SHA-256 of the local file equals the published digest.
LOCAL FILE · SHA-256 · RECEIPT-BOUND
Verify the bytes.
Know what that proves.
Compare a local file against an evidenced SHA-256 digest without uploading the file. Official installer options appear only when the public distribution authority exposes an installer plus a parseable checksum receipt.
Verify bytes without uploading the file.
A SHA-256 match verifies byte integrity against the supplied digest. It does not by itself verify platform code signing, notarization, store publication, malware absence, regulatory approval or product safety.
02 · VERIFICATION LADDER
One green check must never imply five different assurances.
D’AUBE separates evidence layers so a checksum match cannot silently become a signature, store, security or regulatory claim.Digest and artifact are bound to a governed public release record.
Requires platform-specific signature/certificate evidence; SHA-256 alone is insufficient.
Requires the actual provider receipt when the distribution claim depends on it.
SBOM, VEX and build provenance are surfaced only when attached to the release.
External security/conformity claims require separately verifiable external evidence.
03 · SECURITY BOUNDARY