Trust

Security

How to check that your copy of DiffScope is genuine, what the app does (and does not) do on your computer, and how to report a security problem.

Applies to v1.0.1 Updated Oct 2026

Verify your download

Every release is published with its SHA-256 checksum. If the checksum of the file you downloaded matches, the file is byte-for-byte the one we released and has not been damaged or tampered with on the way.

  1. Download DiffScope-1.0.1-win-x64.zip from the download page. Only download DiffScope from this website: we do not publish it anywhere else.
  2. Open PowerShell or Command Prompt in the folder that contains the zip and run one of these commands:
PowerShell
Get-FileHash .\DiffScope-1.0.1-win-x64.zip -Algorithm SHA256
Command Prompt
certutil -hashfile DiffScope-1.0.1-win-x64.zip SHA256

The result must match this SHA-256 exactly (upper or lower case does not matter):

SHA-256
ee57ff27e5a2ee1db9b45608ddc4c4f476599f63d7232be61a462b28528688ff

If the hash does not match

Do not extract or run the file. Delete it and download it again from this website. If it still does not match, please report it (see below).

Why DiffScope.exe is not code-signed

Windows programs can be signed with a code-signing certificate that names the publisher. DiffScope’s executable is not signed yet, because a certificate is not in place. This has two visible effects:

  • Microsoft Defender SmartScreen shows “Windows protected your PC” the first time you run it. Click More info › Run anyway.
  • The file properties show no digital signature, and Windows names the publisher as “Unknown”.

A signature would tell you who published the file. Until DiffScope is signed, the SHA-256 checksum above is how you confirm that your copy is exactly the file published on this website. When code signing is added, it will be announced in the changelog and this page will be updated.

How the app is built

DiffScope reads the files you give it, shows the differences and writes only the files you save. It is designed to do nothing else.

No network access

The app contains no networking code: no telemetry, no update checks, no crash reporter, no licence server. It works the same on an air-gapped machine.

Locked-down window

The user interface runs in Chromium’s sandbox with context isolation on and Node.js integration off. It can only reach the app through a small, fixed set of functions.

Strict content policy

A strict Content Security Policy allows only the app’s own scripts and styles and blocks every network connection, so file content can never load or run outside code.

Files and settings

Files are only written when you save. Settings are kept locally in %APPDATA%\DiffScope. No admin rights, services or registry entries are needed.

Security fixes, including updates of the bundled Electron runtime, are listed in the changelog.

Supported versions

Security fixes are made in the latest release only. Please keep DiffScope up to date by checking the changelog from time to time; the app does not check for updates itself, because it never goes online.

VersionSecurity fixes
Latest release (currently 1.0.1)Yes
Older releasesNo, please update

Reporting a vulnerability

If you believe you have found a security problem in DiffScope or this website, please report it privately rather than posting it publicly, so that it can be fixed before others can misuse it.

Private reports

A contact address is coming soon. Until it is published here, please keep the details private.

A useful report includes:

  • the DiffScope version (.\DiffScope.exe --version | Write-Output) and your Windows version;
  • a description of the problem and its impact;
  • steps or sample files to reproduce it, with nothing confidential in them;
  • whether you would like to be credited when the fix is released.

Please do not access other people’s data, disrupt the website or download service, or run automated scans against it.

Bug bounty

DiffScope is free software and there is no bug bounty programme: we cannot offer payment for reports. With your permission, we are happy to thank you by name in the release notes of the fix.