Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Votre application est inutilisable”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
92c8d9e2c33567d55c130a01ed0ca2850e02447ee9ec788a06293bfa74bb2119
Signature (Ed25519, base64)
dClPHVSzt1S5wJHga+rDoX7iVLjAmskTZeppXUthR+ifXugEYHY8EPMt/m82J2DNXWvThsJZzkt0gFx9ca0eBw==
Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef
Merkle path
["92ca1437213e60cee438600c92a79f4b01cab0efaca2a2e90f0f83edff985890","5150bd85fc4c5b33a443cf0536384e4cc8f695574a7d9fb5a7c3747b66270ed9","b2f84c6922f533d993c466ccd78429b0e7022f0c6a04ce72f8b68bf121e9eec8","28fa63e1fbde00515f27793ea99549fb27dccbacb41d44517e15b07a33ff40f7","78d20e4a2b4c20e230b75bb5755c12bc32d9f2e304b52fcc49db5f552a00e0b3","9f57f2ec351b10196d1e90ad8a41c38117f871e50d1003930f1f1d5392716221","84eba903bba09b1a7bff9e1ecf54adb2daa646ecffd65424a737c31e7007383d","a1b7fffdc3cf3356539c2067e82cb4e45da273e0f4ef8f5ff1046ecb47b78ab1","d6b238952f2807d230b79a09266b682ef788a5c7e3a1a7223a8c6c6a23f736de","ff1ac9526ebfebfae03ffcd9a5d8cdd3e896f2f805d0aa8b855b0f87c72e07cd","808361c2cc11d1d62da97f81cb8537cc3a8a9e7c2b553285d63cecf18a95be4f","81ae0d98613af401743ec4987802323d53d8fda24ce374cdf2d369d04f6e8e3d","b5d03b72964f911025dbd61c2eea673598b47768b7619e9a279966a44a138147","e3714293de39ce3c6e3cb9d5ea7711343b19d2be532c75504682d8ef52e8f91e","2a462314156907e42d6f0d96eed96123f1d79516aef73ed189d9f5466556b638"]
Anchored
2026-09-21
Public log entry
search.sigstore.dev, log index 2904877428 · entry 108e9186e8c5677ab408…
Expected log hash
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"fr","page":"brand:v-zug","quote":"Votre application est inutilisable","rating":1,"review_date":"2026-02-06","source":"Apple App Store","source_url":"https://apps.apple.com/fr/app/id960378213?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.