Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Simple operation and works perfectly.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
9d1a0afef84ad1e577931b55f24d882e881270d4060f0b9691a9ad44ba020653
Signature (Ed25519, base64)
QyplA+Xss111Ey6lZP2oLFVucT9KbKmfl8IgnbNiev6FAltbtjAAa2bhLhs2IZlVCvuG4BSoYamNOM7pE4uSBw==
Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef
Merkle path
["9d2010c003ac17d4bc368643702ed5dc95efef859e83a19a23117a53c0e503ff","33c44d7f8fb681e0766ed84f1e96ffcc716a862978ce706a093a29b11228f557","22c747dd515c337a21fc5cfd8f72992b56470050d27104b9950d2e089ce5e30b","434637216400d59440463dc3978ed17c64df7cf079e135f464a261352f410df8","337cf92fdb690dc1300b0d371c35eda4bbb8876aa89767df424e740bb571b51b","9bb64c7b71c0561d9a2c2887fc3032fea3aca2e5b59e160a0137e22234a67ac5","279078dd64d411953a27335bb68dc4dc49b9cb1ca57f8523172eb6722c35f151","ace284657524efff02f526ce5f7ae1fcd512d90943d583d084761a8233e93335","1984ac37b713107bbc866e7c4128dee90e253d661e3a81322362447351fadc1f","c739acd9b5af7952a302b572353d6cccca9fcdc523c42bd40237cfad9ebfea8e","6d2c471b82300715f66f5dbf8b523ac1e6edc072f3668c57fd7750412f90467f","81ae0d98613af401743ec4987802323d53d8fda24ce374cdf2d369d04f6e8e3d","b5d03b72964f911025dbd61c2eea673598b47768b7619e9a279966a44a138147","e3714293de39ce3c6e3cb9d5ea7711343b19d2be532c75504682d8ef52e8f91e","2a462314156907e42d6f0d96eed96123f1d79516aef73ed189d9f5466556b638"]
Anchored
2026-09-21
Public log entry
search.sigstore.dev, log index 2904877428 · entry 108e9186e8c5677ab408…
Expected log hash
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"en","page":"theme:v-zug/quality/en","quote":"Simple operation and works perfectly.","rating":4,"review_date":"2026-07-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.vzug.home","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.