I am not familiar with how it works on Windows, but if it works like Android, the devs will need to sign their binaries, and this signature will need to be whitelisted. So gatekeepers couldn't vet them if they currently do not sign their binaries (idk whether they do).