Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Unfortunately, I couldn't complete the newly added verification process with my GrapheneOS phone”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b109638026db55a4037b99bf1fb5aea14db1cabcb00ac08398f33cb72e496cc
Signature (Ed25519, base64)
9bHHNCgv996hvKqAgwcZPALuukTpcT4cam6qMoqIaAwLIMqZHbwvT+vv7B+Tr35jUcXV7p+J7KqacmNXusbWCA==
Merkle root
fc0474f2ab9253f8c52a81a0b2f1ae382f5f022f9b54f4e3fe06eadaf19fcf31
Merkle path
["0b1448ef5af6357f65444e31e3744465673415f3dec5209f6bb76a5b785d20be","16a07812db662421b4e140e0b4537f51b56868c54a422f79a706db35b37effaa","91e98186e9e68ea1a0a4ba0b15450dbd6d6f4b38174d7d76a9e4202710af86b7","c8efc998f55d2f730de794285ba5821e9c32908bd94bcbd823ab10df868fff8d","a7fe56a0a22cb36fcd20964988b666a56e8d0aaaa06dc16832941ba2844fb058","286bf2a610f82649eb1934c043e3256d6bcdb6df7603c0f549398fd543805169","19067080a67152d029fdda169b0acb32aac308a9daf51c3364394c74b92dc28b","5388c1442a8167abd3f9858f43faf19f47a358a25096d2eefaf09392d286360e","c77300adcfa2312e43813b9e7869a636d9bf0808c75695981dc6fa2dab94f7d6","5796e3545da33e47160544f93e68b3f43bbdf3685d881d71c3ad0f36e05f6d19","0414b835d9d4159b69a5d85ae49045075554a3460e84fb35f3d3b2e426dae0e4","fee761e8242d8ba3849c6e844aae866739620eab15cd0f1261b960ec67bcf5f4","0762348a28234508bdd1e30587d1fdc0dd40f0417d1221a51093b63a21a51b25","d53ce14c8422f7b98c01f3be46add79c44e4551711bc517ba367121540130adc","df2c1289894581f6e22c526afc719be15b70c61ef4fbef0978dff78cc8fc6054"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2544092674 · entry 108e9186e8c5677a1b30…
Expected log hash
e3ca1014bd6a1a766a29da72cd2b9f7f9c6c416fe6af720fafa94eca555dc171 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787289954326","kind":"published-quote","locale":"en","page":"theme:relai/ordering/en","quote":"Unfortunately, I couldn't complete the newly added verification process with my GrapheneOS phone","rating":1,"review_date":"2026-02-24","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (fc0474f2ab92…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.