Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“very reliable and easy to process app”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
b0266ec77b68102f0d571ccecea6aa6b46df7c4a8bc8dc1bf2698cfb3b673746
Signature (Ed25519, base64)
mUHPnT+HtEX9IA4NOaZunNBLeSt1b942oC4oxF3qUcVNaao06XnMcwxWJSsvll9iE/c+HX/Qs1sFX017Sv+qBg==
Merkle root
04b39eaa56e1cf8f75dc8eac18bf6942167c8418ea731a7471223f0be60e3e6c
Merkle path
["b0237f55d82bb16b1cf430a9b33743e58d5803d85c07c123d311bce8db364dde","8ead67a03c9e23ba80edfc54c512d674a9fc2622270442767932eb3e2848d93c","7240fd7e8cbf865fef847a07ded7077b1acde83f985dcaae9f1d8fc69e5925e4","2341e232262de8c053042ae57d8fc5f323ab1f8c1f7aa33da4084f7f70f6e220","8c22e6232bb68aec9417bf29da9f151bd4c50351b3d481df6ad9f63c4e7f3dac","9c577b137adff46a43155631f8488b392311ffae5d583e2cf490e66dff2825f9","14af21aca63442a5997d3719be75cbd32c82fb78d22a88a309db696e36035577","940b0225edf317d0b79eae89a1e36c496caf4e5d89bd9bdc8746a36430b57942","e1f920c5e5847143404c488fb8bb79e1046c37dfdf8237972d2c70ea28494b2e","d2a79a9c20c0d4932303f4134acf2b8c72567e61110c4e14b4f8eec5b13e4284","76bc58a8ab567ab0ff729fa45030cdcefa42a6f685d264f867127e3cbe1966b8","e27b6f0d2a6e378ff36cbc28e04f11599bd9917f1291e082191342792770949d","2f760d0f42bf27702bb03975eaf8d6ea5e036b0f49b2fda05a97a4b8e2bd9942","8f074eddb198349108c1e544aa98c8c80e756f627b29b4943cfd74cb3331adf1","3ba88b0016422cde319348a72d81ed01eacc4bd155bae80b5c4b6ab6d98a745f"]
Anchored
2026-09-19
Public log entry
search.sigstore.dev, log index 2890214870 · entry 108e9186e8c5677af53b…
Expected log hash
1f3acef0f063246e051bf412e40f4279cb96ed334ff7b0647a13320c1b31c4fa The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789722569406","kind":"published-quote","locale":"en","page":"theme:taxfix/quality/en","quote":"very reliable and easy to process app","rating":5,"review_date":"2026-08-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.taxfix","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (04b39eaa56e1…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.