Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very simple and easy to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
974e04ddb56535e2f2c3ddf1a6279ae8d4185b5a4fa03e99437342ae4ed83844
Signature (Ed25519, base64)
XlGG7YWYox3WXRGCBEs8lKu7D1fnXl2+sbbyyEWQ4haaqykhX5haBZ9SJoLNIBUV/Szvf7w6ygZiqG3QNekpCg==
Merkle root
5397210619679ac63434abd334c13f5aaccbd1dd184ad9d8cac5ebeceaa346bd
Merkle path
["974a80e54d251a16ba291482f19ea4fcd3dc435a5b44cca66fba460657ce1de0","8c9c3561304eab88e41eb6a558dd25ab08cd65b6c7dc67153af2fb14c2f65d2c","4305f249e4a3dca378f40b398546f9926a82cca54cd73de2f6372959a7ee1b9e","c99873f478083f986d21656d49f20270516aa37d2d918913b630f837350225d8","80bec05dbb1d59713e4018315396ee4616f1426a4808b5b5d98111675e22d661","2b8f196fd95aa9c6bd16a8701f6c44739ff06dc8b8103075171034ea7468774c","91faf1fb26f54321c2a5ba65635c3dbd479e24f93918bbfe50bcf11e42c19259","c740f3820b9ca796ecf913c61d90e7bdc926f7000486be8ae1358c4229497343","884049f045baa8330c1732b59fb27ac36fc72494857f99db141b29356c2d9fd3","252bebca477cb297786b72d64a9b16e3be70ea63c5d12408a686a5086cc028be","04ea073d1ba0017558b64e075dacda8359dd875e68d419ec16e85254acfaa64a","57cef6631396d6541da6e13b3470e6b8a464094ab53c852077db03ccc58bc7b3","cf100015419b4e08a8d3e2de5cb23ad7a262130bd3e6bdcccfa47329e90a07c9","468adf75cd56eeaa89e39f50b974b405db9921529d680bbe88ff0d1caae6f316","77ebbc5a767f49a9f64068a716a8c843de0ea8d44adc624726bf46e2e415a41e"]
Anchored
2026-09-25
Public log entry
search.sigstore.dev, log index 2948162176 · entry 108e9186e8c5677a61d4…
Expected log hash
5ff8f25b7934b5d72d363d6805344624efba4d637f2c851f11783b259b9d81be The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790226990092","kind":"published-quote","locale":"en","page":"subtheme:zasta/quality/user-interface-simplicity/en","quote":"Very simple and easy to use.","rating":5,"review_date":"2026-09-01","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.zasta.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (539721061967…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.