Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“It's detrimental to my business, I didn't authorise it and it means I can't invoice today.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6a82400a9063a1217309840cc576f65d5e9d16145750668a903514b26488bd3c
Signature (Ed25519, base64)
1DEm3ZsgLgc+5hlr9h4kKf4rVjNHHHzsYTVgSuGl17BcpD6eJ/J5LOohi78v0u4NGM6zGf62g6NsKb4a7ll7Bw==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["6a823802412c7d0a999e217c435d4eb6b67dea1919f087c3e83b23b02bb51fea","2af063080b3c770ad75781cd4328b55f5f6c2afebe13611ca00d2fe67b8d43ba","dd3adb9fd31cd343a0db3839e688e01c5fdce8f69aa5a516e539d8ad6829d9ef","40714ca42df503f2162c98550ea8d9a4d621d063c91dbb9eb10c7b18cdb7eeef","49995263ecece2122441738f12a5e15af6beb99dcec8684c6b7ac5173230ef27","46dbae435fe14078bc3bc8b2be8f5cc6fcdb0dc8de3fb0323a6fca47bd816a80","ed473e90654e2e88b4aebb5890e52364b75e323bd2ddfca22dd8b3ac40d7f978","e004f6b5d1714578eaccaa673f63b047b45aba3d7f6a8e7d2b28caa4a43ef70b","3ee58f476b550ff7fbeb7d3e53bff4da71b314b934051a7154299edd9bd2e513","bb7d2352b9ad7572c79d28fa1c5a98774667c0d1179bcac107008d310258e7da","a6ba2320bebdb525294e32051203a108db199dafa5e32fdd427ef9ada1bf92a4","cc930d9a14ea152753caf04b31f0e79f0b00ba63dec8c58c38ded3f85cfd7dad","66d13e8b5300f6cf7ae49f9f9692863758845bb98773f7a2bbb28032eed5ad1c","90e3c3ed08ff9f4dee6683cf95bfff311f4715cac07e97ca75ea5b9bcf13efe4","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:xero/billing/en","quote":"It's detrimental to my business, I didn't authorise it and it means I can't invoice today.","rating":1,"review_date":"2026-08-30","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a9457b141e87b89f25c17cc","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.