Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app works perfectly, is well-organized, and easy to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6ce8f32243b098258ffdb7ddf7bf3fa5c138ea0783e0f26763ddf5cb45c273e4
Signature (Ed25519, base64)
QGBIZPaHNCR56t2qDkqEhu5WKp11ruh5hltLVJnBZ/3lzORQ2sO7fU6puyFovMAAZcB6HZgJnR3Qc1F9HvXlBw==
Merkle root
fc0474f2ab9253f8c52a81a0b2f1ae382f5f022f9b54f4e3fe06eadaf19fcf31
Merkle path
["6cee4f763b8327cab53bc36a9bf1226fa16b2beffd88bfc41ec95d4a23020e87","9a89607d12e97ef84abd12d9b8485c014f2dea6bac522231d2be365fd42fdb5d","5a230073b892caa021da27cb095b2db8d2659b2fc481b048fc8b1df9d813cabb","ec9c38ebda4766958323c7eabe2416238e56b29f082fbd197fbc731cf85e6857","7d6c9f2a985e9108ec6574b91463cbe0eb8519aeb9d834d5b64d2fe52118298f","8171962230e4f108ce58030ea133fad06792fb19ac6b5d29b40565ad57221c53","48fbb52fd261946434cba5f17d8e712656b5fd370f85ffa3165d4441a25b6b3c","dde89e84e14a74a18093231104d00f48b459bf957eff325ab4cf40cbc1a403f6","3aed013c80b72e032e85136615f36fc69269ab4c40bde93e32efbe80e49e4f99","4054dbded90df5cd8850cca016ec37c42f2b7fd699a23e95478f6cc569e5514a","f82b62ed393df6e75c6eaeebf74f077be510cc4b9badc5efbbd62a5c0df8d751","4b473519aec772c9e255916dd393be76b9639055882afbfb7981bc3d09a6ab5e","45c0c0e230e3fef68f32d677676bfb42e35f39fb2908713c2469479af7a56696","5e3e14a1ecafa84280522a5086c1c4eb7da1d2c5613bfc63f3fbb10c0768d98b","df2c1289894581f6e22c526afc719be15b70c61ef4fbef0978dff78cc8fc6054"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2544092674 · entry 108e9186e8c5677a1b30…
Expected log hash
e3ca1014bd6a1a766a29da72cd2b9f7f9c6c416fe6af720fafa94eca555dc171 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787289954326","kind":"published-quote","locale":"en","page":"theme:sunrise/ordering/en","quote":"The app works perfectly, is well-organized, and easy to use.","rating":5,"review_date":"2026-01-24","source":"Apple App Store","source_url":"https://apps.apple.com/ch/app/id1231971182?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (fc0474f2ab92…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.