Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very well-structured app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1dc509041a56ebddd93acfc9a6888c11eec408732102db3ab8e39f9917e87d64
Signature (Ed25519, base64)
1FJHDzI6eyq67K6mH2Tx2uo5CGpIsRWheiiPK1xCEfOHTXH9YeNK07oI6c4NDVXv61OkjGOImnY+m7NgD+zuBA==
Merkle root
8d929b933d3da853a342174568dafd4f2990c556a59a904f6c4eac8eca263c18
Merkle path
["1dbff9e2e27e2625279c5fb4a394c2cac5f7158adda9ca20d41747022898f4be","70ffa4404a358255b9c380d5c5ce0a4cf2fb18a4b3cd0dab7697c7ec0a4d9426","6a00199ebd41bd4638f05c172e48a37a4daba6907278f3bee4ba94c864ba5908","0ebd40978e539614515ecf6b49f764781145c3b345483681d76db25b5181652f","c5c6b68c89f9cb953e05bd7caa0d04408b9bc836f4bf324324e4356398507fa5","048fe2da7eef0fa0353cfadce7eb61ccdb1f851e14c41102424918a313c6250f","3fac123929b0b02d38c422d1627d78551ae51e6054792153c3853f1960ac8221","e04d04ad1f94d550d45348284430c20e50b7db08e62cfa3874e3e9c43946ed97","ac80557e8a6f041022ea6b5a497a5a9a6e14b563e506c3a3179d8f3fd1c76332","d9239e949635978176d418c979d96e224a5e97582a5a5bc7345cef2851eb89f5","d8f9089bbaa166b39c66d8d46212baa18bbe6e974865684197ef92ea197094ca","0b2b4f40dcdde808f62b3e4ebf260be017a870e6cfdcbdb9db918ce3b9a44669","db36e5683a162968d642d2b33f1127be2dcf059690ad38add1e5db8d7a7a41ac","9576369f408a7fb58ca2e97774369b4e7458346c8937c3d02549b43f61f201e1","67cc9c31bb9e37342ca834f1c2afacca9d4e9ea3aa24cfabf98f677678d81a55"]
Anchored
2026-08-24
Public log entry
search.sigstore.dev, log index 2579616312 · entry 108e9186e8c5677a98b8…
Expected log hash
169fea3926d76eeb6fbcc1ed6cb8bcc55e598869705eefd29172a719878e4a1c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787542624469","kind":"published-quote","locale":"en","page":"theme:findependent/quality/en","quote":"Very well-structured app.","rating":5,"review_date":"2025-12-02","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/692ea6605df4cdc1978fb487","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8d929b933d3d…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.