Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I find it unacceptable that, weeks after the update, I still cannot access my orders/quotes in the mobile app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
453906569654e76301ae8acb3f30ad06c771f883b9536032d2b5fd106ec170b1
Signature (Ed25519, base64)
+IpN96WxwjlTVUflLSfIhfziESnNZcdB8WcDI7uTNUE/s/2vqVK/Z01JvzCBnuwjtCN1WEYjYZkp+zO134FsBA==
Merkle root
c921242d78a65e026e3281000ec5ef04ef930758058c4fed3f79f3b5ef992cde
Merkle path
["453f8a748c1642e058d05083a4ce416021c51bf4e32e6f2edee0a11c3ef115f4","99b75ef1fe0cf2188c0c8aee2383985272ee414fd4647c584221ac95f7d6c4ce","9635f2674279cf21307d3ec2e906150d53f289cebb8db5611fbd1c846c6032a6","fdcf37ce832d529c2c7800b942476ebd1d5a304c895030b1930710756bc83edb","6b2dd1d81f4cb83c4f3bb93389074f3821c9daaecd8445a8c00d63d939868923","c8323681bb5ef39325c9a056e77362e943cbd10f90d390d2804f09a52423431f","1f3fb2b89d9645da723fb0cc69b8690540d63489149cf02bbe3f38265f25beef","a1e3fde28d0360a830c9e62f106aa7f0f4ecf7bc9fc8202b590b30137f74d531","300e11975970f6965a651166d137b56571c56f95455252d8575a06dc0f31459c","5b76a59d0182755dd489bd6f44e1c3735eab668f7f1de025e25bdcc5e529a185","5bee4181db969ed3a5bbf24fdc2b31e496c7c61b8bc5c88ec540a73c2fc385c2","fe73ce509a77325b5ffa3ce5d771087bfb0281b53fe18b6fd059050b1823b872","affd4e3e6ec270a4ab2ae23163aa1a6ec143fc7cb3b6399ad8156d5289cce2ce","a3747175efd8cc3d769be29f15252da2dfd09eccbeeae76e08b0112f75ae1173","522d5a6bf348351e5632579ca190fcb390464957ba4b4698b399695ee13b67d6"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543700701 · entry 108e9186e8c5677ac7e1…
Expected log hash
c1abaf0323b08bce2cedebaf1993162920ee741ace8973292e7ffdd13aca356b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787287374804","kind":"published-quote","locale":"en","page":"product:sevdesk/kostenlose-tools/en","quote":"I find it unacceptable that, weeks after the update, I still cannot access my orders/quotes in the mobile app.","rating":3,"review_date":"2025-07-27","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c921242d78a6…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.