Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I find it unacceptable that, weeks after the update, I still cannot access my orders/quotes in the mobile app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
106ea605e05d6ef274ce46fed4f4f349ee7b3216cb3dcd08adc71e377fe4b5c8
Signature (Ed25519, base64)
OStiIHCHYnKkkk3pYuDX6jcTphIg2Ok2mnGx6fTjHhSYBPx2XKiX9uyZ/8frTaOOrE2Rp9WcNCEt6/S1DtFuDg==
Merkle root
2030d4ef17fc68fad1320305cf569e85a00baea931fba0d3ebe628cf9c90c35f
Merkle path
["106dfd94ae4426236ee1c232d2f0cf436dac966795a6f4e0656dcc6edbdce4f3","03060f05d35a2fb8edfb37df3d633f51feb269185661adebfd612a83aefae82f","edf00c440e0bee57cb4d1fbe0a67863c1111e46545ebbfe0fe227ed8d142ca15","74367ba6eed632df6fc62f983106b7f4f1155c2c0980387d18470628dcdd1986","871dd400d95ae42a00678d48de4c8f7347fe77610bcb2dbd3f1ed71f9180a5c4","27291a8bdce6f3f86b50779fb0febc2b03ebd8af4e375d2d6c6a5265b768490c","87fe738f2ae976855137ce6aa771e1be007c1bf4da354069333674f9b72e7fe8","62d18bbfeb81bb019d7f5334aaa3869484beda8f05d4593a497e7f9ee91e6fde","926a71d97077bbeb7994853de8eb582bfed372c084f493318f3e334e0ae647b6","318699dfee4192be3bb6991b89892d9e3a2d781180e396f88f50a324091277d0","053aeb2882a40cef67f04682285457fed3d577e11d90ea5db39babebc61c3c10","217c89d31a17046b10361dfe1c171a079ca6f41a95c91fe077d21fc7059ef5e2","918213bbcd6c7aeea281036e9f4d443f99addb7e227a2f8f78d8ca7cbe526c6b","bac51ea5b704b29646e9427857e311e108c5e79191194f7fff260047321ecdd7","e362b663c2c1f5a93380a04a7aa41b42f4bafc7f870e85cf63803f76c744c486"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514654467 · entry 108e9186e8c5677a9253…
Expected log hash
ddd8d6dfa3771a4106292f7bec674337dc9649465b28b118bb17bfc2b8ff0a67 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787132872903","kind":"published-quote","locale":"en","page":"product:sevdesk/kostenlose-tools/en","quote":"I find it unacceptable that, weeks after the update, I still cannot access my orders/quotes in the mobile app.","rating":3,"review_date":"2025-07-27","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2030d4ef17fc…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.