Download EasyDeploy Platform

Standard distribution package for all tiers — Free and MSP Advanced share the same binaries. Refer to UI update for more information about legacy UI and new one

SHA256: 5845b8aa078898ea017d002a653cc262f2e52713c42e3db0add0771027c32206

SHA256 Legacy: b6a72508a063077135c7b8911c54cdd52963a6ab44e82a9aa2bec220669e49c0

After downloading, please verify the SHA256 (guide in the Security notes section) before use.

Package Structure

Package EasyDeploy-Platform.zip is distributed via R2 and shared by all tiers:

[1] EasyDeploy-Platform.zip
├── EasyDeploy.BootBuilder.exe
├── EasyDeploy.BootBuilder.exe.sig   ← YubiKey signature
├── Links.md
└── EasyDeploy\
    ├── EasyDeploy.exe
    ├── EasyDeploy.exe.sig           ← YubiKey signature
    └── system-config.json

[2] SHA256 hash of the .zip file (published with each release)

Extract to use. The package does not include the Portable apps — the tools in the default configuration (MultiDrive, HWiNFO64, Explorer++, Pale Moon) are reference design choices only. Bring your own: add them via BootBuilder at build time, or copy them manually into Softwares\ and declare them in user-config.json. See Configuration for details.

Security Notes

YubiKey Signature (.sig) & Trust Chain

Each .exe ships with a .sig signed by CoreSystem's YubiKey. Both applications have the public key embedded for self-verification:

EasyDeploy self-validates its signature before running → BootBuilder verifies EasyDeploy through the same mechanism → if EasyDeploy fails validation, BootBuilder blocks the ISO build. Modified/repacked files are therefore blocked at the source — you can't accidentally build a USB from an invalid binary.

SHA256 Hash

Every release publishes the SHA256 hash of the .zip file. Please verify before use:

Get-FileHash .\EasyDeploy-Platform.zip -Algorithm SHA256
# compare with the hash published on the website

Only download from the official CoreSystem link. Add the file to your Antivirus exclusion if it is falsely flagged (binary is not yet Authenticode-signed).

Recommendation: always verify both SHA256 and .sig before running, especially when receiving the file via an intermediary.

What's Next