Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Making promises they can’t keep but they keep taking your money”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
7279731e927f0338c31d5dcf0d59004f7792e98adcf10cfc7ff31e88fdbc9cf2
Signature (Ed25519, base64)
U5/t3wkUOl5iPrM/gKL0+o3tAXDm2WH9fZcHQRFg7wPyFvLyBLxYHK80YgaQx7MCMq587I2dB4WLVO6Yx94xAA==
Merkle root
80de158564b7616572ca0c0059561f6ec90cd5bce49a388e61df989f3f6f2a86
Merkle path
["7275f3a468932a5e0fb69081692f9ed3a2f8a513ac4e817446840f0870ed3a41","a9ca7ab1e684f3265749fbc2e682435d9cbba4cc96b5287c4f8e4c224908e1fa","0fab5594bbb4b838c5a53a1c69c20299270174f031fb716de681b3f6fa5c1e36","c77c58babd175b09b5ce791e3168e640e96d8e00178ce667a581faa5f681a1fa","3656ef67196347d1a5c26ede678767c1491d496c3c8c264a9687b1a948f052a7","ccbfb202f33f01e611fbd59d726094942563e391431ace139b276aba5e82460b","84cce6b462e23ffbaad07d5626a95aeb1f5b2ab43bf85e569f02e08c9d0c682d","da26452a8fd14b360d97ab85e23377f6e5826f424c1b2552018f8e2f4631f2da","27886323b2cb0a647b76fc4b889ffd4b75d872865bf44c21496e9b5cf3fbce49","badb71a6ed9a9258f45fe9481371f53e9efa057299f4640abf84bd897d6e4172","63fe760c030e1655a16c2d483846165f3bdc19a9d51ec35beb8b3028e1ddd224","fb884b13c6c7b6fa45ec692f0cd19450269fcd13629216d89df8f4f8f28f63db","4030647c2ef4f8e3330609d1b1b8f3b58008674f60e870e605f772c875dc6aa9","3492e7b3aa9fff62b956cd07fc3f980ebe20033aec60bffc5a515ff87c949351","68889fd35b89925b8d265e65260618471cd9c2f5458718fde3d6cb3829d8f00f"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2513802575 · entry 108e9186e8c5677a9216…
Expected log hash
5899b5d0ea18fa3c879147333708054c2e3cd77662f2b6f633aa3b5d5512bbe5 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787121142818","kind":"published-quote","locale":"en","page":"theme:accuweather/billing/en","quote":"Making promises they can’t keep but they keep taking your money","rating":1,"review_date":"2025-05-08","source":"Apple App Store","source_url":"https://apps.apple.com/us/app/id1196015787?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (80de158564b7…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.