Bỏ qua đến nội dung chính
D’AUBE SONNTAGARTIFACT VERIFICATION CENTER

LOCAL FILE · SHA-256 · RECEIPT-BOUND

Verify the bytes.
Know what that proves.

Compare a local file against an evidenced SHA-256 digest without uploading the file. Official installer options appear only when the public distribution authority exposes an installer plus a parseable checksum receipt.

LOCAL SHA-256 VERIFIER

Verify bytes without uploading the file.

A SHA-256 match verifies byte integrity against the supplied digest. It does not by itself verify platform code signing, notarization, store publication, malware absence, regulatory approval or product safety.

02 · VERIFICATION LADDER

One green check must never imply five different assurances.

D’AUBE separates evidence layers so a checksum match cannot silently become a signature, store, security or regulatory claim.
V0
Byte integrity

SHA-256 of the local file equals the published digest.

V1
Release provenance

Digest and artifact are bound to a governed public release record.

V2
Code signing

Requires platform-specific signature/certificate evidence; SHA-256 alone is insufficient.

V3
Store / notarization receipt

Requires the actual provider receipt when the distribution claim depends on it.

V4
Supply-chain evidence

SBOM, VEX and build provenance are surfaced only when attached to the release.

V5
Independent assessment

External security/conformity claims require separately verifiable external evidence.

03 · SECURITY BOUNDARY

A matching digest is necessary evidence, not universal trust.

Use the Security Center, Trust Center and platform signature/store evidence together when the risk level requires stronger assurance.
D’AUBE SONNTAG · Artifact Verification CenterVerify locally · interpret evidence precisely