Quote verification
This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.
“Votre application est inutilisable”
Checks (re-run on this request)
- ✓ Signature — Ed25519 signature over the record hash, verified against the public key at /.well-known/citatio-signing.json
- ✓ Merkle inclusion — Leaf recomputed through the sibling path to the anchored root
- ✓ Public transparency log — Sigstore Rekor log index 2904877428
Proof data
- Record hash (SHA-256)
92c8d9e2c33567d55c130a01ed0ca2850e02447ee9ec788a06293bfa74bb2119- Signature (Ed25519, base64)
dClPHVSzt1S5wJHga+rDoX7iVLjAmskTZeppXUthR+ifXugEYHY8EPMt/m82J2DNXWvThsJZzkt0gFx9ca0eBw==- Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef- Merkle path
["92ca1437213e60cee438600c92a79f4b01cab0efaca2a2e90f0f83edff985890","5150bd85fc4c5b33a443cf0536384e4cc8f695574a7d9fb5a7c3747b66270ed9","b2f84c6922f533d993c466ccd78429b0e7022f0c6a04ce72f8b68bf121e9eec8","28fa63e1fbde00515f27793ea99549fb27dccbacb41d44517e15b07a33ff40f7","78d20e4a2b4c20e230b75bb5755c12bc32d9f2e304b52fcc49db5f552a00e0b3","9f57f2ec351b10196d1e90ad8a41c38117f871e50d1003930f1f1d5392716221","84eba903bba09b1a7bff9e1ecf54adb2daa646ecffd65424a737c31e7007383d","a1b7fffdc3cf3356539c2067e82cb4e45da273e0f4ef8f5ff1046ecb47b78ab1","d6b238952f2807d230b79a09266b682ef788a5c7e3a1a7223a8c6c6a23f736de","ff1ac9526ebfebfae03ffcd9a5d8cdd3e896f2f805d0aa8b855b0f87c72e07cd","808361c2cc11d1d62da97f81cb8537cc3a8a9e7c2b553285d63cecf18a95be4f","81ae0d98613af401743ec4987802323d53d8fda24ce374cdf2d369d04f6e8e3d","b5d03b72964f911025dbd61c2eea673598b47768b7619e9a279966a44a138147","e3714293de39ce3c6e3cb9d5ea7711343b19d2be532c75504682d8ef52e8f91e","2a462314156907e42d6f0d96eed96123f1d79516aef73ed189d9f5466556b638"]- Anchored
- 2026-09-21
- Public log entry
-
search.sigstore.dev, log index 2904877428 · entry
108e9186e8c5677ab408… - Expected log hash
-
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360The log entry'sspec.data.hash.valuemust equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm. - Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"fr","page":"brand:v-zug","quote":"Votre application est inutilisable","rating":1,"review_date":"2026-02-06","source":"Apple App Store","source_url":"https://apps.apple.com/fr/app/id960378213?see-all=reviews","v":1}
Verify in the public log
- Open the Rekor entry (pre-filled with this proof's log index).
-
In the entry, compare
spec.data.hash.valuewith the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry. -
Decode
spec.signature.publicKey.contentfrom base64: it must equal Citatio's published key at /.well-known/citatio-signing.json. -
The entry's
integratedTimeis the independent timestamp: the root, and with it this quote, existed no later than that moment. - Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.