Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“nutzt nicht die Kalender-API von Android”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0ba3f035b632f16a2d8d61107860af8e56d56341fb12a3d1b5d66aba04470fe0
Signature (Ed25519, base64)
yp+A5CPfAbdmzRJcHehukps08PFfwVDfDN9P4T6ApVbt+qIoicOy7AtFuUGq3/8pDfpAFbzMPgfZGlSw8cxTCA==
Merkle root
a4c18639252762e8592e52699d716003f75d0f7e56e7fa6339035d798c5faa4c
Merkle path
["0ba3f1e237060695962b89d3e4b09f7444f52a276e408e13cce41876ea33522b","d1b67af2bacda0d41e09368ea24df7ed2e833d1a3f9c3a7c8de750940303c470","a1ed705267ae25643a426bf87fbcc91f64a06175fbccde7e15178c541a6e37c7","bbae6c49f20de7cb0214707102f384db225d3a64351088bd1efdb558e9395803","36644262146a233f5546f65dad0eca77f3c77e6be8f5a7cfa29b641b2e524cb6","9b5fdec961c3f61ce011d78971aa4168c387a90659ee621074712cc681827622","b03cb28c8a86a53a2bac549d9b62288a406d81bdaa0741199e2296fa30113968","72484ef098ccea69fe6386630ff8442cf8e40185e87b7c65c40aabd13724c9fa","e606ac6fd13073fa4426be549cbdf4f417145bd321e76096b373ab004373660d","0ee843a520abd0bee90a57da50d0b49f813e35ce9da332878af1194312c4595b","0b173c715a5f3084889c2022194fb83eb9ec0c3d79187995f69b3443609b5cef","ea39482b5a7e0d45d9fb3ae639170732241133dd31b00e5a83bcb03533f8d238","a54fc815eb1b1840822e4a876caf80ed05f30705f1d63949cf36ecaf8a968901","991436b9578e675394ec672133d1c374d83d4a1e2c908b8f139d4d517c2af4b3","38817b8565345ec373a63f174b7c8fd25668576b72ed4022ed922334dd0dbde5"]
Anchored
2026-08-25
Public log entry
search.sigstore.dev, log index 2582656976 · entry 108e9186e8c5677a65b0…
Expected log hash
918fc3881cd55f75123813e7996add0afe4b7e68bfa1a75328681c18d541d464 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787629605596","kind":"published-quote","locale":"de","page":"product:proton/proton-calendar/de","quote":"nutzt nicht die Kalender-API von Android","rating":1,"review_date":"2026-08-10","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=me.proton.android.calendar","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (a4c186392527…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.