Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Even better now that estimates are included in the mobile app!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
a371795f5c985a1376c3d3ab6d30bd92b615d75c8a9ec50fb46dd956a10babd7
Signature (Ed25519, base64)
P3a2x0KR7058c31vNkahtrGrf1xIJjLZHQJtqZ59h/5EIOY6gsBI1pUipcOTqUvuOxkR5xgYebu4QZD/hX9YCQ==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["a36d121b9f62c296ae114c6e240838cb0ae408a350defdf2362bedfa185b99cb","ab9d0dd305ee2cd5443139abe3eb1ef3e78bcaad6173b9e91258f8badf5c589e","1cd1be0f3b4123ab3717c76d1ab36c2baebf6357b433b1c54a067392387215ce","9e10b1228c5b2670efbefea4dd42aac9b36ecf7dec566235fbf74ce27018402e","0e19b090b2cc7b1ef2a816b055d804f9d9bdf571fcc74760ca7b8f1d49999962","01c4d36c7d6cd8365676b14b066c7f741c43ae9ac66a5152243b860cdf2856e1","56427074fc6c18078044d0a33bb8c707e732c25e2d8fa0303f5dee300fd61396","4ff7aaa6d42c047d2619c979d96120f49dba766c15daa19d00664fe21622f094","06399ed5f840bca636e65b6ad74157f443177986ebecb363b587c4322b47fa1a","28d2cd05f1342fb799e790c54518dc64b213d2c8ce938ce7681df6a5dabc1e60","7d7f77ad1d1b5b329ae9df2d9c4d3f987a64dd198ca897e32bb89e242691f902","0bbaca186fa570cfa914cb3e4cb0d5d663a77ff60ade12385fa90fdfef78367f","6772a6b2cfb742f4baa103e424787f6ab6a8cbdfc294db886f1451f7c9752077","90e3c3ed08ff9f4dee6683cf95bfff311f4715cac07e97ca75ea5b9bcf13efe4","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:wave/communication/en","quote":"Even better now that estimates are included in the mobile app!","rating":4,"review_date":"2024-11-19","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.waveapps.sales","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.