Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Best app in my opinion for storing your passwords and passkeys.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1c8ad7120233f3c8d982fe9e7b0024464f534e678ae410ae1857dadabec59835
Signature (Ed25519, base64)
iK2VCSGyXKuUPsASYdSm1vIKgL2RQyXnNoaGV/Ow3PJg7eh0hXrj/NZunZNqmn7dRxmajbndu85g1Wm8vdkQCw==
Merkle root
feb82b7f8aea18b46b248fac49fdc21a6b138fec64dc2fa12c4b3c7a81799706
Merkle path
["1c8608d160a314bb79823b7727d7c57e4bfbdb785be0a76ac139c2b5b05262b9","8b440a2bbb90f5a29ca604a40134776e6fec2bc6d16894f9cab45907cb9035ad","ca71a61f0896dcc060f883856a1d6e414a6be587ba2c0ece63c686f1a6fd16db","3c54fc5b22c89e7de27867cfd091338d74217fdbe3b5cb5b21fa0ae1d72f2e25","f8a5d78d178635ad40f58824ec2077f6f0ab3485a4cf17e2ba1fab005926ed63","6a7708d56d9a099704ca8558127cec200d6b15b98db0f0d6eac22ba1c153de5d","e27703ad5850b25d718b2d30db04e5bf9146303c01a1ecef2a0d849ef51c0889","ef3a662185b9fce3c0fbc1be6300e7829900a83e202a3aa58007510f3c664fba","5380cfa235b9d284004e90dbba9efdb89808ee8c739029c9a7d6de3cd66347df","3fd3846d0131fe45f7d07ecbd8d56884303418046dca55a756d9969d4df82541","cf77f2a706b7ca35e10a87b8133f6c65d58e187ce763515460edf9a6388a03c8","a86586d097ad6dfcc4efd60a975e3fb89148c9a3be61ec9b351b9cc4a0526bb6","ce9fe8fedce3454cf180d6a66efdbe5fbdc70a0fa838f69d2b9096cbcc6c4c38","e77d494af9e2547c53e58f62769cd14d89c9d23aad38b861f53f29b79396acd3","3520002e20f205a5e2c7683df52b5c77fe454ada68a85506f659d94f96d1078c"]
Anchored
2026-10-07
Public log entry
search.sigstore.dev, log index 3122521988 · entry 108e9186e8c5677afa72…
Expected log hash
9fa0d177312c5b0b22ba9dc313f3316134d71d179dc19912df4abe4610de68bf The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1791343163559","kind":"published-quote","locale":"en","page":"brand:pcloud","quote":"Best app in my opinion for storing your passwords and passkeys.","rating":5,"review_date":"2026-09-02","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.pcloud.pass","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (feb82b7f8aea…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.