Quote verification
This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.
“Why can't I use my phone number to verify a new email if I've already used it to verify KSuite?”
Checks (re-run on this request)
- ✓ Signature — Ed25519 signature over the record hash, verified against the public key at /.well-known/citatio-signing.json
- ✓ Merkle inclusion — Leaf recomputed through the sibling path to the anchored root
- ✓ Public transparency log — Sigstore Rekor log index 2632227861
Proof data
- Record hash (SHA-256)
0fff945ebbb77668e336f1ae8cbc40ddb6713cc1711763f3643c4af1b4646711- Signature (Ed25519, base64)
ZfPrPqUNVXPGYMDpDZcQiwOD1BHfltTUCyYWFbR/iOrfF4rXH8RR1Kw1Kt37rPlDSPdLwwSBbl6Jg4WeHXf6BQ==- Merkle root
9809cd1f65a3d4e144579745a20f7882b635b7ad9e75f8b31fa040fcb7e74470- Merkle path
["1000ea8859f57d24b5eea7119f657532b2a504da5ea051545b58ee33176873e4","d8b13f1cdd313b695c1d91ba90de828c14dba071e64cd9f409c0f36c978f02f6","be03219a15f080cb8e8668559a10cf9920a98cf06e6041c5f5f04b05e4af8758","65497da0c5731eb0e6f62965081846e112c6c2826c7bd3dfec57358e8c04de75","80347eaa820d6cfd31da8b04319296fba86f8c9e8e01e43ecebe54e01d25b35e","195dc87b27b196ec39bf3dbdb79849bb1da4746f8f344441fb91a3a7c45ed84d","48fa1ae443b9f8efa3939a1ad3330b1c9a8ed96d7ca42a8f57cd9bfd92af2674","530f193ee1608234f1a078600562b33fc294fcacd1869036ee578a144c8e3f6f","858feb0763deb3c592cc8294aee3a6fa476ba560a890c845ae9a5cff8fd890e4","a825ac2c874560ff482a5d3363a1858ef340ba4bdf8a7ef7bfa322036f7fecca","07a027eb2fd4a498e30798d2a1f2b58a0f4b4ecfd380ccd4b59009139ea60da8","481f7ef0a039f0ac74ac45e941b1f75812097a8a1d86b01a2fa72df921bd5f85","c33a9efcd0298a63eaba2136cfe18dd1517727e1b9e9bbb60122216df6f0406f","13cef35a80378a74af4faef102936039d3a54a741843391bcf32134dd8e61270","5420b3c3f4a7cfc61de84c757928b42517e167d282e291e38912f2169ce60350"]- Anchored
- 2026-08-29
- Public log entry
-
search.sigstore.dev, log index 2632227861 · entry
108e9186e8c5677a52ba… - Expected log hash
-
8be5978cb1be4c5daa434c41d0072ddb211c64c3f93b137b58c71c55ff15eb8eThe log entry'sspec.data.hash.valuemust equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm. - Canonical record
{"dataset_version":"v1787972611008","kind":"published-quote","locale":"en","page":"product:infomaniak/ksuite/en","quote":"Why can't I use my phone number to verify a new email if I've already used it to verify KSuite?","rating":1,"review_date":"2026-07-06","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a4bc8a3f62c5f7ceb289fc9","v":1}
Verify in the public log
- Open the Rekor entry (pre-filled with this proof's log index).
-
In the entry, compare
spec.data.hash.valuewith the "Expected log hash" above: it is the SHA-256 of the Merkle root string (9809cd1f65a3…), which ties this proof's root to the log entry. -
Decode
spec.signature.publicKey.contentfrom base64: it must equal Citatio's published key at /.well-known/citatio-signing.json. -
The entry's
integratedTimeis the independent timestamp: the root, and with it this quote, existed no later than that moment. - Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.