Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I love its organized design and how easy it is to know what to do”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1045e076a445bdf1f15c2b559e567355602ce174c741ba7d961798d42b5ec344
Signature (Ed25519, base64)
UFaeJrEetJvc9BQW/Ja8e/MW8gTDew9foYkKPGkWiXVuqXNgUKDV6ODFfTXXdRouQzVqSTB6aJTmGTifEB1xBw==
Merkle root
33c00cd8782e83e7660b36f31023b9067dd316746fb34a5456c153a308339c6d
Merkle path
["1046251033ca87fce00585423c3cfdfb267d18120e4341942b43a6997da3b0ca","1b3fa4748462be57fd56d92e25a236fe43dc10b1fd5297223378f1fc89831332","2de29a2cac748ca9d0bdfffe3f553e57a5d5bff258d1b3986350e45889cc8db4","7737b91e383814ed909a7b3ca5d11407cc39c280050d811730fc9fff31883170","7538f62ecb6b4d00781526ef64e4772578cd2745c0c186109498375602a62091","4316a8948ba2af94b8bd4c37c4668aa7f6245c9d7cd268090322fd7093307f14","b7b0c8cd54466ce81c6b347281fbfc87017f67db10d175f0ccdc090a16d4eb8b","926f7c9b9fec048d3966375057afaa2ed59164e064029ddb68b8f891f1e0287c","7b6a7a602ad2fba193f6752472bc659c08c23a250241155326afc4eb46f20459","95dc54d0946435f20844b6dbdb0ca1158e02c9800fe1954bc67c5e6b2c643d88","267958dba583829fd86af7dd435d0c1de6cd61b6e49b166770f30d08ea9a596e","d3aa483f4e4b46fe7fc7e840fc99c1ee942dfde16579987c10dca7fe286b8a16","d18f27a41b03a07d2014714c62631a673cf276797806c236330f5fe764feb6bc","c4aec0fb70f7ab82582654e3e3f71a251f73979eaf3fcf5c39210c14e09f34e5","1c612a54ea4200be62bfda791ae9c32645368a1c77880f74595307b48a6cb39a"]
Anchored
2026-09-01
Public log entry
search.sigstore.dev, log index 2681187280 · entry 108e9186e8c5677a68da…
Expected log hash
6c4c4fe04f66541fe16d28c86bc42894dbce07874d32b961c3ed57a7667195e3 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788300906973","kind":"published-quote","locale":"en","page":"product:smallpdf/sign-pdf/en","quote":"I love its organized design and how easy it is to know what to do","rating":5,"review_date":"2026-01-17","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.smallpdf.app.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (33c00cd8782e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.