Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“the data would need to be verified”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
3bea3d13f6590015f87e7ff399f91d061722680900bb49bcb03bd635533883f9
Signature (Ed25519, base64)
JaApx3SN3ezUYxzVT7K4F8zQrm3lDKlh7Aj4oD4VqANxUExqf3+1QuZGyAZjjzwI34tYoAm73F7xdWfngS32CA==
Merkle root
749703591848535a8600340214debbd99b61273e3bed402bec28b292f90ce9b6
Merkle path
["3be90128fdf89b655b6f369df0c8f26803fa2db864d74ddd2e864158274a2c69","a1088309599c6bdcfde275e0b3520c18c92a3540c19afa7ba1d39ce83cc9f79a","389a393ae8794b86db016247c286a38a0ee454aab7a2faab85023f3caee8a474","a86ff8ac7e4945eb6e8e310b795d82bdb48e5a519677c12873907d0ed1ff2c0f","13cdd5a786ccd51c3179150f9a3f3201ba36b27d0865588a39d89b5b6ba0389a","7471251e71f406d001e0a3da12c5750dae085d6972cba11baeab892c6e17c849","6310067b1cad0edb082d2197d0bed508db298d3b846d3f9eb1f7acea8352e358","52dedde95d86309e31982950d0ec67263b4ee68874074063a218b5ab8b7ee714","eddca7f8e8f9b60f12f3dde838edcce5ca2befae98f3abc3cd70148bf0267a32","edc8005fde5c470c881d08cb44e29c747897e9581d5e14b4cc45bb1cdb8c555b","d9e43a5647eca40fd598cecd8e2bc511220dc53b6372077ab1b93441bf002b8e","e04edd46730d46a7231a44413f4b33243664c2fc3601cf38f9b64a55bf2c2a61","a2915b90b240e669a284e589beda484d5a4772c71c4de2d4ce016ee69aa293a0","f43a1936699be5b728ab2cee5100b0cce7fa6828f7bb521f1ba149ba44cd48a1","bc5d1d560a30e83fe0f1b6a9452dc46dc135b1a7f73575ec3aa5d459bb76fc8b"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514602687 · entry 108e9186e8c5677ac525…
Expected log hash
e53e7f935eb508100ef1046b60c784e0bda15dd54afae176c275a97cf1f64052 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787131269839","kind":"published-quote","locale":"en","page":"product:relai/relai-business/en","quote":"the data would need to be verified","rating":1,"review_date":"2025-10-31","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id1513185997?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (749703591848…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.