Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“As far as I can tell, it works flawlessly and is intuitive to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
30e40b8c7e352d273eaf836d3714b3a9d83bb6249bc7d2aea271a882173259b7
Signature (Ed25519, base64)
jl6GxJEs6sej06jPKeJtziaUm+GmMY9MR133cFwPjbW5orUj+aja1mKpoMbW3s0/eBS1OtvNfdoHJgqELfrMBg==
Merkle root
62390602d5b1801b2c96dd61074fd5810278db65461e368ee19c9bb147d249dc
Merkle path
["30e3372539e7efe6d8fc8f533e7aa95ea60fef73098b2bc996409d3b2ac75ea8","27ab170f850e791fcb42dd970bdd451bca0c90322ccbeb284fd764656f653e11","44326a918ad4437c9b9698023d339c1726a00612f65723df7e591de3683a80f5","bb2a69f1caa4418ebbb5194201ae95f88d0585ba00e98652b29e05afa1f09b82","385406c0b9fa99702e773365e8e65cb05b4cdbfca761d0d491de349edf10d986","6dc45916dea06989d26cc1fa34183abc55976a106c8e0e09186d357602a94d0a","3908a6c0a2aa306b0cae799ff2d1b745d3c724abf3c483a742d031fec22fde50","97ad9f9bef22f45c0646c346972a3c9edb03022be92b9fda8c9f7fa067d9b3a7","55c4f1ae51c300c1124a2bd6c640fad59963c19f6879119f281140ec236ac070","f126eae3217bdf9d280164d09ea9d9e5474c5f3a0a2fbc24078a5a916a01e944","0a81532ed18dfbe4c35a4a310959295e895a1eaf400073afc4a3c8be8882821d","c8a985d29fd069b48125bdfb11bf27edcb5cfa1446e752f56ce2bd2dd58dd173","f75f5f1e00dba7cc7ee2b8aeb382748de199073ec6ef3e4e45223ece56d4b910","67ecfe5896e15a16726f3975884f00c44d75c0b203d4245b5c0b41921a024634","9092fce07a46a5708f071a70ba5ae2d3ebe27de5e813ea1756180e7747d7c5d9"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515033577 · entry 108e9186e8c5677aaea6…
Expected log hash
458ac564101d02a2c8a5f98465ce4e920300682f0855e017234ab870c48a16cf The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787135948936","kind":"published-quote","locale":"en","page":"product:sevdesk/buchhaltungssoftware/en","quote":"As far as I can tell, it works flawlessly and is intuitive to use.","rating":5,"review_date":"2025-11-17","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (62390602d5b1…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.