It's okay because it's secured by using HTTPS.
$ gpg --verify software.tar.gz gpg: Signature made Fri 25 Sep 10:20:57 EDT 2015 using RSA key ID 99BD2CF1 gpg: Good signature from "Keith Alexander <keith.alexander@ironnetcybersecurity.com>"
It's okay because it's secured by using HTTPS.