Quote verification
This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.
“Impossible to receive any passwords”
Checks (re-run on this request)
- ✓ Signature — Ed25519 signature over the record hash, verified against the public key at /.well-known/citatio-signing.json
- ✓ Merkle inclusion — Leaf recomputed through the sibling path to the anchored root
- ✓ Public transparency log — Sigstore Rekor log index 2515144749
Proof data
- Record hash (SHA-256)
c6a607c2c197e12b4a33d877ba6d7e3e144a21a7be4fb78f3faab690fd5ef4b5- Signature (Ed25519, base64)
mRahV0aysIZ28dQE4ziJH9dFwGi/a1heci6VLVeTeARLXSaYPsFmjYTgfAE1drIWep89dHJQhajN2MRIEphOAA==- Merkle root
8a6ad893af0f0bb6c448016a777af61f3f4935afd82df0db132e64f813535715- Merkle path
["c6aaaed1b58c1bc7451d7fa9fecb4053139130ba6818d6b5a5d77b5b7c7d6c12","14eb99728a89324e3acd8a158a4091d4c64108de6f57dfaebad2819a50a7aaf9","9e371d1b68443fb367d9a9dae04b8367a586e112f4bce979392a64b283ed7551","f62b2f6b994db34153ceb26468f461b8e5e7b29ba322afb24108cfa21e6ab55b","e48bdc9d8de9a36bc6c4deaaad20d97f4eb1afcd6238696d545195e5936eaa2e","16fe3c389f2391d8515040d127ca57a4a56ae143b1a7c439318cb0e915e62afa","e347404642dcbcef22eaaa23964a8663cc090601a60152169fa6304dea9f5fbb","f55758a0ec29bdc8a2074de59e1d134e3341caa2bb1c2a2948efba14f0665dd3","8aa512908e8a38bfcb3765b67e67838f098a8c48fbe0168d7bc2b14d2e8492d0","7d1066c142e74c6288ff62e4a8ad3e48372d078170175f4c5a1555b4a8cc2077","d8a1a33a8154f56597c22e86bca5517a9068d8a4552d7b7d4c835dec2b3cd40a","bd0c1f2bb293beca31112cbae0a0701b5af110df7e3fca022c47447f9bd964a6","86ecf9405e70cda4b965af2cb0338f06a3a6959b04914c1f62f998ca30a5b84d","aca625c2c743c13b7e188c90a8dcb2895afae601815729b8511e9bcc31ba8968"]- Anchored
- 2026-08-19
- Public log entry
-
search.sigstore.dev, log index 2515144749 · entry
108e9186e8c5677a63b7… - Expected log hash
-
b6b79ad662332330e69c4ef135f6fb13ddc70048f846024d496aaa533f7f7fc0The log entry'sspec.data.hash.valuemust equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm. - Canonical record
{"dataset_version":"v1787137589246","kind":"published-quote","locale":"en","page":"theme:xodo/communication/en","quote":"Impossible to receive any passwords","rating":1,"review_date":"2025-04-07","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.xodo.pdf.reader","v":1}
Verify in the public log
- Open the Rekor entry (pre-filled with this proof's log index).
-
In the entry, compare
spec.data.hash.valuewith the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8a6ad893af0f…), which ties this proof's root to the log entry. -
Decode
spec.signature.publicKey.contentfrom base64: it must equal Citatio's published key at /.well-known/citatio-signing.json. -
The entry's
integratedTimeis the independent timestamp: the root, and with it this quote, existed no later than that moment. - Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.