Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I often find myself having to log into the desktop version because the mobile app is unreliable.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
07142b886534a5521acfed0a2b73464f1a999dd48a503e3867be3c2bf2646c8e
Signature (Ed25519, base64)
hVlIa2aU96ILb7EhPZTJMsP1DP1zIMebq07IAhOpzo8EhXy4ee49lpg4Vc+/D3OMJb0H+e0x6uzhYtiZrT8ODQ==
Merkle root
e650e75fd77078528aa305533eee5d0a1a546628fc8516773e724c8dbfd143b3
Merkle path
["071040a35db2035a9a05d276b7132e556b819054ce5d572ba63135c03645e0f4","861a8ee6ad740d40b5cd2cc79abfc4179f588b8fcb5544d81299114a624e55e4","52be3c9bf711fbdcb298894da1244a1e746da2c2d8d2b3d9dc360ed8f42980fc","b92e23b6d0732e573691fa15621af88f8c4d08469b8e276c4c7f4d47b51e1aea","67463e390c44fb02f0050350ec9a79981d6f0c222d6c911ed91810adbf32c049","93e133cae3e5d0742d9faf72a098c1c61369df061ff82cc8c6ba5ec46fb94343","5e874c4ea6f55865b2a48856cd21a96aca3a34ad43de6e12f305613d35316fd7","7a05b0af6a39a5c4786e091dfd8330f2a4ec2ff782dd5af93e8249a41b936941","e0b84f57fb2860be91e416a32da8a9b1802adcab01ec75b8fa002c577a59f4d7","990a175807201d3243142bc77255ce1e9e5bcb1b0c14f38e5e2308588630a301","d091556122043933f3541ce9698baf36c60a2bddf02ac0e7aec614d9f6274e7a","9cbfd3204b3e2f5027edc155e8333a2328120eaa38808f017553940b835c0837","03229a02d4ef23689ac574ce2fdb2e91509dccaab3854dbfc8d9e90af4ef8953","de4b01acb55e434b8077712a3cea8899c69e63005b6b5c436594f06bca9b060d","bd662811507e1e874bc6ba02d614a311af652dab0714938ac7c98aadfaf42cae"]
Anchored
2026-08-30
Public log entry
search.sigstore.dev, log index 2647299953 · entry 108e9186e8c5677a1824…
Expected log hash
d76177f6a64b24e24552f49a73f627dcd7dc14dd72da9a30f95c027c24a50fd8 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788057950482","kind":"published-quote","locale":"en","page":"brand:smallpdf","quote":"I often find myself having to log into the desktop version because the mobile app is unreliable.","rating":1,"review_date":"2024-09-06","source":"Apple App Store","source_url":"https://apps.apple.com/us/app/id1485259500?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e650e75fd770…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.