Pinned
Commit identifiers and SHA-256 checksums prevent silent upstream changes.
Content integrity
Quran Feham does not treat a provider name as sufficient provenance. A published content release records exactly what was used, when it was retrieved, how it was reviewed, and whether it may be redistributed.
The reader currently fetches labelled Quran, translation, and recitation data from its configured provider and can reuse successfully cached responses. That working runtime path is not being presented as a reviewed redistributable release; whole-Quran morphology and tafsir remain unavailable until exact sources are licensed and validated.
Keeping these layers separate prevents an explanatory note from looking like translation, or a third-party API response from becoming canonical silently.
Immutable text release with riwayah, orthography, ayah numbering, and checksum.
A named translator and edition. Translation is never presented as the Quran itself.
Exact analysis by surah, ayah, and word position. No prefix guessing or loose alias matching.
A named reciter, recording edition, licence, and stable media source.
A specific work or reviewed note, visibly separated from translation and canonical text.
Commit identifiers and SHA-256 checksums prevent silent upstream changes.
Published releases require a named reviewer and publication time.
Redistribution and modification permissions are stored per source.
Each release records provider, edition, upstream version or commit, checksum, retrieval time, licence, included assets, review status, and reviewer identity.