We use a checksum to ensure the download is not modified in transit. We then scan them for viruses. If a setup triggers a virus alert, we will not accept the update and host the file but will instead communicate with the vendor to resolve the issue. Because we are not wrapping or modifying vendor setups, any security signature applied by the vendor remains intact and can be leveraged to confirm it has not been tampered with.