Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“please add the possibility to password protect PDFs from the app”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6710ba5d823169545616c5939e9381fd05e0642480227cf7d5cc11e07740200f
Signature (Ed25519, base64)
fJyabIAksMi697j7eFaXj4gEUrUx/p092tH8CvZEiTD4zIlmTfDOfnPzBPu5adtaSJRMhFnEoS9wugx3MrSpDQ==
Merkle root
ccae92ceb3dcfba104788424188fa34a8cb1410075ff6c1a21fa513e89f0c4fe
Merkle path
["6711169596ce0f844e7154fe1b8e4ed7f4e1734c8b2bfc034e24d58d0957f41d","ab358e37f4843255326d53829df25f83ddba7283371b3f35c206ae354a2152da","d22a08057cb1420d05e91328967953f5b10be69bde5f4de2752d06c2b069e241","c0052905c4808993562814ac5e02b061e0db79bb01f2f5ed68ee2dfaee52f3d4","cb3197e57d633a4a174b3a1c66b5aa7efac12cf1018cf7468e8336b17f4c1794","074b421f324c9625322ebde274a7725630bed374c4c53a1af70124d184be6e53","cfffd24e7d2dc4ea7227ea82d8cb0cd1b922de765ba438c2f714cf33ecb6e040","32e2e40ff02d6bbfe797af0bee8ce69a16c90f2492604f31b2ed7706280d76f9","151df2f668b59cd084d1691c042ec2471319410e65baef2a520e996b81713ff9","961c17b2a1daffc0772c4e630130b5c5cf5c52406ea5b5db0ad8dc8d62c5ca95","c8f92c5483e1ed0d2ad2a19bb44ffbac4a439d62b0feee55b433d2a06330f826","34cac883526e693549080af2663a642191eb446b9634aa864485beeaf771fe87","e472864955793aaa2d19219057558dc2b6f5214abf252963626c32870bd50cf3","35f1bb6574fe343de1c8512e58fe7937cd8ac075d63d989ecbfbabdbaf4d6344","f73291c2ca924ce4b3764e4b6ff1da65a701069f04fad47c52c8b693a0ec7e41"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515282333 · entry 108e9186e8c5677a6652…
Expected log hash
af455e73500113c158c8df9793eab703ff863c9c98fe38560752c9a1772810a8 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787139531268","kind":"published-quote","locale":"en","page":"product:smallpdf/translate-pdf/en","quote":"please add the possibility to password protect PDFs from the app","rating":4,"review_date":"2025-10-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.smallpdf.app.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (ccae92ceb3dc…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.