Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“S'installe sur Linux et tous les systèmes d'exploitation, avec synchronisation multi-appareils.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
05fa7f8b9d9d70e42738e9ad059b8463f5d62aec4db7c5e5a3b137a0fb28851b
Signature (Ed25519, base64)
45uh0NY2eEjcDPXXjhmr9jC0BKTQ1N4SchIkBcpOChjt3WWE+gxvR0Z/O62rHI1rLcKt2LEIldamT0CiRulACw==
Merkle root
8c6268a14330d1a3403c561e774645b0671f81571ec1735d4674ebe1de7502e8
Merkle path
["05fc7dd7db16289f9dd5f6a902cc074676d5ec8b08aa08cc6bb7fa753591ffde","eb709ee3e43353351122d8f763247756a6c2f39d3eabc90f76f7ba1b42c0ee56","d4fee6b87116f1f9af4fe47972b9bb12090ad409d95f51c3d4651280b5fa4c00","113dbf5df546f113a630df99cd682c473119cf9cbe99b85fb147a2e85d3d2cc0","c63c2d75443aaf86a101e68b7a94e752a61c2855cfdde0742f0602dbae7b6659","444379925ed86f5f55d1b5f1a755ed907f7b2316710815d19e6c405d8e229fdf","26f72a95fa5bd5db722187f24698af110f0f1f594da8657ca9b32540f3d973fd","ee1dc693a430a504a6ba6a584e6d6e8be44f2794038ae994729435ac47584958","e2f6e789327a643d404b6cecccdb57a1057e02019074f144b5015a5e7416a359","3d68eea6fb71c5ab5a6813553fc61ff7d3857bcdf01694dbc9ff399b30ca9c70","1cd305ce3ea1bfe7bb15a8c8744c8b0388c86379b11935e414bc5a89780ff6c0","7ef6ac7024634bd499c7b4000924d4521ea6f07a4fabf02115c6a5454f25c229","87aa107dfdf756911acc54672d2c33287c6855f38333ff4636b90748c8d70127","894fb50f273584bf006781fb08f5958320d3e5510a31da0d6339bcf63d847254","f548939ab1bb46e2c6638c372c3e2eef0d561ad18c63c15229fececc951e0b3f"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515439294 · entry 108e9186e8c5677a4f15…
Expected log hash
128701fddbb19410bf57cdb2d04d7a0278d13bcfda6410d76f176fa58341e1c9 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787141082461","kind":"published-quote","locale":"fr","page":"theme:proton/quality/fr","quote":"S'installe sur Linux et tous les systèmes d'exploitation, avec synchronisation multi-appareils.","rating":5,"review_date":"2026-08-13","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8c6268a14330…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.