Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The findependent app makes investing super easy and transparent.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1c6b8d2099561216440f368bde26b9d286eacc42ba81b1babf3420c82927c65d
Signature (Ed25519, base64)
L4T3LCyfL0pYxDIvwBlvuY5CfSNDaLa5J2h96Ydz3//HVhR8f8XOIt9hobEv5E0aGbi36p9Mpp2M+klNGQh1CQ==
Merkle root
f0c601bc37f52c70ded17f76faab5612e674bc087c8faf99b4d2f53e921c2b03
Merkle path
["1c68b00eb5d708c7e12a328cb87f5ec3ed357ef3ed408c447165d67395c1ed92","6d5f8ecbda81de0b1272257d3650532daf7e5835440fc5cf2c2d1fc8be1a88c8","5d041c5dd14d33a5a5600a89bf65bc9d13ef0d5245a2fb81d04dc1a90a690976","68e725bd8a21a320e8949a0fdaeb2195535abce228ff8a912570d7edbcab03ab","44a63fc15ae70e11cb102036c8e3958d96644d39b64e63a06a89eb5a9f428334","0877565d3ec21291af136a9857f137f6bd9087ec1f2c5db171c4a07b4b4965cd","3ddeeaf4b6136cd2a83a447d8adcf5cd18cb8f8fd94332480b5030f7d4fc56bd","2a390550013fa086f251b0bfea2b3afb78953abb3ef4da24bcb8fc42dcbcfa52","0cc70c952c85597e631c0195b07c57b9dabb9a9355bbb60a3d3db992877b2966","e444106c145cf368c6e4e29e4a125b72221023835e6efdbabacc409a8004bc32","d0cc9d1304beb11ef7ec8bda5eebd1618d795810a236c60e2bb98e02493f20cc","ece5b7624a8b788460f5bb1863aae1b8199ac67fb6f473f98a88c297b38dd241","63626d343fc27f295a2ff318756408f19fcf6ed8639844617fa9d1e202804a12","ec79f032c08fea2de521a7794f897a556ed84b17f8ece659b547d74d3137bc36","d5f5465b6d70ec9eb5fa4b73b511305c1b686def0c98a0246e8a4e9838a04a81"]
Anchored
2026-09-01
Public log entry
search.sigstore.dev, log index 2671768867 · entry 108e9186e8c5677ac984…
Expected log hash
bb91227cb78cb3334e4fa0a34a7640fc05bd48061b2bb5126f5713e7d64ceade The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788238642169","kind":"published-quote","locale":"en","page":"theme:findependent/quality/en","quote":"The findependent app makes investing super easy and transparent.","rating":5,"review_date":"2026-01-07","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.findependent.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f0c601bc37f5…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.