Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Anyone who doesn't want to give up all their data privacy should stay away from this app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
340b83413bf2706f4ff54fa4fd45f16c6e1735f991e17a22a5b9d805e23e537a
Signature (Ed25519, base64)
s/S5vFhKQ4tdQsa/ZghDpT/Z885aYNxwoP53KsEUaNwXURr68xKdLX6YjYcTftiFnlSuAL2iTSmNIgxMwRj5Dg==
Merkle root
c921242d78a65e026e3281000ec5ef04ef930758058c4fed3f79f3b5ef992cde
Merkle path
["340afbb560a6b9a17eb0b5906be8ff95c52dda8b987b2b892b777334c1035078","77cc8481c74676cced9e294a2c7f887e2904e6e079370dbaba62be4e147f340d","df0c956bfb8bf32f4240ba68d02057193f4363c8e9f569a64727c984794135e9","1a559f67e171cee18442fb468d84dc432a409233d84618900d10ae35da8274f3","9da105a478b927950e37b5e8065440b131fc5006609d7017674b99034fc020ee","c470c6710367142783b435c1fd0864475ba3e9a79dd81bc7915c46a977aa8e9d","3f8637a275eeab61865b1d222f8b4e2c02a54cbb45bb044c833764b75aabbb55","c0b91901eac944c159263d0b26bb69edfab131977f3b2872fcbb33589a4ca199","484180b1e494ecdeb3fdaa6e1458f11e479879b390a523aa3590bbda2d0c9978","c392ea0092133956b77e6853ea98d8186d50c433f350405c1f291655e6e2bf16","3c7435e43c83c03b1ba40a295d4666b439c0dc2fac13e44eac9d3230203b6dda","fe73ce509a77325b5ffa3ce5d771087bfb0281b53fe18b6fd059050b1823b872","affd4e3e6ec270a4ab2ae23163aa1a6ec143fc7cb3b6399ad8156d5289cce2ce","a3747175efd8cc3d769be29f15252da2dfd09eccbeeae76e08b0112f75ae1173","522d5a6bf348351e5632579ca190fcb390464957ba4b4698b399695ee13b67d6"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543700701 · entry 108e9186e8c5677ac7e1…
Expected log hash
c1abaf0323b08bce2cedebaf1993162920ee741ace8973292e7ffdd13aca356b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787287374804","kind":"published-quote","locale":"en","page":"theme:relai/communication/en","quote":"Anyone who doesn't want to give up all their data privacy should stay away from this app.","rating":1,"review_date":"2026-06-06","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c921242d78a6…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.