend on your jurisdiction and the organization controlling the relevant data; this agreement does not waive those rights. You must have authority to use the computer, install the components, access the Microsoft resources, and sign the selected files. Protect your backups, accounts, MFA methods, tokens, and signing permissions. This developer tool is not intended for children; do not provide children's personal data for support or use an account contrary to the relevant provider's age rules. Your Microsoft subscription and signing charges are separate from any purchase of this application. Microsoft can deny signing, revoke certificates, suspend accounts, or change service requirements. No SmartScreen reputation, Store approval, uninterrupted service, or protection against account restrictions is promised. 11. Source builder and third-party terms The optional source-and-builder ZIP is a development tool. Building it requires internet access to collect dependencies and restore the build environment. The builder can offer installation of the .NET 8 SDK after approval, uses an installed Inno Setup compiler, performs validation, and uses the developer's separately authorized signing account for internal artifacts. Builder workspaces, signing sessions, caches, and logs are separate from the installed customer's application state and are not removed by the application uninstaller. No developer credentials are included in the generated distributable. The final outer installer is left for the developer to sign separately. Read THIRD-PARTY-NOTICES.txt in the installed Documentation folder. Component licenses, accompanying copyright notices, and applicable Microsoft service terms remain in force. Purchasing this application does not purchase Microsoft signing services or expand redistribution rights. Nothing here overrides statutory warranties or remedies that cannot be excluded. This notice describes the program's behavior; it does not certify a user's distribution, legal compliance, or Microsoft approval. 12. Policy updates and acceptance This is agreement version 2026.10.10.1, effective October 10, 2026, for ArtifactTrust Pro GUI 3.1. A changed agreement version or text hash requires renewed acceptance once for the Windows account. The current agreement remains available through the application's privacy review and the installed Documentation folder. Existing acceptance of the previous product policy does not accept this revised text automatically. By checking I have read and agree and selecting Accept and continue, you authorize the described readiness checks; installation or repair of bundled Microsoft components when required; Microsoft authentication and use of its resulting saved session; discovery of existing signing resources; inspection, backup, signing, and verification of files you select; single-file PDF reporting; and the disclosed local storage. This is permission for those requested functions, not permission for undisclosed advertising or publisher analytics. Selecting Decline and exit or closing the acceptance window exits before normal prerequisite inspection or installation, Microsoft sign-in, resource discovery, file selection, or signing. Windows has already loaded the application and may have handled elevation and runtime extraction; declining does not uninstall Setup's files. 13. External reference notices Microsoft Privacy Statement: https://www.microsoft.com/privacy/privacystatement Microsoft Product Terms: https://www.microsoft.com/licensing/terms/ Microsoft Artifact Signing documentation: https://learn.microsoft.com/azure/artifact-signing/overview Microsoft Artifact Signing pricing: https://azure.microsoft.com/pricing/details/artifact-signing/ Azure CLI authentication and token-cache documentation: https://learn.microsoft.com/cli/azure/msal-based-azure-cli Azure CLI data-collection settings: https://learn.microsoft.com/cli/azure/azure-cli-configuration Publisher and contact entry point: https://AICreateNow.com External pages can change independently. Those providers are responsible for their current statements and terms. This product's bundled policy remains the disclosed statement for this release until replaced by an accepted update. END OF AGREEMENT