Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I think the app is really great and the program runs very well.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0aee63c30b39b3624d8051b29923f5be03a69b4e20dfed3f62c073bc85ca9cb2
Signature (Ed25519, base64)
Iyi2omwBl2cyTKB52BjSnQl/hvV5DjYm3UF53MV3FWB1MYNVjYJ8exao7tDVLMlf/jnuecm4tPqQf2bXlIC+CQ==
Merkle root
3b820b0e91b2475ca02a79fe65f1dcaac35af570ee21f4c868099b9c17e17c1f
Merkle path
["0aea2646aade13fcfad4ee90849b28afd98b9ea9646a51a2474b2d51dd21ad33","3bd5dae90f50ab7b9ba1c6f366e5bafb155a1aa6fa3f55886cb1db43afc7a33d","be35dedea4cdfc4adc201c273eea4879061a2e7a3c7b983e6d55d3e33d67bec2","b4f5d10d70d796693773fd71e39adb228ff93f860968b6fef439526e48da110a","c9596e105dbb96e6c05bb93a0e8381915026967ed372764338eb05b86e7eb26a","d9837d68a9418deab7bf7ec3142668b5890538936a6b1972745e6decb2751f5f","fdb696629cf352f58eff82c4915ef3c74921d9399005e99c61b15344e43eceb5","686c5914d8c3bb357ecc5082539fa97883aee9c92f746718287879a4b11a56df","6fc2a8af06916bb61eb0aebe4cbd66549e32890bd1da4f68906b492daa327806","ed508069095ec7117631564ea38f89355536652658babf22c30856487c1a4bc2","89db876a53fea154da0cb85b4c6f363d9ef2250349f7874215141d599e56a24e","908905ccf01aff1d877120de1672987ae5d5a21dd262fb78ac6d3eb20ba17367","3b28c91ed1c07c20e7a9ea170d94b917c6d123814303aca3f92997be066c952d","e448e4cc350a9a69a05538fc74a8236040fbec1cdf0c4908e91135fd4a29e380","92de2c105ee268f1f08dcd9d0a8fc946130cef7b39b15a2b5ed0d7209687c9ac"]
Anchored
2026-10-07
Public log entry
search.sigstore.dev, log index 3124210377 · entry 108e9186e8c5677a0172…
Expected log hash
20a5241ced0c7b94303a7b8002f1aae217df3f1371aea54ff5745a148bddda47 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1791349684588","kind":"published-quote","locale":"en","page":"product:sevdesk/e-rechnung-software/en","quote":"I think the app is really great and the program runs very well.","rating":4,"review_date":"2026-08-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (3b820b0e91b2…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.