Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very satisfied with using it on my smartphone just as I do on my office computer.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
10b74007546ed6a62705d3263a281ecf4a80ddfff1805c56676a785ce5b061a9
Signature (Ed25519, base64)
xxZCIwcjVXfrKHUirwhIDpCMfpL5/981YnCADOjG5WE/CcyXZRxOU0zPCwlGmk+aspMp0m0ZHI8htGKguyExBw==
Merkle root
ce02f748e6331cd02eca8f57641bb910cfa3ac6a0583f19c214186c96cd0e8be
Merkle path
["10b74827aa82d8f558693569670536587fc4c4dd2e40abc3229cd02ab045ea2d","5c284ac388a999fc0590dc7e180bfd78dabb15371704c546d1444e310be60408","d4b913b00d092a6a77153022d81a1e270a184a0e2bfa3e751280153881578da0","146dd9e50b8d79e462b9251fa29bdd32cc0d047d6ce9876cb58ae8c1406db9a9","421962c9c08e3f1a62190c4bbe7aadb945cfc5ef2ac3c674ee64ce394a96a3ce","52e0408160b84825d43cf07f1d65b1b33fb840e7b98eceaedf460b6b529df73f","02020347d63ca30d40e2160c9d917cb929da02b7b9abab3431023c42c1ffc75c","4eca4b8152363a4019a6ca92ec3a88d1a5da09b17b0c0afd24b6481cb73e0601","44eac5426cb3a3eeae8a6a3e7c31f4a7db52bd03d03c74bf8871c7827fc28cc2","fa35624da18dd59298b05fad3f6595fdf79f396aca342ad574ecc34be9cb33b2","da644d555e538c7c981ba2b58b54008d76800b41edb7fde9e57f8a4eddc673bb","b32c84383744c57b015abb43fa1400023699589bbec65b98d5d9a1020542c84c","2ca5fec314a169184d28bce72e10be4d0dc96e78ea6b0fcf500eb6558685fbf8","1bc99d2925512f6c847da60b09ad8a40a192f29b50aac2ed7ad1b460e9e23fc9","8475fb82080060bd6fa491c94e8e1c5001264fbf6fc66e6998631ee565101bbb"]
Anchored
2026-08-25
Public log entry
search.sigstore.dev, log index 2582604655 · entry 108e9186e8c5677ad979…
Expected log hash
3437b01b95be42f034b7198b6d5e9c0aa9b5bd388493d56323aa647d6d8ff38c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787626024249","kind":"published-quote","locale":"en","page":"brand:bexio","quote":"Very satisfied with using it on my smartphone just as I do on my office computer.","rating":5,"review_date":"2026-01-14","source":"Apple App Store","source_url":"https://apps.apple.com/ch/app/id1481169504?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (ce02f748e633…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.