Arqivexa / Security

Verify before you run

Arqivexa security and verification for the 0.5.0 Stable release.

Use the published checksum and release evidence before running setup. Arqivexa also exposes its current signing, update, diagnostic, and data-safety boundaries instead of hiding them.

01

Installer identity

Match the exact published SHA-256.

SETUP SHA-256
b89a650b96e3dfe981a28b2ff13888cbfef30ec8873f2af77955a1ead98fb46a
PowerShellGet-FileHash .\CFS-0.5.0-Stable-Setup.exe -Algorithm SHA256

Signing disclosure

The 0.5.0 installer and shipped executable payloads are Authenticode-signed and RFC 3161 timestamped with the existing CFS self-signed publisher certificate. Windows may still show Unknown Publisher or SmartScreen until that exact leaf certificate is explicitly trusted.

Arqivexa never installs a general root certificate authority.

02

Updates

Updates are explicit and verified.

HTTPS manifest

The release checks a public update manifest over HTTPS.

No silent install

An update is not downloaded or launched without user approval, and elevation is requested explicitly when required.

Hash and signer checks

Downloaded setup files are checked against the expected SHA-256 and pinned publisher identity before they are offered for installation.

03

Archive safety

Persistence is designed around validation and recovery.

Validated candidate

Arqivexa validates a new candidate archive before it replaces the current archive.

Retained predecessor

A validated same-volume predecessor is retained across the transaction boundary until the promoted archive has been reopened and validated.

External-change detection

Arqivexa checks archive identity and avoids silently overwriting an archive that changed outside the managed session.

04

Privacy and diagnostics

Normal archive work stays local.

Local archive processing

Archive contents are not uploaded for normal compression, mounting, extraction, saving, recovery, or update checks.

Sanitized diagnostics

Local logs are designed to avoid archive contents, filenames, credentials, access tokens, and certificate private keys. Review logs before sharing them publicly.

Reporting is optional

When a reporting endpoint is configured, bounded structured failure reports can be disabled in Settings and reporting failures do not block local work.

Read the privacy and diagnostics policy ↗

Important boundary

Arqivexa is not encryption or backup software.

  • Keep an independent backup
  • Use Windows access controls or separate encryption when confidentiality is required
  • Do not rely on a retained predecessor as disaster recovery
REPORTING

Found a security-sensitive problem?

Do not publish credentials, private archives, file contents, signing material, or an exploit that could put users at immediate risk. Request a private contact channel without including sensitive details in the public request.