Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I think the app creation process could be much more user-friendly.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
061aa6b3c5bad8b18368cffd037b56b943d51907feb24af18f5bd5b6896537fb
Signature (Ed25519, base64)
82fCqX3RqKksDcC1do14fVwMdMDnxFKQ2hKR2XW3N30Jx8qVmLxsyEAK3HfywURWRQSvw/yZFe6IiWr2CsgHBw==
Merkle root
c69b412346f0db8d88aed17dbaf2e4876a3743c1c4d16fb306ba56b5c0573123
Merkle path
["061b551c342bb1c6b52265cc4cdfb9d0ab5baf97bd661fdd7333babc1de6beef","ea7ac6f54f01ba1f7cfedcbd0115d5fb66612086a53461dc9173e4e28c23698e","d564367889c88c55d37676e963d63d53f55db7125ec4c169590762d01e30a72f","cbe0877caa3ac60221f9db0aa19514de2387079fa9ac6a577e40a2f4e7e978bb","f9586b7cc88d6bf1219cb25d224d1d53cc06d350ef8c2368fdc3fe36ed8d4131","29bbfb2d32ebf75205e4fb2e56f88141036245e7ad88e123cc08353b524ef3fc","8e98175dc988ec6a96c4a900ee19600b7ceadf2e070292dbbe91bec13e40b14d","39f3ae96f51b193c16e4971372d5fae6f993dccc3bd2624e6744e3fc45460f78","6db628a71f71a716f4cda57354feb342b5bb16e3c54f8efe68f86ac8be0b00f1","0bcab07500f9e04c04cfdb6f14b0a08ea37d66af7737f2c2dc6aab3970d24996","7a518cf36ad2945b3c7b0324706a131a6d32d4c8e33c1a00df94c7dcb059fdd4","d2ff7fe4617f0faeab86be5a07d9e5994cb2c5055379e39ba5f38bc3f21c4e08","09997fd9b1ef8c57766815e6c9849e05f2447cb27e8d805273108da18c60273d","62927e8f71080777dd1935c21221e60b742dc0377a31e2f20a0a64cf6c3282e8","3da38b679e2392986aef224a332d14750fb3a22c4e75287765e8f68f575f24f3"]
Anchored
2026-08-20
Public log entry
search.sigstore.dev, log index 2525010456 · entry 108e9186e8c5677a4287…
Expected log hash
659be4fcc7663b2dc65a53351e16497fea44ed9ec8aef1f3c48c8e452b350dc6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787194832011","kind":"published-quote","locale":"en","page":"theme:cewe/ordering/en","quote":"I think the app creation process could be much more user-friendly.","rating":4,"review_date":"2026-08-05","source":"Trusted Shops","source_url":"https://www.trustedshops.de/bewertung/info_XE3D21EA81A56276ACEED1C9AFB85F941.html","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c69b412346f0…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.