Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app works great.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
b332cdc0e013628dab36b52da382274072c4396a81d076b99a6f44a0038a353f
Signature (Ed25519, base64)
e5/2zp44zWpayKYPBJoyD5Mos36vax5XEsOcMep38QdnNLOVWj/FLsIqQIModewBfEgwzJqIhC+EP7mOcRZgDw==
Merkle root
c921242d78a65e026e3281000ec5ef04ef930758058c4fed3f79f3b5ef992cde
Merkle path
["b332c8660af3abd2710c5484b38c1eaeae9fd75f969a80aa97469ba03550816a","b3153ed79ca17634e0203da804796d195cf1520fd37a091e1bee382b9c013bc5","3d00d4cad6c385b78151a0856905f95a49f77d934915256e099d556d83bc3854","b129159445761f83894b6d76e1b8f079111c76389b9dc32d550bc17c3f58081c","a7526523274c191ee8f955e41c8b9b7a036b61b9aa4e1d4848f509e685139408","c89448df49a1d3c3e31f6f4c8218123a069f708cea4bee2a332d8d2e3c3a0d6a","c38b65f703dc41d173e02844acc7c2685910025cdffb16ba4ddefb1e36b754c0","9cbebb3c36f3ff010f50975a6149c4c1babe7bad27463a508f7ab8cb9308ac95","7615c1df61953b818e911014fdf3ecd939ddabe69edeb9be98efa2c6be05a164","23bd128cec6dc789f8e1f44ea08cf44d960e2a6c3de3fa724c004bc2d7288631","5711f12bbaac91696c74cb6b3b4994068b4497f303a00bab859a9bee597e6a0f","8825fc1aab8f63f0e76e56b09417c2ae382071679d3b00197c62c53fcee32b99","dd9ac1ec648f41d4f9192f9ab4a90e9984a25e2b4db00816e217d361519f5150","11c55b906d5338fe2597d0d6abbdec07bcd15a81c2687346b92acf8d9db0c2f7","522d5a6bf348351e5632579ca190fcb390464957ba4b4698b399695ee13b67d6"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543700701 · entry 108e9186e8c5677ac7e1…
Expected log hash
c1abaf0323b08bce2cedebaf1993162920ee741ace8973292e7ffdd13aca356b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787287374804","kind":"published-quote","locale":"en","page":"brand:nextory","quote":"The app works great.","rating":5,"review_date":"2026-08-20","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a86aa5a57859bc030c4c26a","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c921242d78a6…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.