Record the product and release
Include a stable product ID, display name, release version, UTC creation time, supported platforms, license, and AI-use disclosure. Keep those fields consistent across versions.
Describe every artifact
For each delivered file, record the exact filename, byte size, SHA-256 checksum, media type, and buyer-facing purpose. Generate hashes only after exports are final.
Store evidence, not customer data
Keep the manifest beside the release archive and sales records. It should describe the product, not contain buyer names, addresses, emails, or payment details.