Since 14.5, we can see some visualization mods are signed by "Verified with root certificate from: N/A - Verified by pinned certificate", these kinds of certificates are not verified in the normal way, aka require root certificate and intermediate certificate to build the certificate chain, or make http request to ocsp server to check revocation status. These certificate can be trusted by groups and all mods signed by them can be utilized seamlessly even in a environment without internet access.
As per support these kinds of certificates are embedded in the product and not customizable.
Please allow to add any certificates we own as "pinned certificate" to our Spotfire environment at our own risk.
It's the best way for us to use visualization mods.