Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Registration and set up went smoothly.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
2ec0e867c812da663ec9717bc470a1415d2143db3c72dd1efa4d445675f78b76
Signature (Ed25519, base64)
z8rPqBcETkg3bQ77RPYp2Y52FdPCcp06xyK/ay+/RpS7FUQWqsUWhj2Va+GEPT++GIFEPLREgU32REVlfPBlCw==
Merkle root
3ac2a65164a98b25d6607e9cd20ce9559bf4391886ca2eae943b9792fcb8a323
Merkle path
["2ec3010a19d74ee9e429b7bf3e2fc8de281122af43c893d01d70e47f4d14656f","be6384d008a6aeaa60345f0f50ee84cf41220c7afc61b46c714d48e4e398a7b4","ef5e91fa76fc33ccefde29b7dea0d5ae6a3b3446a3a2d6a3beb64becf1c18b3c","13cafdb6082e684da4186cc33ddfd6164a1a888a863ca7f3aa339fa4d87555e9","1a698c53ee5d5168ceea434f0ed6e559ec924f7f9a34b6cdcf1ca789d3a9a41f","501c8cd77b6a4e3e47e51346006960dc2f926b68164009852287037c113b5af5","941530ce2acbeea0163afa8e4eb5eada7bdda63ec61763f9d66de55745b4ed2e","b6c448221ce31f151afb443962324fdbe9165d554d27bdde53f47d343b1ef140","3ef1e7cf8c3a4890bf303f0cca8dd5980dc80c84a46d6923477f392d87722f38","6023ebaf1d1d15a5db889e48fc571bff7ce121f851e48a84080d97010debdd91","39d0bb73d3c363dd5ea6f1636604a0d217c3fea13fa942ae215fcdd4dd99a9db","2094ab83c3c47e93e56205cdb18aac43fb141c04c25a12152217e58fb016ae9c","18d7e09a11c1aefd8f659754a760d772ba4400d2a964c6d68bd3555565e60300","900a8ed1297dc836a8b3be52e4e74bbac6319948157ba123cef010c147d9cd86","b933f107006d8bf043be83ef3bd88a04368b06893809d6915935ad1f675c78b6"]
Anchored
2026-10-05
Public log entry
search.sigstore.dev, log index 3083528439 · entry 108e9186e8c5677ac4c0…
Expected log hash
8816bf48c9e6a0b1ef2758b04fc7021824819cb4cee30b879cd603a10d38b8a0 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1791181418024","kind":"published-quote","locale":"de","page":"brand:mypos","quote":"Registration and set up went smoothly.","rating":5,"review_date":"2026-10-03","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6ac0c12cb673464a0e988093","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (3ac2a65164a9…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.