Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“As far as I can tell, it works flawlessly and is intuitive to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0e870891bf850a8944fc1a07ee0075fdaa9720f5a40191ef9b555405d8dcf702
Signature (Ed25519, base64)
PJCd7SJmpU0R1WGeBJugCFngCiwGNQeePBe1JLspQdYgynv+GIyAITjOsKEAAk3xL7EffwFdX11DA9Cx5CCMDg==
Merkle root
5c4849a28e8624d6f6d3204e1f81a6b24f2188b6690e8b122801054617ca25d8
Merkle path
["0e8d21621d097a4942e2e7af73c3850fe429d7557b5fd20d8b6659376fb06c19","3f54b5f572bb8a57308a68a894d7b7713f55e1d9abbe4d7909dbf1824d756826","bc243dad7b722f23a07587b71ba433a445172a560ff7a190a09f44401efeb7b9","82188a2a10b4a54341fec70ec02cae58fd4ffe189b4b4e81ac48056fe1d9e88c","8ef9c95966eb3bb780c1e7d891ff1318c42a07d660df8a137d161501ade4da8e","b80f6628d82684275e3a4d34ece9b3e64304e74cec821dfe090842b0feb74f60","b4fb4af623e5a7b951c96b8182a50d991817e52c15f0c8080a69b6f4d30a1edc","42bb8b1a0da68ed2158baadb27a92312242dbd793e76207e52358dcf1e9db50f","18b170badcf2d193e6a21591756eeaff6e7d13bb4009f8fffcfbdbe8af2b9d77","5e761cd91d7763ec2688e3783040041152536c1d3ccb4debbf192825c5ff8029","78f919805cc459f038ec12cee7b5c6ce3ba8cb52e32db58314807f6532c2a82d","d4188d2c80932f475c810ced976fef9d816f34d9a371db67d8b88d0e2c021c71","294fbe7fed0fa3af8e60ca01a3a05891e9e1266a19028060f205705712eb6e96","9693116cb745ecfbff942949993950a2efc72f3f48b394aa6516ac43c745a9a2","649f189ed3a422a3ffceae7f7673f3e683a1fac940fd27a4d89bce585dd48e49"]
Anchored
2026-08-20
Public log entry
search.sigstore.dev, log index 2524617489 · entry 108e9186e8c5677ab139…
Expected log hash
2051fcd76f2ba790414bb1c15fd4d3d064889742ea46f8e55b5028f1f571c27b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787193158162","kind":"published-quote","locale":"en","page":"product:sevdesk/buchhaltungssoftware/en","quote":"As far as I can tell, it works flawlessly and is intuitive to use.","rating":5,"review_date":"2025-11-17","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (5c4849a28e86…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.