Security & Verification
Know what you run.
Know where it comes from.
Motion Graphics Creator by Visual Standard separates the public installer from the private commercial runtime. This page documents that boundary and the official public identities.
01 / Identity
Publisher: Visual Standard.
The public product name is Motion Graphics Creator by Visual Standard. The official npm package is @visualstandard/install.
02 / Official domains
Two domains. Two clear roles.
- visualstandard.io
- Public website, installation guide, product documentation, legal pages, and this policy.
- install.visualstandard.io
- Official public installer/bootstrap endpoint maintained by Visual Standard.
Do not enter a license key on a lookalike domain or paste it into a web form that is not part of the documented Visual Standard flow.
03 / Public package
The npm package is not the engine.
@visualstandard/install is a small, dependency-free installer client with no npm lifecycle scripts. It does not contain the creative runtime, customer projects, reference library, private signing key, storage credentials, or license database.
Verify the exact release on npm and inspect its public source on GitHub before running it.
The current public installer is 1.0.14; the separately delivered product runtime remains 1.0.15.
The linked npm release provides the registry integrity metadata for the audited public package.
04 / Private runtime delivery
Activation comes before download.
- The installer requests license activation for the current Mac.
- A valid signed entitlement is checked against the configured channel and device.
- The service authorizes an eligible private release and issues a short-lived download URL.
- The installer verifies version, size, SHA-256, and archive safety before applying the release.
The private commercial runtime is never published inside the npm installer package or on the public installer site.
05 / Local boundary
Product files stay inside named locations.
The runtime is installed under ~/.visual-standard/motion-graphics-creator. Claude Code receives only the managed Visual Standard skill and visual-* commands described in the installation guide. Unrelated Claude Code files should remain untouched.
06 / Reporting
Use the official channels.
For purchase, activation, installation, or product support, email support@visualstandard.io. Report security vulnerabilities privately through the GitHub security advisory form. Never send complete license keys, entitlement tokens, payment details, or private project files.

