Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“the user experience has grown leaps and bounds from when I started!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
4f791fa004a661b0f9c71dbe121e7ea23ce1378aad0c8f6dd6327f2f04bec80f
Signature (Ed25519, base64)
uWxK/VbjNrFNNamLdauFToNHVgiebzIvg8d1c3BFhBHFXtB12vnhIu04Eypd+z4awOkoLcZY3Ogevq0DjYNgBQ==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["4f78994354c7aa1fb144715be4b2a178e52d74e6d22bd7cd5fcfdfcea67fcd9c","0253137e89fde0f916de69fe5b8195f45f29958992462f7807445b48fb145df2","12c31e0923c4ace565a303b83372aa2399ce1b441696c68610742bb7da271113","ab99bb7f3ddbeb971512c558c10df4f51e636a6ae11744143e9200e18aa7e37a","2096ffbf0806f900f97aff7081cfac8017d3b00cbc858912c853c1b72b5b4539","13a215b147e81fa2d9bb694f7e60038a51e23991ac11e6d53814d6f5999d15d4","34bfe85c1b1237452ef31eb93bfab75a29466f3c0bfa3bc8270465b94a5eb109","34a352f25c22d02d83ad836ef07a61eeb6a1ae42edf5df8aa914fdc6c1f71978","b6fe74dba8359a36ab44804679ec1c06cb34cd9569d4d224c92f616a7e5cfe99","5e4018fc5d36211641bfa8f918a4a0d17ddc5284939da790bac0936d8c0bebfa","d3a7bd3c71331cdbbc263d45811b1aa92d779199c11eb4bbb8cac215c32a530d","aa7c727744c972cb66fba1d64eea69090f0779e70821de9cee298fb3fcfb9463","b2cde2091952330dc6d7773f9467df58d2e8463851174cad44d4f743c8f8617f","a9559f2ca8536f2c18bf059f3f0099d62235a93ac35dc17b09967d392b72be7f","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"product:wave/invoicing/en","quote":"the user experience has grown leaps and bounds from when I started!","rating":5,"review_date":"2026-05-27","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a16a1c8d96b36d5da8e55e4","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.