Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I'll put off giving a non-neutral review until the refund gets through”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
915ccb1b6ec570634bef1c2d0497c40cbd589f5b9f6ba9b92ab2b019d616017a
Signature (Ed25519, base64)
y0xI0zFBqfPRX7/NeUu9zuB+syCFqOCmTBJrtshSI3bIC7T3cWSjADwH6fU0NFlLdfzLyKVBzmmtGhJEewo1BA==
Merkle root
5c4849a28e8624d6f6d3204e1f81a6b24f2188b6690e8b122801054617ca25d8
Merkle path
["915e3cfe55c11f1fbfcd180e97c486f232e8d79f7c176042fcac403cc2544f65","5f20219ba1a8d38237e9bf223648ec07bc16b41f652352504b8ca918d91b8617","dea121ff1cd5cbc9e7247bebe20d4f3d145f39ec7ac48506f449918602747e5e","3e673cf48827c191a8a36a878bb11154850d32bdea75a09937c820c70386fc77","e369444077b72d3f140d0553695b194dfac4ef616cc7a6a496519eba8ce77c61","60839aa2f4aa8aa167807725c24252c57275cc0dc1eea7fb8b4a51b16d7dc9f3","591d84fe7c8bc64f217ab8751122082c2a7ed2ee8c6ee1168022a244e9083966","1d1e6779d3b1cd6a7c58301217246f6ea46463fe756f473aade3f02371f4f925","997f7a3f5fda76ec6b6af76bcd363748bba987a06702fc4b2476caf38152ef31","cde379b2b14b663abc92d34a9f6410761ee4de18a1c0db938ed3cfe837c15cc9","950693b38b2a8aac855e0101a3d4e62279f084804189e51e043aed9b39182b8f","a6f0393e672db1f7a42a0e48f58d1ab397f70d4769af231ff695e788c43f5323","6f1e467d4fa619cb3e08538173acf01a50b505f4c6c960921062ac94dca51c01","855df8175222f9db398f9629c729494a6b2f86ecb26c7fc54bbd061fab2ad520","649f189ed3a422a3ffceae7f7673f3e683a1fac940fd27a4d89bce585dd48e49"]
Anchored
2026-08-20
Public log entry
search.sigstore.dev, log index 2524617489 · entry 108e9186e8c5677ab139…
Expected log hash
2051fcd76f2ba790414bb1c15fd4d3d064889742ea46f8e55b5028f1f571c27b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787193158162","kind":"published-quote","locale":"de","page":"theme:canva/returns/de","quote":"I'll put off giving a non-neutral review until the refund gets through","rating":3,"review_date":"2026-08-02","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a6f5ed34e792dd611818d3e","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (5c4849a28e86…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.