Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Bietet alle Funktionen, die ich brauche, und ist absolut zuverlässig”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
64a42e9d136f3f2671535c0638d67383c2b697856998daf6365f64af659fbb74
Signature (Ed25519, base64)
DGNCVj+6CtHFQqjCRQTx/OH9bHB+/vjj5THLxr3Z2AxMh26D6NtlUZQa8dVUwHbbInr4HLFMcyyyjjGxE+3vAg==
Merkle root
cee60bb6c0816d1bc69326ea12cf0c5c00cbea13afa283147bf24b52e30f839c
Merkle path
["64a91093c6e659e8bdd110e6bf5037d8ed1a4a91b4c89a03424a8031e31f1c38","008d3079824a9aa0c1549c333dc4eddf88f2453a7b528487d5e9097eac117b3b","ff45ca4fa9b4ab0fba2d823998fa1b70a430c0a007565f1e2c0868bbf526c43b","2beb98b626d467b2f3880034e45ee2bb41b6c3ad26ab855b96e885ba0cc5cba0","fa5af090223e79b526a8eefba57fa473c3d00e5b445e1d737119c69e73817070","e66d869f6126ed2a167d72d9513cae5c6b0234815d5e07ad1879ea5125b1e8b0","ac71ca6c18233700458a4784b66a943de8e89da15dbc0d16dee12f5af69fc553","cb4524ee507699920ed3a627194466581cf0963aada22cc3f273f010f1eec913","22a36ba406db6fc6f155a3284f32e3d80be18cb155b520dc3c2f8e1d466227fd","09e871f14ce39a4e7bb4331d2736bca09d42bb29bfc7ccf732d59ebfc332028c","f071ff0fe90eb090d530737bea647a49c6ac03cbd9de375459cee4a3eac2f1c9","a38c05fec9f7756f543ce7316369967ef218f420bbd707b00cedd3722b7b49cf","1a634c86608f8872bc200c568ce8705aeceaef5e6ca2a6b293c8a08d19857cba","6d215dc9023570789455be9902e0d62b0310ab7bcbe811daa69263c90da55ffe","57e3801fc0af4bd2492130e334ef2d0425fdcd10c95109df38ad0d371e279fbf"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543857133 · entry 108e9186e8c5677a5231…
Expected log hash
d8e1ac8b740526c2915424d7f7c6bce881a4ef05d0a3a3dbd88e4c760e36623e The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787288037224","kind":"published-quote","locale":"de","page":"theme:threema/quality/de","quote":"Bietet alle Funktionen, die ich brauche, und ist absolut zuverlässig","rating":5,"review_date":"2026-08-02","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.threema.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (cee60bb6c081…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.