Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“this is the best free app for doing only a couple of invoices each week”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
13faac7572a6047d46761763fa0b2aa24a0a8b9ee48ac5a0feceb0f862b1556f
Signature (Ed25519, base64)
YgFWe9I6sTC+dh6uSfbfOdt8SbV7xzRjKoNwjnVZK68kQO4L6zIUA4lZISb/iu1svKuH+77mKKkTG//S49hlAg==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["13fbc72c090fc0cd58d49dc984120c20ca732dcb3636ff41b34f2ed32d69ab69","92a45f857ab758e305a8f160227a7a0a60fe44591cb80f0909fb711ee4b78937","ed43911e73da8bea99ba8fb3131e9c1fe21bc46422183dccfd2d5c01087443f2","8d13fa39e8f21701eda4c991c7f199d1b3914bcb0601964ada9c38cfcd3d8946","75a7c1b8de1b6a35b8cb7c76e04061d73efbe6e49be0c2b95139f8a9a9699690","cb1c8fef82f87c488bf8dec343fa89af0e34448b4f57844be9e42678a9a2d2e7","640ec58b2c76f729aba9834ad0c4935885e26940630755475d8ce29dc90dafe2","531392aca7f2cedc3e42525b422c785141c809e40bea2fe21a621afe5e091954","71fa99dfb7af1457fc6004bafa49530dce25da62cd6d2573fe039660d23560ff","395b180c77ccd11120a7cda4cd1dd93f02a32dda4ea752d18370c9990eeea689","3debd39a24af6852066a31af419923ca1fb9349fdf8444f76aef62b0f9a98230","7fc459298391904a3838099fd1a0b7e635c26503d7f861328c446e440a4bd8b4","5b47260d99d2c4ad6e0d963995c990c8506dbf10eb0b146a116c3fc6ba348071","a9559f2ca8536f2c18bf059f3f0099d62235a93ac35dc17b09967d392b72be7f","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"product:wave/mobile-app/en","quote":"this is the best free app for doing only a couple of invoices each week","rating":5,"review_date":"2026-04-01","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.waveapps.sales","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.