Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“he has made me feel confident in my ability to use Xero effectively”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
7ad028eb7280556a1817dcdc24eaf5003004e899c1e3f74abaa26b84c7f722d1
Signature (Ed25519, base64)
LS6lfG9dObY4468K4Xo6O8RDpOhY2ZJmBg+5v8jRm9fXnH1BfmmT5UzZt2iZfPUes63CvI4yHPpQuz8dsNI3Aw==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["7ad356110bf846af67f1a9dd172bbf5e73d3efd8fe4495e215b24f175eb48e43","103c494b30c1923813f663d2d5a9c41e7db8aa6b4b97846441a8da506c7137da","c1f7d7ae4d542a0b4ed92968162567acfdc9c047fd82b793d05c120c2c22d06f","343bc429582147a9ed07ad33da633d5d499cf3e6c7fd017bd3720293c377b2d0","a7d7d144dd050626f242ff6931a6ce232e17c70ad4bad2ec27314d0c12c89b1b","2f0954bb5b0133504e33a9c2a8984bdd13115c33e290fd5425bdec290cebc635","f3a6c1cacf58ecf0dc1163cc1124d73d45645bf915720df70371f89ea5c22d76","59af406feb985ad19a5365703cb69c0d2701cd86ae2e818b229e750e1d558117","f6eb18f3c0909d2d5df51bf93f40eaf8d3cfb3b09a8a01702334cd471cd70a2d","2d8ecb41f8400c70f915406462ee47efc269e681ddb12759aa75be7bb6a1c1b3","4a7da3ae635c518c772181747583fe91b52dc970a195f2fea0b029288d95f308","ed5206c0018c25fc911a5b83d48a4b07edf1ca07ade25d7e56162349167c269c","6772a6b2cfb742f4baa103e424787f6ab6a8cbdfc294db886f1451f7c9752077","90e3c3ed08ff9f4dee6683cf95bfff311f4715cac07e97ca75ea5b9bcf13efe4","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:xero/ordering/en","quote":"he has made me feel confident in my ability to use Xero effectively","rating":5,"review_date":"2026-08-21","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a8851fe65c8b47506d60173","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.