Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app is intuitive to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
20a9624f11c3a64e8e74763f210d715472631b3d02fda3b75dff52d6b0231dcd
Signature (Ed25519, base64)
rnv9mZJF3LZPgYaMsdx09ujIhML0z8idv820K4xPNT7FW7Har1rfJUWCLTvfoFrEPX/ZtDTwcyiIZDC0A7d1CQ==
Merkle root
72711ef72b8a7ab084630b9628ceb2defcf0aae546304d44ed173db57929457f
Merkle path
["20af0f50d05124368471d8f671c1218ba2df0917afcd4bd7af7d132d8c83faa7","92fea9d1251b458592ae547ffd1e832f5a6a1c06fa363550ccd2184951fadb03","55f52850b9166786db2224948788cb51ab5f76131f73e678611fbecaea5b14e5","c4538c671473db63996b37a6f2a48df520fb3075c0a94c39931b1d1571690940","25b8a3c8c1f7a7e30394cb3dbabca5013937a95019fb3ae882ada8c7c49aaaf7","78524d9a2a0e2158cfc5fc549072fe95d51fb0ab5b2b13b4dbb91ef975039fa2","89612d8ff899297267ed26ae4bf5fcd75f34868ca790f5b3c2977523da8b73a7","409be7e23320155be46ff76f973822b2007c1556b7618dfd13665048121f919d","21ba61ba714d667615e2cf13095b9418744946e00c11c2f089dd379b1e583919","1cf7a21dd104e83ef9e7e8eec77b5c4e5e6ae35a096e2fa0195fc2fd3cc7db81","e67f89b8c0a4633d6e88da75a6e5dc25e0c9354c9f174e556f4b51a197484a27","6a6dfccff9dc241f298e0a52411b762bea9080a6c51d433e9025bb218ea1e106","135f944fcf4a92d6f5a1944e44ad8a4edfeca6c93156b3f0cac35c7e930312a7","768946b507e7dea873e9570265486799703565faf3780e57d953562adfb568fa","6eb04938b6a483bb163369a1d918b32576dde0943755b89bf4c6d18743828ba3"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514130917 · entry 108e9186e8c5677a3273…
Expected log hash
65ba51eff926c65ed0ce093a942d84c628d811a59302f32867c6589627e47792 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787124488047","kind":"published-quote","locale":"en","page":"theme:relai/quality/en","quote":"The app is intuitive to use.","rating":5,"review_date":"2026-04-22","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (72711ef72b8a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.