SHA256 and signatures
A SHA256 digest fingerprints a specific file. If your downloaded EXE hashes to the value published for that build, the bytes match the catalogued package. Publisher Authenticode signatures (when present on Bitsum builds) further confirm who signed the binary. Always hash the file you actually saved.