Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“maybe the feature will be available as a paid upgrade in a few months.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
41acb9228a477034362f7111c9a4aed60f54328dd9ffffa36bb94701933de844
Signature (Ed25519, base64)
EHn/7vQ/cULl3uv5w+R7Blp0Bht3w5BrEV7/vOlZPkZ8hTxn3FWcEIRAUfKLanitV96sLxkoRws0k8PtgVINDA==
Merkle root
681242bb8cfa94d3b60cc06de1bbe3e5e124dc1675276b11df0aaabc9faee58c
Merkle path
["41a9461bdf5ef8307cd2aa3d55d90cb7795b3c71155f91cbd81bbac71640a1bd","f3bd437cc2825e720342f4fa6cd7bb1cefc3237664ca5bcd1035c6ed327bca4d","1be321876e95de6b2ee28b6eced83a4c5e019c4731544526708041353942a629","b48f4b70c9ae6a1a28321ef1cc3c09492df183c8d9043e2151386e7ffd90061c","5161500754389c8aaff11c3f635f9563b58628d297b63ddcafb385b88907ff04","c704e172ea403fee94318c60f508f2f77ec6748071e1c363ecb88582620b4ebb","e4e609d8dadb25cc59cc5cf9e48ffc339c3f163bd2150a0ba5b7781bdf6b08ce","955e8c440a01a49ba5b02a813dfeca3affd438fdc1d80f2a643344dd8c8e762e","257d59ef38e59bc41588dd401a8b667951f564bb0b2f5a84dd1a36e47a2d5ed3","cac8b8639e68c38aa0a2427848f864e2f8854a7265a56e465280f9e53b1eef66","193c8ec985e58e63082c7441e9f9bd5b88ae4baf809ad92bf75402bfcb40d80b","97ce548aa17d964696b9f173e45dc7b64b9cef42fa2655d3d3423462baa6b078","ca35c0fb2a839613499bd489c6b0c2aaacd771cea479126a5506cbbc9ba09ce1","018848b1e64bb342ebfcf3461012f852a9938ad88239203d89ee764353ea1567","78eca2193b177c5ad7546ff5d365dd6cb79efa278dddff5151740888f319c0e5"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2542879916 · entry 108e9186e8c5677a2329…
Expected log hash
8337812f20bf1207a3c96eed87ab975d7e92ac1421dcded24507b32e456b788f The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787282728402","kind":"published-quote","locale":"en","page":"theme:sevdesk/fit/en","quote":"maybe the feature will be available as a paid upgrade in a few months.","rating":1,"review_date":"2025-06-05","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (681242bb8cfa…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.