Know what you're running.
PC Dyno is intentionally transparent about what the beta can verify and what it cannot.
Official downloads
Use the installer linked from pcdyno.com/download. Each published release includes a SHA-256 hash so you can verify that the file you received matches the release PC Dyno published.
Unsigned public beta
Early beta builds may be unsigned, which means Windows can show “Unknown publisher” or a SmartScreen warning. A cryptographic release hash helps verify file integrity, but it is not a replacement for trusted code signing. PC Dyno intends to move to a verified signing identity for later releases.
Raw hardware identifiers stay local
Stable machine identity is generated locally from available system identifiers. The selected identity is hashed before upload; the raw serial or UUID used to create that hash is not sent as the fingerprint value.
GPU identity sanity check
The lightweight GPU dyno records the graphics renderer used for the test and compares it with the GPU model Windows reported. A mismatch is flagged. This is useful evidence, but it is not cryptographic attestation and a deliberately modified client can still falsify a submission.
Report API
The report ingest endpoint is public by design because a secret embedded in a desktop app would not remain secret. The server instead validates the payload, limits request size, applies rate limits, and computes performance baselines server-side.