DEVI

Trust and Security

How the published tool handles evidence, how a download is checked, and where to report a vulnerability.

How DEVI Validate handles evidence

DEVI Validate is a free, offline, read-only evidence hash checker. It recomputes hashes and compares them with values from another tool or process.

  • SHA-256, SHA-1, and MD5
  • Sum files, CSV, and FTK Imager logs
  • Match, Mismatch, Missing, and Extra results
  • A PDF verification record named by hash
  • A built-in self-test

Each lab should validate it under its own procedures. No certification is claimed.

Windows. Requires .NET 8.

How a download is checked

The published SHA-256 for this download is c790b871789811aad65cac0a2a46e630460c3b14d0a8dc9b0af69a9e5362866b. A checksum file is published beside the zip.

On Windows, either command prints a hash of the file you downloaded. Compare it with the value above.

Get-FileHash .\DEVI-Validate-0.1.0-win-x64.zip -Algorithm SHA256
certutil -hashfile DEVI-Validate-0.1.0-win-x64.zip SHA256

No install needed. Unzip and open app\DEVI-Validate.exe. Windows may show a SmartScreen warning because the app isn't signed yet (More info, then Run anyway).

The iPhone app

The iPhone app ships with no analytics, no telemetry, no crash reporting, and no tracking or advertising software. That statement is about the app. This page does not make it about DEVI Validate.

The app security page describes access, where information lives, and how to report a vulnerability.

Source code

Source code will be published under Apache-2.0.

Reporting a vulnerability

Email contact@deviops.app. Please report a vulnerability before disclosing it publicly. The app security page states how a report is handled.

A machine-readable contact file is published at /.well-known/security.txt.