Trust Center

Verify a CIP Sentry release

CIP-010 R1.6 asks you to verify software identity and integrity before a baseline change. Here is how to verify every CIP Sentry release, and the hashes to check against.

How CIP Sentry protects its releases

  • Published hashes. The SHA-256 hash of every release file is listed below and in the release notes sent to customers.
  • Two channels. Hashes are published here and also emailed to each customer's designated contact, so an attacker would have to compromise both to fool you.
  • Direct delivery. Releases are delivered directly to customers, never through third-party download mirrors.
  • On our roadmap: Authenticode code signing of Windows installers and cryptographically signed update packages that the updater verifies automatically.

Verify a file on Windows

Open PowerShell in the folder with the downloaded file and run:

Get-FileHash .\CIPSentry-8.16.1.zip -Algorithm SHA256

Compare the result with the hash below, character for character. Record the comparison with your CIP-010 change record as your R1.6 evidence.

Release hashes

Release hashes are published here with the first general-availability release. Customers receive them directly with every release. Questions: security@cipsentry.com