Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I have used EmpikGo.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
36f1db874d4e383f124aadeeb53f5f737b5fc55fa4adf5e528d930c616be85f9
Signature (Ed25519, base64)
eMKlqAhgyj6CKJ42o8qGiHyIlwGy5TT6LjfqDK7taJzHlYRhrcS/s+tZT9xaYOUXRL1z3lUqG6o6vA4LvY5uBQ==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["36f2b19c32eedd978dd22c81f0fbeca6911764b800a936052faff8bec1409e57","22313be2757b13e917af54c0fef164e92f0ab0c6d812f83010eea703adc8348f","adfeffa5fbb1445191471d4a9fb7eacc67f749eceb2375b41a7ff90b963e726d","70f87526a41f3c18a688ca1fdc1b0f0708360c7f720fe829973a59a367aaea75","292dea1c42a3f7fc7ba06560a710346619a80ea65b05fb6fd7ec92e373fa1d14","d7ad12100d1900d0306c04cef560345a9cc41a055bfab00c30b8a77a040ec5d2","00bb62126171b01475326559c10ae438381e00364e53edebcb69c0210fc5e11c","9743a2f6e4c34f131e66690a796607e3d22dfc9c9bff9a3571df6257d9a9d888","44d22b7616b33b54caeb9d34a02eb7685020c9174b7c8e309fd2c20d3daf0c03","a2c48b210887d78af2726a13f98aa722b185d42282ef19d24a24a7070e9bc678","d50558677eb3b34fd5289f4b3a387bb41118ee6724c345daea7bd33ef7860d83","00a58474486d38878667c018eb810e71180b9858df79c82d171ce5b4f5fcd15f","5ef2d0b70398ea508e6c490819b91bf39069023f910bbf3a50f0ba400757578e","0cf751b4d000491c43eea40a33568458d763987b542601ca0644e491c0b04ce6","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:audioteka/ordering/en","quote":"I have used EmpikGo.","rating":5,"review_date":"2025-09-23","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.audioteka","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.