Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Un excellent remplaçant pour mon ancienne application d'authentification.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
241d974705f36173c46109bf301d3fcfde5e309b50813a839390ca410920e2f5
Signature (Ed25519, base64)
AaUfVEDDAwj2jrgfIMjKsZSeOND35c/MaMLPGqUA+SNkONoBeE3S7xi0yWEVYh/n4snSk7Aq87MT6mshmaoCAQ==
Merkle root
677e672fa444dfe5152ab91687c577772e13723ca441b5c8063508daedacfe44
Merkle path
["241e68bd8deffbaf38880e218f3c38588a15158b3b13a2acefa94730ff8ac264","20a68650c8f85b4ce994bc003de55960146d04a7a1b96a676b7eb0c5086a9e4c","784b16d1a960c747196fc59e0ed826b5c9e0ead8a04c9b8c94f9ece45d71acea","7ad09b83503daa13626e4ef6e312585fd5a3c07ab41e11a1596d05af8ddc430a","2b3e8980f77e3bcc9ab0bae34c24b59203c9ca62fdbcf095d63a564ff3e045ff","bd9ee0af5c82f3474a0442af5dae00aa469c010745e960f2192f0611ef924dd9","70c3754e6d0dd44cb39919d22ffb1221ac96f5e9662aecc9df3e69b936e5c900","4501dffd6f5d6cd1345604f251743c6f0a7baecc7b06ab617ec70812837094bb","6f6062866db19379a46f5efd77aa18b4f701378b9517ccc08617530240955a69","6a8607df21d20667ef3e9182d483e70edb210237eb6936895cd68c14c7f29b88","4f7e11f3a09e24aaffa2b5d9bc4c2442ccd282fb80ac21f46af1fca289c5cc95","8e9a5f4bf1bdbc745ade9fe1e5c7ea795fb91f97c0b4fe18e82e03e5ed00cd64","bd6e996c146ac2fec0eac3e8c06d1c7b69fe86b69de929b1fa7a0fb372eb8d03","4160c2bd6ca5556fcece7b88bcddb2c951ca86b46a4df6829fdfab8c09bafb4a","188420cfe03d9830600dc87f84622c41659cea53d9b8db8954bfc926ce1d4dac"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514013184 · entry 108e9186e8c5677a6b00…
Expected log hash
a596e5a342226b61371cdf76b5c8be8e37a3d00e7ffe8f7b0b550e1a8d1459dd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787122978040","kind":"published-quote","locale":"fr","page":"product:proton/proton-authenticator/fr","quote":"Un excellent remplaçant pour mon ancienne application d'authentification.","rating":5,"review_date":"2026-07-18","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (677e672fa444…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.