Security and verification

Every download leaves a clear trail.

This is how an app gets from its publisher to a download button, and how you can check it yourself.

How files are published and checked

  1. Find the publisher. Each app is traced to its official source. The publisher and website are shown on every app page.
  2. Check the release. Version, platform and file type are reviewed. Files are published exactly as received: no wrappers, no bundled installers.
  3. Record a checksum. A SHA-256 checksum is calculated from the file on our server and shown next to every download.
  4. Serve and re-check. Files are served straight from SOFTGIT. The catalog is re-scanned continuously and every change updates the "last check" time.

Verify a download yourself

Compare the checksum on the app page with the one calculated on your computer:

Linux:    sha256sum <file>
macOS:    shasum -a 256 <file>
Windows:  Get-FileHash <file> -Algorithm SHA256

If the values differ, do not run the file and please let us know.

What we do not do

  • We do not wrap downloads in installers or download managers.
  • We do not inject advertising or tracking into files.
  • We do not use cookies for visitors; statistics are anonymous and aggregated.

← Back to all programs