Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Unfortunately, this app is still missing the most essential tool: creating quotes.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
4adf6013a79dd770cd3a885c116a2f56b5acca90d75d672c4183ae7075431333
Signature (Ed25519, base64)
4PA03VSNd+l83WH07ysV8ocdJuS3va2SdYAbMU3DrTVZ/ukA07Es591g04GPZXw7oQ/wrnB8AAW4WRO9QtlkAA==
Merkle root
3e1c67438f658ba7fd015e6979c1bfd82d90efb0848cecbd4d902d6b2ed171d3
Merkle path
["4ae8366d38f4062575883dc3b2b8672eb9b218ff0e0cd0863dffc22570a68ca9","c7b2e8103d099b7943d77474a790bf6256885a8179c4cb02ec4389d82e56f697","a68e6bd57d1714f09e68458b01ec6c0f2a00c061d300d9c041941a0e6479d8bf","c4b43456f5d207d609302830f54acfc5e0f936e37ab76c0189e2f84378f586fe","09e2d4b3d80ac686c14a965aaeec0f3cb2654b06c37368b88572fe18ad420ca6","f5a50a37132b6d0b11e8fe2fb012b0eac1364f2da333c220975b84411df9bac1","08d42355e2a58daabbd49b9facb10b200459c981a158de2610fd53bccb307427","df03f484ff047338e3ea18057bcb6eebe0d014e8678498dbc2af2ca1ba8d1e11","d23df098f111798622dad44e920b73a3263125f5acfb85486accaa44c2df00aa","38bdbf9224b73ae6351d20dbab20d93f4c96718304aaaaba29a7269324260220","e1064864699083fa3394d945ea7e300fa79076dbd55288e061752085d6858da4","f1892be337cbf3f4bf9cd60db0d449d3527108f04611233f1d94a0b7ca806215","dbfcb3d5021da50b8b4634be051dbf46681ebd2b647e213f1973335aec3749d8","0790a9ec23117ba3e0ba9a310290906a4f1d2b0055d4607b106ab21651087c1d","db72b82118c1e08b77018004fa72584377d6eccdc4c75ec19bef6a78273f75c9"]
Anchored
2026-08-20
Public log entry
search.sigstore.dev, log index 2524810465 · entry 108e9186e8c5677af074…
Expected log hash
129b219cb6155ac24569a579c61e8fc9cc2d89305732944b8849d5e719dfd073 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787193927339","kind":"published-quote","locale":"en","page":"product:sevdesk/kostenlose-tools/en","quote":"Unfortunately, this app is still missing the most essential tool: creating quotes.","rating":1,"review_date":"2025-08-25","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (3e1c67438f65…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.