Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app is beautifully simple and straightforward.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
125a8a96d666bccb335c4511fb986fa087ee780d1cc760e2ae4197a9179fe697
Signature (Ed25519, base64)
7vfNn96CCUL9bzF0Eu7iaeQAt4FOigkKkkmMCvGTpdqPBcbBzh3Zqn0ADo4OeeQGGhCFm+/lA3emQlwfxiubAw==
Merkle root
e6ac019704b226508e994cc0855a4d192d5ca56f36bf79e20dc9e3368a99cf1c
Merkle path
["125c8a7c8cf1320493789466c520c72ca2a3f130ffdf020d1033155130cc78cc","160634102d102ff00e7a041007e1b9e3cfe4af9b68c66ee3241503def663995b","9b435200719866df778252c0c0aa6698c73ffe5ea3e6f0eb57589ba8987416bf","0d9b90214857aaad51fb35b0831a45109da610beaa9cb4ff9c7ed01c093bb61b","ba7c01b6ef2c65b4d58b233efcbf533dd24d45c58108c687971d26068114be4b","d671bc13e1b62a011b3027776c59d517e13796e4b04afd44ea8d6fd1bb097583","d4935a9894393f628268e42517286bbbe3f551169cff98acb435d30ec9bf53c6","092b6b87c5fc8af88654ed3975ef24b141e5cbd07a62a0e7dd424e338705715e","a67c98cf029312588a5b9c5d987b7bbcf500e27f60dbd7da2cba76dd099459db","ecb8f41bc31e5931767ba4f4c80331478c12cf7781c522f04f81e6e087082d74","0b5728ab90256078d612e6c073a6a29aa05b8222aa5d6067e790c655c5ffcf95","76aa14c6b140f882f5a6ca82e1bd3d30ada81e6f9ebf68b6cb689ed74e97d2de","af32e6ce7a9c3f92995c628e9a34041f7ca98856143c57e4fbb6f9b1d2e86f88","300daef4aa548e8c10fcf4706d8cd6c134a74d44a2fedd09c528770268883f87","55037d90ebc6f8ee5750b678c0269386792b0a1b293edb3e029a7c8e378291ff"]
Anchored
2026-08-29
Public log entry
search.sigstore.dev, log index 2631716425 · entry 108e9186e8c5677a0f4e…
Expected log hash
45ebfa784ea01d364c463997b417af34e35327c4187ff9e9782aece8c325deea The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787968874252","kind":"published-quote","locale":"en","page":"subtheme:meteomatics/quality/widget-functionality/en","quote":"The app is beautifully simple and straightforward.","rating":3,"review_date":"2026-03-24","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e6ac019704b2…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.