Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very poor data protection, an intrusion into private and sensitive data”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0c1ecbe3d09979ff3b9be5cd240b908c253dcf33af9e062ba29aff00db25a181
Signature (Ed25519, base64)
37HDfER++FBRm0ohdZBItGRypJOkMXmkEjkcaY2Rbk4yJMV9xFbBn63haq1/HGQZdEpvanUm71HzEVLdbrEEBQ==
Merkle root
76a70861058eff5ef068585a821790f9f0f67bcce12a1ce96d55cb6d986420b7
Merkle path
["0c203204571be1a9562744a9a0fefef23db694ef913364e39001f426648af810","8bde8a5cd6a96f13cf5b944d44bfd55905b4315ec3746b348c55376b6224a541","e698ed65a58af15d17c05148c5bd5cb5956fd86fb637d4984cea6c1558344c28","a6aa8f28a35de02ca55adc781f2b9bed80b9d165ece1f8eae1d2bed74c979253","41e243101370eccc5b147222eb5efba6dafc9a2c8dcad83da8767e385500d1b0","a616bbe7f84259b3c6ef8d6800e24fd2b7f3741db5b901c581258ffc96acf12b","3ed38c71c0ab751bd278d3fccde78d79e7b3718f1dcfe517d24b4b423eafd777","7328bf2bf2f3a47f6b75b64f8613012da5760122e8b705d2a2bae96e7e03267e","042d5a8819fbdba478d086c5f134571a27f81890ca391cb3a0be3daee370ffde","2b8b173372f2a950d934b0bfe96f0b31c7a016ab97f5bbc2ca4109f8c2bb4d62","95cd5fd7fee37caec8f7ea06401a33e5474bee9a9f0b6ae63f9cc48dae292ed0","885a56f1a8f590664f08008255c1eb2a74d0d0a846d6a42d92c2e2591556db98","33a24b835ba41f8728ebc0e33693e8ba0fe91b47741da4e5756ce7fa9eecbcfc","b0708aee6a3da06da7ce07abfd9012194714f3e4ae3087e24e97cf8d1c46ebbc","02ff7ae642a7c307d0ed4a3e268c40962e14ad4fc94744bfb27f110b29b33c79"]
Anchored
2026-08-28
Public log entry
search.sigstore.dev, log index 2621558263 · entry 108e9186e8c5677a13d1…
Expected log hash
ed6aad59be4bd5b7ebab65a83a91c56e9ce506952d0d4a22235f03a556d0f54e The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787889797689","kind":"published-quote","locale":"en","page":"theme:infomaniak/billing/en","quote":"Very poor data protection, an intrusion into private and sensitive data","rating":1,"review_date":"2026-03-19","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.infomaniak.mail","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (76a70861058e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.