Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The best alternative for those of us who like security in open-source applications.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
f671a5559cf6c17c43966a2750a22c18965238e62417ea95a51eb87ab5722831
Signature (Ed25519, base64)
1qZ94zbLHQ82rVyIKQxpR9l31opStyoImhSW1eudECM5lwUU38/Jku6AIsSx2X0qYA0GVp4uewki/e6RKvmxAg==
Merkle root
4dc0bd79ba3e9442f7f1feb21f347e2f6fdbc72e99098aa5164776a6202654a8
Merkle path
["f6724c62b6357931bafa3fe7345651653a92e4135503deb8ceb87c71cbd03736","0a4643680d3140efcd821e38edd05e72aa8436d0780b5d28298b3d406e69a2cf","f622aa3d0d7d228bc5ce163afba7ee61c4c8a42a555d90c598b038d6aa6b5270","d83793071cbfb5c90fa37c0e1d61b23fae46c0050b460fe408d680ebf87e420f","5742dc16ad07c9b9d7da3f60f65a8a94104bb6b8fc1bc233a2cd734bb601c40b","584cbd01cdea4fefc8938926b7f0d7967e98eafb5b68a225762118931f7fe08c","b7ba997bdf36b6b55653f17c7420be1f3fc45057d2942ae2c2526a089769b913","48fe85205b6bd496fddcd5e32561a343c82c3377156ff42cef92087dc7ef2e04","ce9857ce523c0653efdc453384c8acafac163dd9e4262c7af7548fef255ea886","31dd17030dab2df5d2a4fe7b9f8245fa3f3d14446a9659d7a5e6669db78299c9","5cb7ef9a1914589522aa0eec83ab74b09aa3e8302af23298eec4d1e6ca2424fd","8be8841b862f5520d66c96a9ace469cc2bbd47fc9d2a440fb26a1f3ae81325cf","92ce7b112a5230537628edf62c10d3699180f9c58135530242c50c3d07cb3a9c","6ca8568b4e7c7e4e3b794231ecbe4a3822994a26c5f3f7fd0671946fee25f414","66f93059eee3676095d6925b7cc2fe3b97c348e816a4d3ce47c4b00902d3a227"]
Anchored
2026-09-10
Public log entry
search.sigstore.dev, log index 2776103867 · entry 108e9186e8c5677acd4f…
Expected log hash
2498329b7eaf275d309293dfbac35d05dfb8a55c65956add8448561c05945f28 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788848066028","kind":"published-quote","locale":"en","page":"product:bitwarden/enterprise/en","quote":"The best alternative for those of us who like security in open-source applications.","rating":5,"review_date":"2026-09-01","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.bitwarden.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (4dc0bd79ba3e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.