Is there a gpg signature verification for the initial operating system download?

I have read that OTA updates do not have a verification signature, but what about initial setup download file? Normally would check signatures before installing anything related to financial matters… I will be installing from a Windows pc

Thanks.

Since no response, I take it it’s a “no”?