PRODUCT GUIDE
install update remove
Local software · limited supported scope
Local installation, update, and removal — Early Access
CryptoProof 0.1.6. The supported environment is Windows 11 x64 with independently installed official CPython 3.13.16, including venv/pip. Use the pinned openpyxl 3.1.5 and et_xmlfile 2.0.0 wheels supplied in the ZIP. The package metadata permits broader Python versions, but those are not supported by this initial offer. Python is not bundled. Processing and the documented wheelhouse install work offline.
Verify a downloaded candidate
The local review bundle has a wheel under wheel/; SHA256SUMS.txt sits beside the review ZIP. Compare the SHA-256 for the exact wheel and bundle before installing. From the extracted bundle root on PowerShell:
Get-FileHash .\wheel\cryptoproof_local-0.1.6-py3-none-any.whl -Algorithm SHA256
The displayed hash must match the corresponding line in SHA256SUMS.txt obtained from a trusted release channel. A checksum detects accidental changes; without an authenticated release channel it does not prove publisher identity. Obtain the ZIP and published checksum only from the authenticated Exactloom Works purchase/delivery channel once downloads are enabled.
Install
Use a dedicated Python virtual environment. From the extracted bundle root, the following install uses only the included wheels and does not query a package index:
python -m venv .venv
.\.venv\Scripts\python.exe -m pip install --no-index --find-links .\wheelhouse .\wheel\cryptoproof_local-0.1.6-py3-none-any.whl
.\.venv\Scripts\python.exe -m cryptoproof --version
wheelhouse/ contains the exact public PyPI wheels listed in third-party notices. Your organization's package policy may require its own validation or approved copies. The RELEASE_MANIFEST.json and external SHA256SUMS.txt record hashes, but only a trusted distribution channel can authenticate their origin. CryptoProof's core commands make no runtime network request. Keep private CBOMs, questionnaires, mappings, owner-answer libraries, and output outside a shared or public download directory. Run the Quick Start from the extracted bundle root after installation.
Update
Review the new version's supported scope and checksum, back up your mapping and owner-answer JSON files, and install the new wheel into the dedicated environment. Re-run a synthetic preflight/compile and compare the result before using it for a customer pack. Rule behavior and output may change between versions; do not silently replace an in-progress reviewed draft. No automatic updater exists.
Remove
In that virtual environment, run python -m pip uninstall cryptoproof-local (or use the environment's Python executable). Remove a dedicated virtual environment only after confirming it is the one created for CryptoProof. The tool does not remove your CBOMs, customer workbooks, answer libraries, drafts, final ZIPs, or logs; review and remove those local files according to your own retention policy. No cloud account or remote data deletion is involved.