Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Can be installed on Linux and all other operating systems, including synchronization across all devices.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
07246cea2a241e2b5d9d4eda56fd5f5d77a27b8964b6adf574806ca18cb76358
Signature (Ed25519, base64)
1mv9eDCH01sV95c0JwgBcnhynUc3ZTNayRsOs82svwGSEapEyYgtyNXh9CWFUj4OgZp1xGAPhBCZZOVCcFAtBA==
Merkle root
653f52f612dd7654074ec2f50a8258d24363de118d24fd3fbb293c3f9466146a
Merkle path
["0727eb4567122e27232e0a19bb28751da62cc3dd79eb5248460f244e1f2ab3f2","fa447de05956227e65a999c9301365e6d2446df62579066fbb4408d72c570528","23629ee870ffdc098045fb28dfee98a692750c274f20227a0b01a7576cfe0393","d80007c532737b0d6fefe3a283f4485832c9dd2893df49384e0c1775cd1867fd","120826460026b8cf26fd980e9f515b8a2b6704158f658e1be4e45dc0a8d2cfd8","063d964282e7f461b8f710701de6561e83e803c21d949a23d27df0d6d69d8a65","26acfac4e8e4807da2e3e4c94fba2120a66404fb4d059f1b04db80bee5a42cbe","b7bf86468bc93aa9091ddd9a43b49d0dff5ef3e1ca78b15112f3e81bf97dd444","9de042493ae262ce2ada432ab8ce806c99089a134fab9ae1106f08274f487c85","6fc6e7592732ca5bddba993395de6ae96c1bfe6e70807602b228978a1fa30748","e56204f1821ef0eb64f6695ae10ec59c473b495ccd38e242384b49da4e461f80","f20b68e10c9d60c824a39dc128151a5fb0347bced725edc264111d1392a6f092","9fcd88f1beaa69d65dea3d04b431d43ad97368c1462c24ff050124283ec46f78","88e03340b0b23badae5a3021870a121b2e386f6ec4446eb6072186f7c59cabf0","5fdd4fb85b0ec398c42530ef65e986b74edce2f5c14068ba5fbe6a72c94b89c8"]
Anchored
2026-08-25
Public log entry
search.sigstore.dev, log index 2582700609 · entry 108e9186e8c5677a119a…
Expected log hash
db705c1ce83f047166ef3ebf3406f1398f685221ea16db9703eceb49a1163aa7 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787633403760","kind":"published-quote","locale":"en","page":"theme:proton/quality/en","quote":"Can be installed on Linux and all other operating systems, including synchronization across all devices.","rating":5,"review_date":"2026-08-13","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (653f52f612dd…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.