Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Uncomplicated and trustworthy!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
220454505b2fe160016787c5f137db04878e634f76044b629720de56c095c313
Signature (Ed25519, base64)
kCywTphgBswewCtXsepX6Y7cY8XWjdHy0D0K+04hfvJvJTAR0F5x4nR5I4FVPtRd1ebckX/dQlq0mx7ibouMBg==
Merkle root
197f899fafda406e0c9d0591eaf3664c281655082dfd19c34045187b374127b6
Merkle path
["22046eaae1f49ea7615d56afbda8e8d99e633f8720ed5787c84473c155f0bc5f","3b7bf768d4e84a4b832941e443b3726feb93136bd0b56e490ae10b2971659efa","2e63fb4e2e339a6e5fff77c95999b4f844f82f47a8ce60aa2bbb2404485b4bbc","513440fcf8e956a8095e99b6ade64eb9f9e7af5355e5d861a9fc162c8762bb5f","85ab4920823b31d92ef31f755094eb5de5a4cfbf919f7aa104ae81f63c290af8","687bc488f7140f0fca1ab2d570c4ff3e8baa382a199f987cf384b9808ac6ca89","b55d75d01091a1dfce0909ad25bf69312f7c9368f2b01d7e57b3b853cfa89b38","1052ca6e229858bc0fad6c5acaf845fea401a2e68eda355c8ca538f064ed0635","488221d857cf9b1bcdd51fd8cd5e17abb4058cac87fff3775ad8138f73435404","76f3a85c9ed89664385894e85ba90271cf6b98d1eb64cc60829895d4c738a57c","47508bc9f102407b41c52413e90c185bcd7a8489738862bef2b9cbfc4de5daf9","41f279462ef17425aa188e387cfb84b2777ab44174b67938f7039ad3fc757601","474f5e3eb7f54ece02b72e34f56037226b5d12684c5849615376a356c03ed7fc","043ba08436a7a593c366180e52159485eebe8c0b0baf9b9c62f4c2c637b226b7","7b5d4c2155ce4f6908bf1c61cdd8b51ce48d7dc7c5d7f3bd9a7ce68fedb43f21"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514383033 · entry 108e9186e8c5677a6078…
Expected log hash
4e5cbdb3dc34f3dbd6a57b603e905df6c94968b41f5bd83d5c9a25f2ea060d8e The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787127398505","kind":"published-quote","locale":"en","page":"brand:relai","quote":"Uncomplicated and trustworthy!","rating":5,"review_date":"2026-07-24","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (197f899fafda…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.