There have been no modifications to any of the packages used, no adware, trojans, toolbars, etc. This is simply a tool to help people get around censorship."
I have no reason to believe that it contains any viruses, but if it did, they'd obviously say the same thing.
The "captology" of the site doesn't convey enough reputation. CV's, history and some support / contact details. Also an easy way to build from source.
The bigger issue is making build environments reproducible such that it's possible to arrive the same binaries deterministically, and therefore proving that there's nothing outside of the code. It's possible, but it's tricky, especially with stack randomization and the other minutia of slightly different configs. More apps like the opensuse build service, brew bot and travis might help.
Also removing the affiliate link from the first question of the FAQ would help make the project more credible. Right now, the whole thing looks like an ad for something that actually provides better privacy (VPN).
I know some projects do deterministic builds using a pre-made VM. There are Bitcoin bots that periodically build the client and check it against official binaries to detect tampering.
There have been no modifications to any of the packages used, no adware, trojans, toolbars, etc. This is simply a tool to help people get around censorship."
I have no reason to believe that it contains any viruses, but if it did, they'd obviously say the same thing.