Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Demanding private invoices just to continue using the app goes too far.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
42f5c4eed4b81667ab75caeb1630855e49aa450e49db6efeb0571292c47f1b6a
Signature (Ed25519, base64)
aW/+wwo2lF4moNlSyMbDOiTvTZgSXutNTka/AH2DMk+M2mGSQILBP4ZRWvDKldjwFHjEaHsTSvlXvqw2w+cbAA==
Merkle root
2030d4ef17fc68fad1320305cf569e85a00baea931fba0d3ebe628cf9c90c35f
Merkle path
["42f0fbdc21ae4eb56631e56d818af5efac84f15512b9badf335eb8286d473118","caa2ac3d9f834a758bcab7ebc094543f0c8ac2742dab954c0802231e1951ac06","527cf2b196bb23ea004b40bf233e37c6e571c1abbb6ecf7c7092a8fd420601a5","12efdc9b2cb37604ad1ebc56bb21cae8bf3f69405b56dc341317aa06140f0149","68e393bb1c92b0fe8dc28e72ec02d3d2f06d722f7ad5814fd2035f69e38c96aa","768b2f89908b9a225fad8011a5ccbf232dc05652c82e3e56ac267bdf41f5bce9","44601464ec4247852ddc2ee7ce27a2c59efb4a4fcdcd7db0c01be8b20637a33f","8b650b7475772aee45115cfe1a2cc6df7e58635de3c7408c5f1a9a0af6f1df87","981c6ecfbeb1ce1a251b5a4de89b2372eb45149c8052796803616198165f6e54","6b329e1142edcb519b9eeff4a52b933b9bf88cdf426fd847ed331d540c88eef2","cad5ec49df391490c9f6da8c3ebe12e731ecfc53f27aee36ccf9b34a9d8e873d","4c80fac9a3e2bbcf6ffb025e3533a28515475c498708bca71247f8bf54931d04","3b94761186bdb870df8b4ec2f52e7092158883022257291c3f0981e4939e9a75","bac51ea5b704b29646e9427857e311e108c5e79191194f7fff260047321ecdd7","e362b663c2c1f5a93380a04a7aa41b42f4bafc7f870e85cf63803f76c744c486"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514654467 · entry 108e9186e8c5677a9253…
Expected log hash
ddd8d6dfa3771a4106292f7bec674337dc9649465b28b118bb17bfc2b8ff0a67 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787132872903","kind":"published-quote","locale":"en","page":"theme:relai/billing/en","quote":"Demanding private invoices just to continue using the app goes too far.","rating":1,"review_date":"2026-06-06","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2030d4ef17fc…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.