Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“They are taking customer payments and then not paying them out.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
a9aabe611d690cc427c2da1ae53b4e559807534acd34206812ed4789d8a81d1b
Signature (Ed25519, base64)
o8+UjsNcO/No5arKYO48IishOK+ez495ueencfRbGJSj1ZLaZKI5R5a0UOu1mL4JB/X1qgTzRoIyZQ2J7523BA==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["a9aadb71fe3d65f19d6a040a965e2bc378c33f4638f9c05d12edaf8b9e3ed70c","2327b5f139c5a0a60a6003b499350cbd3c7b34ec932d29bed12c2724ab7ed52d","3511dd60136e9199e184d691ba44079a45d7e90969a83bd3e395ad441042fb99","5a5f95d1f68502d033af6007c2a937cfb309166d564d5453ef3568a41692d025","a94ff36e28b594ae1a684d2d8a9d4e3fcf933e535849cf5f1738a263b5054ec8","69387a4c9e4323783fde0a953ca3eb86a0d252a46e437fa8f72fea70f4654080","05349bb6e6ea934d91261858f728e387a745856c75568c6f59d7e8755a42bd3d","3cd4233af569954d082eb372b2583a36ad895df49e1ec5ff235b214d3fa985b8","cb32524e47bc10d45eaa9e765a595d6f37e5e3760e00780fb0b6dc17176572da","63b4127ad54b9385a6ba821086d4a4c4c37b36bc22ced596a76c47c2c689d22e","287617fd502c0aa03656ebe965c0e480dafb208e3433d9b96ae1ed850f0ffa6f","f331b9b7b0f816973fc5999e2ac6d8d10c8908961884acb0adfaef58ea6e81a0","054c6c39d1f97397366b9a1b659a373f0607ed1b3f28fe998d444aa71461fa00","fb01c9b29e184d558c43a512ba05af475ec20eceeace4dde365559da92299892","46bcfbc656e0e2a380a8a94cdc0be3d8b4c668e5f9e54a10ba396a45b371339b"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:wave/billing/en","quote":"They are taking customer payments and then not paying them out.","rating":1,"review_date":"2026-08-15","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a8097657cc2640487ea5762","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.