executable files ("desktop" apps) released by Cloanto since 1999 have been signed and timestamped with Microsoft Authenticode technology. In 2014
this was extended to include dual SHA-1 and
When you right-click a Windows executable file (e.g. files ending in .exe,
or .dll) you can select Properties, then Digital Signatures and click on
Details to verify the digital
signature of the file. This allows you to confirm the publisher, the
signature time, and the integrity of the
file. Under Details, the signer name should be "Cloanto Corporation"
and the dialog should say "This digital signature is
If you selected Properties/Digital Signatures on
an executable file and noticed an error message, or no digital signature at
all, or a digital signature not signed by Cloanto Corporation, a verified Nevada, USA, corporation, this may mean that the file is either incomplete or corrupt.
This may have been caused by a download problem, or, for example, by a
malicious modification (a virus program, an
unauthorized download site adding their
adware or malware, etc.), and we recommend
that you download the software again.
Internally, Authenticode uses the SHA-1 and
SHA-256 cryptographic hash functions to
confirm file integrity. These are more
secure than MD5-based file "checksums".
Windows Store and Windows Phone apps are
signed and verified automatically by the
respective store mechanisms.