Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Unfortunately, this app is still missing the most essential tool: creating quotes.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1041fdf93ee1a85b66e707c81854bee40b058aca88d4cad7b66af2e90c47a680
Signature (Ed25519, base64)
YckTs+CIwErfOLYjHX0fNKYHG56utpMGmzSpmw7gmS7IlK2LoktpQ899JL5CXvteyWdQ5Ez7ObJqHYFP3mEICA==
Merkle root
249a627257bd2a9dbd9bc74ec65dce63e29c9ccd8f402432a46bbf1cfa12c86d
Merkle path
["10427d771e9b90e3038a4ccd50ac2d2297db6e0bf8b271ea5b540174dad05d14","b4eef023ea79dca9cadf441acd8358cd4c61eb257c196eb4ef8284681f1058bd","a81c54492e3d62854366fd9ba5f0f736df4f3b7dfbecfc403da44ab1a4a39830","ad2549898008d62a54d508be059396240b7340cd9ad5e187da4e6e23b5e47887","6ba0607a8ac2a28e9582b2fe7e609c58b415971a80fd91d1828965e0c6bcffb1","2441ecb928811a03005620db75b0e9c0b6eb85710248dc20cd748ba0820f584b","0e871bb9b2c8028c94e464cbb3e3c81dfd661fc124258e0f34e0747491460574","34ef384190118ebd672068641d6c05b525e23fe7f2b9780f60b85c74dba09a55","241617d66ffd9e0a12805cda452dd37632ba96de337e6616be27f4d76429eefa","08edefd4693fa0aa7333d87469629603fb226935c66348339583991e4074ff89","69e410b5b5c48b40f8e52c4f9c155f124fae82584906da27750633db67b1b9dd","93da08a32a88984f43cb8cf77dc9f15f59275e83068c84de6557b04be928f845","eb7727f04a590b9f55c190f90839cbf73f485e828dfdac586db4b55a34076c29","c94857f058a09552518db3b6411014dc84d9bd9a71b10e488f83e40faa66dd70","98481510f61448eaf55101f28c348e05af213e498327b1646c7ec76c471de7a8"]
Anchored
2026-08-26
Public log entry
search.sigstore.dev, log index 2595205423 · entry 108e9186e8c5677a9f26…
Expected log hash
fbc678ced8e0822086692e4ab6d232b628f26b1a50cd2c52eadc2f6910e32e8a The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787717877847","kind":"published-quote","locale":"en","page":"product:sevdesk/kostenlose-tools/en","quote":"Unfortunately, this app is still missing the most essential tool: creating quotes.","rating":1,"review_date":"2025-08-25","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (249a627257bd…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.