Android may warn about installing from outside an app store, tap Install anyway and grant Allow from this source once. The APK is signed; you can verify its checksum below.
Verify this download
After downloading, confirm the file's SHA-256 fingerprint matches the value here. If it doesn't match exactly, delete it and download again, don't install it.
New phones · arm64-v8aloading…
Older phones · armeabi-v7aloading…
On a computer: certutil -hashfile wingpost-arm64-v8a-release.apk SHA256 (Windows) or sha256sum (Mac/Linux). On a phone, any file-checksum app works.