How do I make sure the downloaded APK has not been tampered with?
The download page shows the file's SHA256 hash. Compare it with the hash of the downloaded APK using any file manager that can calculate checksums.
A matching hash means the file reached you exactly as it was published. A mismatch is a reason not to install the file and to download it again.
The second line of defense is the app signature: Android itself will not let you install a file signed with a different key over the installed version. That is why updates from the website install over the old version, while the RuStore build and the website build are incompatible with each other.