Releases are GPG-signed and Windows binaries Authenticode-signed
Catalog row in Vendor License Rules · Cited
- Kind
- Policy
- Statement
- Keys page (Appendix F): the developers create GPG signatures for all PuTTY files distributed from the web site, with separate Release, Snapshot, Secure Contact and Master keys (2026 issue); since 0.67 the Windows executables and installer also carry Authenticode signatures. FAQ A.9.20: release, snapshot and pre-release builds each have their own checksum files, and installer-version executables differ from the standalone ones. (Undated; as published on 2026-09-27)
- Applies when
- Verifying integrity and origin of PuTTY copies before approval or deployment.
- Applies to
- PuTTY release files (installers, executables, source archives)
- Aliases
- GPG; PGP; Authenticode; checksums; code signing