Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Setup was quick”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6b82f34c5653fcc903643c21afd3510118b7c84f7152a7b3b6c5cc90b989960a
Signature (Ed25519, base64)
cdxGV1fGSGFAGq51SwX5MKe8vX+4sQMmbDahE5tbfNqs+GgQ4ef5COLHHA0pnQOGP2ojmOK0f6vOKCmSPegiAA==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["6b82cde1066edbe14c2706986bdf91163cd43ba148f5e40c90ff0167a191b808","2be35b81f3c98af3a427ca955dc51d4b4cbeffe7bd5c1c0e2163415e2358e081","c846894b1f9ab5f4a8019aa99fbc6519ff2fb8ab886fe199751e1f71e28a3b22","3c15f9b3f3d393a11af3bb84cb38d1027f8f37e23c6f11d850d95d98c48bfb32","2546a9a1705d9bfffcbb59314ac28777505062fdbbf8f2108b76d28b0ebbbe53","3dff91eba77a17cf39e9685e4b86a99e94eca7cfc59375b45d946928b23e6808","8d27a656604bc95c0cddb4f29cb7e7d8392e40f3e4420340df32b133d584bbbf","e132be821127c38195d9ce4a1fcd64f55debc9e61c27bdcfe2fc01370bfd48e0","35eaa92ce75817f52d9230370d5d74fe0c01617367e57a0c01fdc7e964818721","6025bb34265d6164508e73f9e4fbe5fde5e838d5d0fe5ff539c4e424d3d616fb","a6ba2320bebdb525294e32051203a108db199dafa5e32fdd427ef9ada1bf92a4","cc930d9a14ea152753caf04b31f0e79f0b00ba63dec8c58c38ded3f85cfd7dad","66d13e8b5300f6cf7ae49f9f9692863758845bb98773f7a2bbb28032eed5ad1c","90e3c3ed08ff9f4dee6683cf95bfff311f4715cac07e97ca75ea5b9bcf13efe4","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:keeper/ordering/en","quote":"Setup was quick","rating":5,"review_date":"2026-06-06","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a2403f959d197e3be4fe7f0","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.