Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“This works great for us.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
b8ffaf142209331bef02ec3483c48007e457ae822d9922503a0140d85617892c
Signature (Ed25519, base64)
9E6GgimwslGBlVZmjzf7HOIYQPHT+4glpAHINVAQOwOIw5hwbiCtiSkZySjW8jUdlUAMr2/nDBt7gmN5Jx1wAw==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["b8ffc29c4fc8570b59c898edb448af7614c26a08c78fd065e1e9a905fc0ca707","cc752ab74b842c04816fea5803d29869ea345ffa82220b2413e16a3957252578","092c5484fcff25563982c4d5d24318195af12e58fbe25f635dcbf7b17fc8ffb2","da9d3f2467c7c99f63e65f12959504621bab3a2a8aa31b2fa14d5f018638f08b","7f9157696d4b339afdb67e6a46454beaffebbf31d65eb41b999ed084c79c325d","db8f28e805cad422576a8bb78af2c6a71fb91ce3b86f7fedbf68bbec7783cf4c","f1e9719c33c26648da935e23ee1cd856530392ee76a96c63d248f6180978d3db","db24bfb85f64a4c28929d36da00e432798ba7b6f98b430134ea1129e7b70b07d","1d867cc342823e9bfec836d3e35b49139d881697cb31a58c669a53e96d904de4","0398d05b7e6f2b5d095e18454a98b1ea6a2c750b4b8a0045d43ec0820e655af3","5c03cf30ba6afc005d746c278f2b17211a526993a50ab9c5340f95b65203669b","754ce755e6ee05c3f3abf3d61f526c095312c78b178503de17a63bff0979655f","054c6c39d1f97397366b9a1b659a373f0607ed1b3f28fe998d444aa71461fa00","fb01c9b29e184d558c43a512ba05af475ec20eceeace4dde365559da92299892","46bcfbc656e0e2a380a8a94cdc0be3d8b4c668e5f9e54a10ba396a45b371339b"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"product:wave/invoicing/en","quote":"This works great for us.","rating":5,"review_date":"2026-05-21","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a0f4b02577e06943f7e633a","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.