Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SHA-256 can help people detect whether a downloaded dataset file has changed, but a matching hash alone does not prove who published it, when it was published, or whether its contents are accurate. Brazilian data portals can use hashes as one part of a broader trust design that also covers publisher identity, audit logs, interoperability, and lawful disclosure.

What SHA-256 can—and cannot—prove

SHA-256 turns a specific sequence of bytes into a fixed-length digest. A portal can publish that digest beside a dataset file or version. After downloading the file, a reader or automated system computes SHA-256 over the same bytes and compares the result. A match is evidence that the downloaded bytes match the reference digest; a mismatch indicates that they differ.

The comparison only works if both sides hash the same precisely defined file. A change as small as a line ending, encoding, compression, or metadata edit produces a different digest. Portals should therefore state which artifact the digest covers—for example, the downloadable CSV as provided, rather than an abstract dataset whose exported bytes may vary.

A digest is not a signature. Anyone who can replace a file may also be able to replace its displayed hash. SHA-256 by itself does not identify the publisher, establish publication time, or show that the data is true. The ePING reference recommends “SHA-256 ou SHA-512” for hashing and signature use, but it does not prescribe a specific portal manifest or claim that hashing alone makes a service trustworthy. ePING reference

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A practical integrity-check workflow

  1. Define the artifact. Decide whether each digest covers one downloadable file, a compressed package, or another exact byte sequence. Give each published release a stable version identifier.
  2. Compute SHA-256 at release time. Generate the digest from the final artifact after it is ready for publication. If the file changes, publish a new version and calculate a new digest rather than silently updating the old one.
  3. Publish the digest with versioned metadata. Make clear which filename, version, and release the digest belongs to. The exact manifest format and API structure are implementation choices; the cited ePING material does not specify them.
  4. Let readers recompute and compare. A reader can use a local tool that calculates SHA-256, then compare its output with the portal’s published digest. Automated consumers can do the same before importing a file.
  5. Protect the reference and release history. Restrict and audit changes to published files and metadata. Keep historical release records so a reader can distinguish a corrected dataset from an unnoticed replacement.

For stronger provenance, a publisher can digitally sign a statement binding the digest to the release details. That approach ties the integrity check to an identifiable signing key, but depends on sound key custody and appropriate certificate and revocation checks. The applicable signature format and validation policy need to be selected for the agency and use case.

What Brazilian government guidance contributes

ePING is a federal interoperability reference, not a complete portal-security specification. The federal overview says entities in SISP should observe ePING when planning system procurement, acquisition, and updates; adoption by other branches of the Union and other federative entities is optional under the rule described there. The overview links a 2018 reference document, so agencies should confirm the applicable version before procurement or deployment. Federal ePING overview

The ePING reference treats security as preventive and part of the system-development lifecycle. It recommends historical logs that support audits, centralized time synchronization, and mechanisms to protect the authenticity of stored records—preferably digital signatures where possible. Together, these controls address questions a bare checksum cannot answer, such as what changed and when. ePING reference

The federal government describes interoperability as the ability of systems and organizations to work together to exchange information effectively and efficiently. SHA-256 does not create that interoperability. Stable identifiers, open formats where possible, machine-readable metadata, and predictable update practices must be designed separately. Government interoperability overview

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use digital signatures when publisher identity matters

Brazil’s ITI offers VALIDAR, an official service for checking supported digital signatures. ITI says the service identifies the signer or certificate holder and checks whether a signed document was altered after signature. It does not certify that the document’s contents are true. The service page also says submitted document content is not stored or passed to third parties; check current service behavior and supported profiles before relying on it operationally.

VALIDAR is useful for supported signed documents, but it is not a substitute for a portal’s release process, key management, or policy decisions. A production design should decide who is authorized to sign releases, how keys are protected, how certificates and revocation status are checked, and how evidence will remain usable over time. ITI VALIDAR · About VALIDAR

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Make openness compatible with privacy and access rules

Publishing a dataset and verifying its integrity are separate decisions. Before release, an agency should assess whether the information may lawfully be disclosed, considering access-to-information requirements and personal-data protections. The federal interoperability overview places information exchange in the context of LAI and LGPD principles. The Central Bank’s open-data page also refers to LGPD, LAI, federal open-data rules, machine-processable publication, and ePING recommendations. Government interoperability overview · Banco Central open-data page

Hashing personal data does not automatically make it anonymous. If identifiers are predictable or the possible inputs are limited, someone may guess values and compare their hashes. A digest should not be treated as a privacy safeguard or as a reason to publish information that should remain protected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a trustworthy portal should make clear

  • Integrity: which exact file and release the SHA-256 digest covers.
  • Provenance: who issued the release and, where needed, how its signature can be validated.
  • History: how corrections and updates are versioned and audited.
  • Interoperability: how stable identifiers, formats, metadata, and update practices support reuse.
  • Disclosure: why the dataset is publishable and how personal data and access rules were considered.

For a specific Brazilian agency, confirm the current applicable ePING and ICP-Brasil policy versions, the signature profile, the dataset’s legal basis for publication, and operational controls. The framework and services cited here provide useful reference points, not a compliance certification for an individual portal.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.