Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Easy to use and accurate.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b68c1c3f5998b94971981fbcf76ddfd499dda5e7ddad7955daba2e6dcf8d17b
Signature (Ed25519, base64)
Z1lK9KPqeA98YhulX4PS2FnTioZEdX/dVEdsyh6w1XpmwoiBsuX88ZC2nqf5QZ77IHzCId5qtNYpKEXzSWlWAw==
Merkle root
d07487a7d8598747d5b143d9a16722ca7a83f5bd36bc79d5bf9130c2672dae41
Merkle path
["0b673b9f1840067f67e036e11831adc7866efd3bc77301646eb57d028ddfce70","cda193ff6a07d258fb36a7581736338193df17885543bf0e79a7461194d7703b","fdc23089449e33fd15b4a1d85592285b892a7a27c7fffe343985b607ec85c2ac","cf0cc75e720465dd13bd928d6f3aa000d47964c20c222e9ec405a2ad0bfa98e9","6280f16c54fab3cb4be1c8ec0223a06653d2f62106c9c0ef4baea3891a966a44","e6ab0149b5778bb462d91611f30a75ab367da9bebe0851fc302ad52c8cacfeca","370e61b89a948c86d278e02579447e31105dfd37df1ea496b890d8af5674684c","f8c266173e2f70c7dd0a2d8d3db77c37d4cbda946fac4299b0aff4490b3a2e72","30d230e590ae294748ad6ba3a4f220d6549bd2928a8be97360e6c9b56b71037f","ad8bf15d9b7c6d81e14d912a86a64cd3bccfbf7b55c11ec8aefee72270d10057","6cdc6f101c275a381c25ee7c6393bcfd7ea6fb58256b219da2a01c59b46d7464","a0fdfe7690d005e054fb3a90a34d7cb5dfb00910c185dee375fbde390d3c55bd","884e6220e81a9d5982bd71d70ff9eeca2e340f53981f663fa0ca7490cce6445f","39aaf77ef5b3e4cffa994bd58b84219ff7133fe1d71c02bfd8ea2a47d2f7467b","fa743bec0c13730c5e9e6be51f1ac48c3e9e0953b18cdf4cd6390a132151d0a5"]
Anchored
2026-08-28
Public log entry
search.sigstore.dev, log index 2621505474 · entry 108e9186e8c5677a1258…
Expected log hash
7fc4ddca6f65b68d7bb8897b96188547f56c1ba672ff212c685cdf4bf7438da9 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787887633012","kind":"published-quote","locale":"en","page":"theme:meteomatics/ordering/en","quote":"Easy to use and accurate.","rating":5,"review_date":"2026-06-04","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d07487a7d859…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.