Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Everand acknowledged there are known glitches with Apple subscriptions”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
508d930d9a16bb208830a85175b7c7ac056cb5760b63904c2421844fcb8b66fc
Signature (Ed25519, base64)
dJu0Sh32G9/y4lMriJtoKTsP2EZmHWlkHgEuyFqweoiBNwfIA4M0i3rygsH2PbWDKLvswL4vkIjUGcmySePuBQ==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["5087fef6f71cd8bec2741bb8d2f1a10cea993583397f49e751acaf8f6913e36d","82ad18f7a506feb5ce901953956faf7e3581d33a047be00d1559b26da121e24c","e95e395cbb4854fee99b52a4ae34cc799e66ad2685edf47661e79fa1b33e4865","25406f82f64d7f2341b85da78cd7c8e24ccfff7da4a4ecc35e8fe3002c8053ee","bed4bbc711c6d42eb0bfec039f12257b6e348a17b51bf86752335331421b9991","0c67c6c558ebd1ceaec6d7177f69cef0c18324385636b51722b8e39d776c6a7a","f2d252e0b99da5b846f18247e48eda4aed09fd509b28e3adf533d9cb60924b7b","9d08d2897c9d08e3d5ded1d46edc2702e3dfc3eda0dafb45553f1c538e88ae8f","1fb640767a26cbffad0064b3053da752d9bfaa75c8717b39321adb950b5ce11e","ab90e630bc3b314fe9d928dfda3158d4f044c3781d72c7c4a0a859a930d5aa3f","12498701ec80eb322027552740b37329e5ce7260f2d8bb670d3a26d50a0d6874","59ed91997728cb88879bad2b8337d3faf9e7582bde33c223df4df42a8d4a6fc0","eca7cd52f5c219223fa262f727815d7426f47ee6fd8d3c4a33225271415ce785","7a8821e5f39bd89945ecf080ecd049c93644614124901c8b74f26df2e34d9289","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:everand/communication/en","quote":"Everand acknowledged there are known glitches with Apple subscriptions","rating":1,"review_date":"2026-02-13","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/698e809c1cfc9e1f2ccd6715","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.