Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Clear and easy to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
08702f8d011a2da0bb1028c25b6c4e189d14692f1fe022d9b900536cc2cc6066
Signature (Ed25519, base64)
lwBCmTqGSuZVKvbZSV0SqYpDz2YdpN4mDacvXQEvjSZw6Vi9E2EERWkcdH48jW1XYspNLTzHf3U7w9sVRCcFAQ==
Merkle root
e880a518ba68bfe85ddff87a241b258528b2896d8ce031c201c4697c0b7d2205
Merkle path
["087bc4503c07859bfbb3c20ccd84a80b804596d7496ef90eebdbd3838350d460","6c1e890870b3e32fc80a081e66e3546819202d0dcc03285894c53cd29c872bf3","d8af4edefecedd2f4ad2e94d26f309b4ffbdb0a51332ad53ae9f7d4f3685ed74","80b88274d60e16045efa2e86ee25217cabb14fb92b9381c87d7f9a96b38706a7","42b6a92d68313662a5593618af14ca8fad8403bbfa788fe0524d737238447029","d14ed5bfdb52923690f7ac74f6b629ecbc25352a916fb8406a49a49eef2a91ed","eda2c4fa4f559fb1b9b71e9ea3f5c60cab5efaf0dbdc1a959acae91be663232e","4236f7d709c48a5e9b56d4c721812f7d9d3be810737ca2ae3a03aa70651118b5","f34d7398999fb5bc04f993e27a7d0cc1c62a970373034e4211dc66ff78b0e29a","805a618212de9dc49a1aae9e8ad4d899862ba71d59c5eee463eb159179466632","d2942e0ff67552e3de0560c6bc7d63f8e2e8772154309651438c23ada5551cfc","8abd4d5b06b87286affaa0cf89ccbc72d6059bcba0e452912cc764aa4f8b3a91","0e6818b49626845facd47486279f7e4a6689ed0beda657d93a969ab184e1e0de","8c997d59f41540bab49c6414578aed00ec9a73fd31959523b43a0af5a2eb1e86","269c643459740a67a842bbee9fda4a35b5098a4f015e508a69431212a0912770"]
Anchored
2026-09-01
Public log entry
search.sigstore.dev, log index 2680681799 · entry 108e9186e8c5677adf7a…
Expected log hash
23ab6878cbb153d06d6958de44ea3fafe32bd61b03ba95bcd26de9e09248aedb The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788297623062","kind":"published-quote","locale":"en","page":"theme:proton/ordering/en","quote":"Clear and easy to use.","rating":5,"review_date":"2026-08-12","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.protonmail.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e880a518ba68…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.