Quick idea regarding that: (might be stupid since I don’t know the technicalities of TS)
Would it be possible to implement some sort of certificate like used for HTTPS in browsers?
We probably won’t need to go as far as building an entire certification-structure with root-certs etc. since we’re “only” talking about one closed-source program, but the ability to create child-certificates might be useful for hosting providers in that regard (so they have their primary cert that you could approve on your client to trust all child-certificates used on servers hosted by them).