macOS / Linux
shasum -a 256 /path/to/download
shasum -a 512 /path/to/downloadVGNA Client transparency
We publish the exact release hashes, signing identities, scanner findings, permissions, and data use—including limitations and warnings. No scanner can prove software is harmless.
Current public files
Loading evidence…
VirusTotal is the primary public scanner shown here. Its verdict links open results hosted by VirusTotal and keyed to the exact file or download URL it evaluated. URL reputation and exact-file results are labeled separately.
See additional security checks and technical reports →VGNA-run ClamAV, MobSF, Syft SBOM, and Grype results are available separately and clearly labeled as non-independent.Tamper-evident provenance
The release server signs the exact hashes for downloads, MobSF summaries, SBOMs, and vulnerability reports. Anyone can download the manifest, detached signature, and public key and verify them without trusting this page's JavaScript.
Independent verification
A matching SHA-256 proves your bytes are identical to the file named above. It does not, by itself, prove the software is safe. Compare the complete value—never only the first few characters.
shasum -a 256 /path/to/download
shasum -a 512 /path/to/downloadGet-FileHash .\download.apk -Algorithm SHA256
Get-FileHash .\download.apk -Algorithm SHA512Android releases are signed by the same permanent VGNA certificate. SHA-256 fingerprint: 28358dab239dd992b11fc0da510e774f56e70428f50ce519e12c5aabfc038c40. iOS 1.05 is signed by Apple Distribution certificate fingerprint cc5f7e7cd4c986555c7c133438c284ead75fda82cf2208391c750e79fa8be99e.
Scanner honesty
VirusTotal asks engines and reputation systems about the download URL. A 0/92 URL result is useful, but it is not an exact-file verdict.
VirusTotal's file result is tied to the SHA-256 of the exact APK or VGNA-controlled iOS dylib. The iOS IPA is above VirusTotal's file-upload limit, so the page does not pretend its URL result is an exact-file verdict.
Privacy record
| Data | Purpose and visibility | Retention |
|---|---|---|
| Discord user ID and current server display name | Authenticate VGNA membership, bind one client installation to an account, and show the Discord name in VGNA in-game team chat. Administrators can see account/client bindings; chat participants see the display name. | Installation/account binding has no automatic expiry while it remains authorized. OAuth login sessions expire after 10 minutes. |
| Vainglory player UUID, current in-game handle, room/match IDs, selected mode | Correlate the correct player and bot match, detect queue/draft/match transitions, and prevent false client-compliance findings. Administrators can inspect correlation evidence. Match/player results may appear publicly on VGNA Pro. | Detailed client and MITM event history: 90 days. Current binding/presence and match records can remain longer; competitive match history is retained. |
| Client platform, version, random install ID, heartbeat and connection state | Version enforcement, reliability, ready checks, dodge evidence, and reconnect/disconnect handling. No advertising profile is created. | Heartbeats refresh current presence; history stores at most one heartbeat per 60 seconds and is retained 90 days. |
| Replay chunks and parsed match stats | Match settlement, VGNA Pro stats, replay downloads, and near-live spectating. Replays contain gameplay events and player handles—not camera, microphone, contacts, or precise location collected by VGNA code. | Rolling 20 GiB server archive. Oldest inactive games are evicted first; live uploads are protected. Competitive results derived from replays remain in match history. |
| VGNA in-game team-chat messages | Deliver authenticated team chat to players in the same room. Sender labels resolve to Discord display names, not in-game names. | 2 hours, then deleted by the server cleanup path. |
| iOS enrollment profile: device UDID, device name/model and OS details | Add the device to Apple's registered-device list and prepare a signed IPA. Signing administrators can access enrollment and signing status. | Kept in signing/enrollment records while registration and support history are needed; no automatic deletion period is currently promised. |
No ad or behavioral analytics SDK is added by VGNA. VGNA-added code sends client identity/telemetry to client.vgna.net and replay/chat/live data to replays.richardtravel.com. The original Vainglory game still makes its own game-service connections.
Platform permissions
The final APK declares Internet and network/Wi-Fi state, notifications and foreground data-sync service, wake/vibrate, Bluetooth, audio settings and microphone recording, plus legacy max-version account/task permissions and original Google Play license/billing/push permissions. The microphone declaration comes from the stock game's voice/chat capability; VGNA-added telemetry does not upload microphone audio. Optional microphone access may be denied. The VGNA build removes obsolete broad read/write external-storage declarations, so it does not request broad photos/media access.
The signed 1.05 package still contains original Vainglory usage-description strings for location, camera, microphone, and photo-library features, plus an inherited arbitrary-network-load setting. Those declarations are disclosed here; they are not evidence that VGNA uploads those categories. You may deny optional OS permission prompts. Removing unnecessary legacy declarations is a hardening item for a future signed release.
Responsible reporting
Do not post access tokens, device identifiers, private replay files, or exploit details publicly. Join discord.gg/vgna and contact Trogdor or Lynx privately with the affected version, platform, checksum, and reproduction steps. We will preserve the report and publish a corrected artifact and new evidence when needed.