Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“easy-to-use app”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
70a95c1dee413c4e152fe99cd99d5369043393c44f19abba4c7b6761af4602cf
Signature (Ed25519, base64)
kmdP1vqtYGrw9DB9IA+YbgrUNpOph4k4FeCjo64ov0OY5LJe55PV5hzjSYlMMoQ+w4DnRj3cjcTkWRAUl5rvCw==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["70ac63c6b2745b03f2e1b921b7cc1803471fa6db610611692bf711fa8d1d022c","2c0d477abd952421a8aba28a96654fdc4c77c74212ad81dd69a955fe16cc1f9b","210cadf20ef719731658bc8295a5a89419327234d66e3818969b452ad5c802ac","fa10f4546f427f3347bdedef7d5d60f95977c22a797b07986374e3efba759df8","2755bf3d458eddcaf92a7ee4668013426e57dcee43b8197fb38597c3328132a3","b90769e7e5c459008d05c83f4a5ad4c88875caaceeb713ba4cd96008d8f35c36","d4dee9c4c9472e554b786f0977dfca0904ea5b51f28a0fa17447a50fbdd3b3ec","3b5511e572cb1931ac43095296f12014ac3a88c09ed921c543f46de6362e7f4b","448baad8438ae9c210c0d5150a9ea4ed10ae32871ca83dfed528ac3ef7fdb2a0","73fe5b42bcfb85633ee74393f5fe61aa568a5825612ff1355d1b4ae3b342feb1","3904f8e665a3c2c1eed93f9ae2927dc451ad4ccc79bdbaf30e49ad70f3b88bfc","fa18470c35f7f7bd1895912f69375d26e4d5988a8c583c5aaeda8d2efc824814","ff839efe243c09faa45172bad7cb61d9b7e0949040c580ec02a160cb61e2c279","7a8821e5f39bd89945ecf080ecd049c93644614124901c8b74f26df2e34d9289","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:audioteka/ordering/en","quote":"easy-to-use app","rating":5,"review_date":"2026-06-23","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.audioteka","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.