Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“For example, supplier invoices or bank payments were recorded twice by the software.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0f587c20d7df6a4d80770c49bc296b00b292ca59874c140f99b559a730c85642
Signature (Ed25519, base64)
XaNYcBtJj/jLwoI4+wqzHKbiU7ksFzmBzzWPghuLJZmE/rlPylEZLWUHIY/aWprRQEmkHMj8msV8fAfYyYeSAg==
Merkle root
bdbf351c9ce626213a7937b083c4ac066820b0192efeebf285f31c724e7c7386
Merkle path
["0f584cb5eff52d5bb6eb1564e90e98511c4ffad3a3c3835c9c3654841c860d83","cae1cf5b4d27353a312f50bc8fb3d8d80daf1d3785fb33d819b658e8185a640e","be64806d1ce1d71a9d2377948d52cbadeca53c6520da5ca4c11e476a3faaa142","36f777aae58aec834a3e4434c4edfc8bac993609c1e1dde5f03050446aeaf68a","d8bf7c607e4a831b417b6b8302a0e73fbfc9ed226b692ec6e0990aa9262a0f1b","52fa94167c74da61f5c2b2603bab952578870b63abf2daf2ad66a8dd9b5e7d61","cf007cc277f16eff163593ed622074aa5f342ad0f6b2da62edc494a11f664194","d010b2156bb372f0e594d8fc8478ec64a518dd2aa4159fc39f8630a76d607654","4352f643503fce105500e9705767020793b93f28732f76012b211faac2becaa7","eb68c47f6456106f52596110b81899ab30450a22ae84efab1867a8595bbb9e01","298cc0957339feb0c8e72c1f7b6cbb277bb879b01abd41057693b60c7a1fa4b5","ed0847d04ab049e21d5f1209b43d9db4f9d0aa8b87c3438b7bdd9107f7128c2d","73428a6555103c20fb5ea743b73a12642caa27a1cad4c3aeec7f2fe71e2bad2d","8c4971ed811477bb80cd783319a321eb7e74e629d6c92773766b417396748f8e","4ffd3e6ce61b4807f2bbaabc5ea992d56be24a3e1b0106159ebe9c57df57e830"]
Anchored
2026-08-27
Public log entry
search.sigstore.dev, log index 2611694692 · entry 108e9186e8c5677a584f…
Expected log hash
e78df4d3c8e2db621642a45dcf6ea56f33edf489d8662048cde27bc12924afda The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787755965154","kind":"published-quote","locale":"en","page":"brand:bexio","quote":"For example, supplier invoices or bank payments were recorded twice by the software.","rating":1,"review_date":"2025-03-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.bexio.bxBexio","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (bdbf351c9ce6…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.