Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“It's crucial for me to be able to create invoices via the app!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
13e765ec6a715415123ad406000cec589d97d9dcb20da93430198849751521de
Signature (Ed25519, base64)
zT/x2rMGmi6upldL5UT49CZ6lvTN1SVTawoAg8F9z9j5JcXIUuwtyrQJ+U+Jv8AjE/SjwXwVgET0BbCfC5v4Ag==
Merkle root
197f899fafda406e0c9d0591eaf3664c281655082dfd19c34045187b374127b6
Merkle path
["13e74e4259db808d4e2ce863a2f8dbe7e9fa22c4cc53ac4e0c35f93f47d0f094","6fd6324f40178a0b01a5ca21507625155e81647a916fb0c3fe2cf135f3630652","2357b563fb490c4a1f639810ee790cefaa38153cadb92c8d0ae662526fdeea3d","5fcc80457dd52a9fe5e0e78e29cc71d8d15561b0083aa14427be325fbe166372","75cf9cf1d1941c6423d36f5fa5d394617ec548b80c0862d1d391b3ad3b15e2c1","8bcbef9e5efea14685bacc61085bf6edda741ddeea5730b559f37bfa90fdf442","0038786f703c7fec5843e212088d9f0e5b2869e657d1a4722bf0027a659d59ef","c42806c1709c34f8fc1d24219870c9ec14d034e3d8280099264a2666412a788d","00c2c2bf30528c8622b59e14a295e6c5ab28bc71294109f6d994558ea66e0cca","69d587faff01f99adc480b247773d7439593b79cb199a8f07558c65fcf7c6981","b5571d3aa598932897806e02f48e0016701c260085a00c41938774111e0f3fbc","df8a7c6e5cde16b4c4ab3a58a64fe01086f546e7d0c17890ee9b3ae44a54c23d","474f5e3eb7f54ece02b72e34f56037226b5d12684c5849615376a356c03ed7fc","043ba08436a7a593c366180e52159485eebe8c0b0baf9b9c62f4c2c637b226b7","7b5d4c2155ce4f6908bf1c61cdd8b51ce48d7dc7c5d7f3bd9a7ce68fedb43f21"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514383033 · entry 108e9186e8c5677a6078…
Expected log hash
4e5cbdb3dc34f3dbd6a57b603e905df6c94968b41f5bd83d5c9a25f2ea060d8e The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787127398505","kind":"published-quote","locale":"en","page":"theme:sevdesk/communication/en","quote":"It's crucial for me to be able to create invoices via the app!","rating":4,"review_date":"2026-03-14","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (197f899fafda…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.