Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app doesn't work at all on some days, or is very slow.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
18d16d99245ce7176619050ec04d8bad770e449a6dbfcaa1e882ded168473b59
Signature (Ed25519, base64)
GbHDnVRtosUOaLuR2NXMIeDTGybx5JjpiU7yG6fw5hFBRlPJz3WVW1xuZZOwXNMBu8RhM1jGWzXsrx1mQtuQBA==
Merkle root
2465e26c4b328756360cf3c8bd618981f983464c9d48c736d4fb91963c7bbf37
Merkle path
["18d3c2ae073dd22ac2d1f932902b491290d18ef8e234f0d72ac259a7774345ab","58fbc7cbd535e257c2da15c1b5976178e771c09411e53f358d63178878b78096","46f225866842d2e14856e0c3d56b5004f614f4188c3463257f902bd54d8eee80","83d5557f9d38ab5ded30b9f923ea2550f8f5d3609dd527f02c85b30e22a6a264","39d0befaec5c251675f8bbf65d50457561eea337e0df40fe63073dd83899b9fa","2f794a1caf9f4b9c83a13d0362b7635721c81b0eb12de61a739e2e81609cbd46","4b8a916221257f54eeeff0350a62601ae47eb6f37cc7ab369036ee741917d07a","8a39d0faf9dfddccf6f35b39ba9c3021e5c00dfc9d3eaa3d2494bc4ba13d0943","7a82538f1c15481f38937e9d9b5d5849a85bffab4025655018525778dffed684","dec79354fe2c840eb706f8eb435ce19165e0c60e8737d4d79c2481340adf62a8","44cf1912ec0790525ecfe7e5d723f93f115c30e9d7523ba9f9bbb85f6145909d","3b100a5616b7f63143972892ff75479b15e8bd9a7720b150f45d6a64e586d7a5","890a1abd2d97e7629a6c3241dad0830561cf775313bf20b0e0198372a65fee85","9a0d3502258f00e9b24fd47603847077e05b6024ab65f18f18ec973932102f2d","e3610f98da8c8899ed04a68ebce82a0c000eb56ae4f4b5310bda2678744b0012"]
Anchored
2026-09-08
Public log entry
search.sigstore.dev, log index 2754384098 · entry 108e9186e8c5677afb21…
Expected log hash
0b88e9e5312b5a2c365a5b5596b5d4c442b848d1dcad6ffb77cccb8d8345855a The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788819235128","kind":"published-quote","locale":"en","page":"theme:sunrise/communication/en","quote":"The app doesn't work at all on some days, or is very slow.","rating":1,"review_date":"2026-06-21","source":"Apple App Store","source_url":"https://apps.apple.com/ch/app/id466738063?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2465e26c4b32…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.