Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very simple and easy to use”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
086265175068492f09b7acff7fee3ecc6f1bb0a0bcac09aa36055e8e79ae2a96
Signature (Ed25519, base64)
kVSBR3Q3kn+WOBXB8A2b9NommA0to915HV0qIXE/Ej+iifIoPePh6jsLZ3UQ+jfE5bSuM6zx+X4N5zHRNs/7DQ==
Merkle root
beebb1e90fe7e67e33cbec0f03b99eb76d51091b0320624790586a3cdacfd28a
Merkle path
["08636b8244d647287cd0849a5867bfb187c3f88eee966f7abff61d276fc522d4","52cfa29ed119a30e69246557aa21890c8f3bfb17efc31d26e187fa009df3377d","f2071f25d7170bc7fcbaf152401a865129400a2154ebab2c4c227dae7d1b9600","d2bb1b28f8f8d7691a3bcb04b3a709f439e87733b7c72f0083bdb345bd3f2c99","836b091a8b10c86d68ad823400a86a8b3a27ae635c05bf2191be96bc13b2ee4f","f8dce6c7f0566b43db9b27980570f4ec33fac0659f0867a99c5e14621d984722","85be1ae6ebeade1c303c1437f7896560d5ae075d6ee644731cf1d57a07275d41","93f1ac9cfbc032fdaf7094f5edc069b63819682033631eed22925718e356c97b","4401fc52fab05c80fa574969038bcbc858b7a46487c8f7b08a57aa8b02f76291","aabdd3cefe6be094cdc384151b18b0a400c0117434bf84c612d21ae141ab060a","be1d18f82847cc6f394066f4034b382d5d773f28b4ab8ca255e07c10bad150a0","73b6c01d202cade9897c4cde5230278699ef70c2f92ebdf509b47e3fb229b784","19513067f8bed92dd7049fed420106f7c62159c37086a1108cbdae0ca7dc379b","8e83ff51c482865a520be89d3588d4953cd4ef6526700cb062f0cfe87ac941c4","59e1d7599efc1b651191f22a2d0a899f2a3b0ab0131905b8aa9a10b3a6f59e7d"]
Anchored
2026-09-01
Public log entry
search.sigstore.dev, log index 2671517691 · entry 108e9186e8c5677ae4c6…
Expected log hash
207971f16b8b3b4c1e6f63e8e9291188fb84b37111ae3e0c78101499642ca382 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788236415966","kind":"published-quote","locale":"en","page":"theme:infomaniak/ordering/en","quote":"Very simple and easy to use","rating":5,"review_date":"2026-08-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.infomaniak.mail","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (beebb1e90fe7…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.