Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Functions are extremely difficult for the customer to implement (e.g., delivery status).”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
33b56e5e34f963da137b29d7662b99075ef411faba288688c6443b5b7a24a335
Signature (Ed25519, base64)
mDVhfVgyd+kB86q2ttC78TEBpEQN1Jq7FahhSU1UhklrKAQv61KyYAMsbXL+MwjMwbrBAcTXvRiUVZZO+byzCg==
Merkle root
13d851a0949e31431bfa3cb9a632b995c3cd1c62cfaf1eda783bd9224fc47725
Merkle path
["33b5fc4888b6f9cf4f5521c62f32e8e811e8bf37e38855b196db6550fce7a549","6481f33b2031d35528098f5407b75d8b4ef74a97313eb7673a6ad359aca37c91","98ef7cca67c51ee71a8b730cb01aefd4fc412c02e06b6ad4aa58925606b92cb8","ab1b5314a157f36f6c67bf6ffde78b9cc74be149d38afa216e86710d65a631a2","8a4c9a18f4353380954efa79372adfb233008fca551389bc54c0f68622a56f3d","e84072960c41cef287b21c17138b2360dc838be37372b278680976678c1d7708","0d1f9419ffe07483d6c33fedc23c428f387d3ff98aa85199b36659dcc9fb69cc","fbaaa4febe0b911c07fd397a3461d447ee14ebfee872016528940dc0d6ace99f","e83628314a20687e8ce9f118764b751146934b9d781726290a806b8a8a8c1478","565edef98bded06271ea56bcea2e8669e684ca8dd2f0acbab6b0a34d55575030","4da27f4bf2c032ff179beeaf58384b713b8dde30183425696585c14ad346afc0","a8f7acf9b6cd54c646cd7bd9b5039bf9ed3fbb62110c855f7dfe16810722b2af","def79475a5b87d823ffaa82cf9c802a7968dccfbc8519501ee364e037c0e7931","9c23963b54ac666752e013737b81ec6a31e3529ac67f9360ca3657ae9a4b72b0","bc9aae2a90fd8d311435fb1459ac7953f7f2923aa1b697bb0b40101796e3503b"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2542342116 · entry 108e9186e8c5677a49dc…
Expected log hash
44bd329b5c5f42e4fbaaab1e9a27845aedd26351446bc96ba12b520a563b7433 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787279544668","kind":"published-quote","locale":"fr","page":"brand:cewe","quote":"Functions are extremely difficult for the customer to implement (e.g., delivery status).","rating":1,"review_date":"2024-08-31","source":"Apple App Store","source_url":"https://apps.apple.com/ch/app/id583713833?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (13d851a0949e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.