Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app is compatible and works well on Windows and Linux via AppImage.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
139b09a94e3d969d49c4315deba2d23e112d37422d1a7e9df323b086f9d144c7
Signature (Ed25519, base64)
vuiOIn5/shZ7Yn5r520pI/2cOL4P3MqWiulKCGzWDtevXrzANx9OLQuFvOZROdHd+e/xd5Qp8PES6V7cVf71Cw==
Merkle root
0ba1b80ff2165a62bc9f9f25c7b671d32a81a8e4f351546efb788e090f369376
Merkle path
["1399bfc6856402e7e2549a733b6b19ea191c93d69c61e1321be7c04340f8ea48","8edec76fdfc556cff4b4a947921d6d69fccd49f624c4dc13bfe86266dcf80da5","246744d10567f0dde56a208c39cfb68f64b824957a5068a95d56fa6652bb6fa3","e71a0da8a2545f09a7ea4996e1c46e3f691c163538ec95d32363e824f8114257","613aa9d2fdb17ad885d4994d99adf888e9cf854c9b8a97461bfc7d1084cafd17","30fc65d95af0775daa968924303a10caf43ede8e6b271b781642dcb2d42123fd","298bee2508b5ccdd91cd32f0908c9b74d14b48e562e17997b43d4152a216af73","25857b1174d48913b906f99efa758a131d8e1fa3c29c1b312b064b19fa94985d","83c8eaf9bfe9ce5c52a7a44f97f0829e1a088f4cf4f28181d995a2174e2ff99f","d3726eba4573524b7dd12d159a2ebaa8f73435b353f4aced3864546ce5fb3e04","33cbb318f490ec551167ede4eb9b00971e159d649fefae9f22b109b357c3edfc","aab51e2412790f739095eae6d28bc9b4f817dba064b561c920a4f60198d031a0","034ae9d01226d77eaba75b4d19165fc2dcb9e68ed53458f6ac6eae0fdf330abf","e3bdd9cd4a46c1886472a1771a5799292b1c8a1505c3320e374180146177f347","9c07fc5299395e9629e50b7f7f3c0b3bd92e7116744c8ce6fa87db9d24fdb3b0"]
Anchored
2026-08-29
Public log entry
search.sigstore.dev, log index 2632728886 · entry 108e9186e8c5677a444c…
Expected log hash
ba382b40bcccfd5823af39360159e6e4433d6ffa61f32bd2b6c045e496d9f4ba The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787975494243","kind":"published-quote","locale":"en","page":"product:infomaniak/vps-cloud/en","quote":"The app is compatible and works well on Windows and Linux via AppImage.","rating":5,"review_date":"2025-11-03","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.infomaniak.drive","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (0ba1b80ff216…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.