Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“None of my passwords have been deleted and it is very easy to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
53ed2a9b8ff77703f8f898cd8cf9f6ddd487e49059057c73b32d059e55f9cefe
Signature (Ed25519, base64)
WYzCm0bnYreu/rXVt9Ac2Cl7rzd9KooX+UC+fQfS3AFZLzGMf3jPr+9enf0rQn3nldDtP2vGY7zIy30DGEaPCQ==
Merkle root
4dc0bd79ba3e9442f7f1feb21f347e2f6fdbc72e99098aa5164776a6202654a8
Merkle path
["53ed7cc32779513702c3f042403eb6165d36195e0880977f2f911b7caea39a82","d0da33931688bb52dc28c2f5a6af923b6f9baf9bea76e5ebc9ea986fac152b37","7ec4b9115d0ed49826fa6cbfc279c5b639ef73457510031585640bef01963ac3","043a74ea00287437bda5a0082ac3b46f880a568ed86ce9ee3d064a599ecf3e34","891bdd7bca080fb2524503d8cba1ebf7ff36b653aeda34bb8df0fc9fd9fea10b","b510b94443605b38953ccceb2d70494b8899e48f335be21a1285cbd0cf403831","311ce8c2584f3d3d0d0cc5d56781c271c5a38464c5a5e72d1d392b760cc4bc36","97d54f1235f7e2cd8b10c3b93743d9ee659f70fa06f1605cc92715deed32a9d5","053c73a5ec55eb53ef892d81120763b0d0d98fdb79e3a9db9d6f23d81988690f","d16f76936fa8151b6eef9d79479ca068f268240561cce76a93ba063296abd822","7d6244f57392b638747b8dfa4f19607d93ceaeba3d74599f1922e855b847d8ea","5db6d47c594533280883338cc5dbafe319fd04677875292608d75d9596fea1f8","aafc4d7abd1fbd48f01758db3e1a1278331dd8c09b348c20be15802d81136ee9","72f96e42060ae616ed33b8fd6ac687c1899623eaa8a351026bf33e2e7a041d34","e60c2274998b06992577796b6abe86bec144203fe960878f7951a3ae12c9e532"]
Anchored
2026-09-10
Public log entry
search.sigstore.dev, log index 2776103867 · entry 108e9186e8c5677acd4f…
Expected log hash
2498329b7eaf275d309293dfbac35d05dfb8a55c65956add8448561c05945f28 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788848066028","kind":"published-quote","locale":"en","page":"theme:nordpass/quality/en","quote":"None of my passwords have been deleted and it is very easy to use.","rating":5,"review_date":"2026-08-26","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.nordpass.android.app.password.manager","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (4dc0bd79ba3e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.