Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I sent an email, but after a week, I still haven’t received a reply.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0e2e280550071f05044f1e14ea06cad05db50c2c2a8465b7d08ffebcf6be804d
Signature (Ed25519, base64)
oY4PD6SbJ6eikj3Jo7yQ+RUJdJ7Zd9EXv0uiiK3KGzQ1GqvFZwIG1ThEyLtqxe1EY1kmbXdkVUYx4viCmNgZAA==
Merkle root
6f12cc2c270315565a1d1eee1d2701d6026d319131a58b69c44d9258f5acf4b5
Merkle path
["0e28bf7ab05ceea7b31f7ab7c171c38007b16ac7595849401b021f7af4d1801a","b07058cb7821b9cb6593c6e675fec13d2aae19cc3a4441c01b2e1ec495c20e70","fdaf8d1d059c977c5068541aea990cf9054a1dc4991ec1b60df88b4ea6172882","82862d398da99f9a09ae6262aaae35107132de15fce44254b319b47142b93e66","2636f123e7b2a6145b742b23ee6e2b7d8ee99a0cd52b4612aa910cacdec36e01","9b3966950e9d009c1931d39a6652f2b180440b447a6b918e82cab249d7f7d1f7","274f2ab39c2bc89320655e5de2603137b4631d9ba21e3e85f9030e4bf9a684d6","8448fd25aee6fee89a1226283ead4a8197b248a6219cbd0089e8a17d3ab6b9d0","c8b2bb66eb37b480e0f5135307434c3c35dd49fcf215cae3c4eb63aac98a4dd3","7cc46c5f442150d192924c271e2b6c7cca952a660419d8979ab19953d61c09ac","7ad6a8b64e93197145d809713c5bdb1a8b8351c7c1e4d854c601597ee5bf788a","e1810bb1a57297789aec183f22fa96342544d613c4438ea88ad3682921c3ac23","4cfb0ba358e827cc67056ca0e96e00d8845c97a5122b651824f093c98eb52251","30965059f5ea715e09215550378e817887188467dda82ad254cbb53806a794e9","ca4eccc8ed1a12a080d60e4aea7350c5e9838de027f4bd52c0b417f8e200584b"]
Anchored
2026-08-24
Public log entry
search.sigstore.dev, log index 2579589276 · entry 108e9186e8c5677abc30…
Expected log hash
35976bb6188e24bef6cdf335caffa2c8f3371772e6cecd19a637303b7339aafd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787541175661","kind":"published-quote","locale":"de","page":"brand:meteomatics","quote":"I sent an email, but after a week, I still haven’t received a reply.","rating":3,"review_date":"2026-04-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (6f12cc2c2703…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.