Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Also, spent more time helping them fix the app than having it work.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
c799420d41d88a520151d4ee8a0f1bc23888cd83545441c87292d7e26193b87c
Signature (Ed25519, base64)
Ut+VFm02pm6RydjnfDegJCya8J01Fj4g+FaiOUZgecUlRZ0hX86Feq4aMYz8Yu6fLZmeGlnYsijc8SPwESgsAQ==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["c79a15d4542562f3f41b905dc79dc22becc0c94ead9bb18366de3d721cdd58cc","3663480ee7100dcb440ecba5743be38704b74e64d1a4b072b1d2902683b2ea70","532bca2d68ddbf3088eef0d4625e7ce0fecf72224ec80b104ec76035900b0908","da967633ecdcd970250a4a13caece8cff4d0164fd51f5ce65dc95a1cd550a863","ac0e5eff2f71bf9185f51ce3e2318534a8cd51868094eec22b6ecd24caedcf27","a82f973a8e0e57ce60d4855a5be2ff22c729966cfa2d8689983467fa41a2d838","7cffef8e2dd35d839d5757924bf75281115b8c606af42210a5a68db7b230c57c","bae669c372d672a7115511da8bac601b2417a599574d2ed9be9ada4b3a2797df","4b90393eace8760e2a3945694333970052c9e9d1671c7b3449de27ba2a2b2e29","7be99692b1f5adb74f31544330dce9644c845e33963677134c82c62078090163","b0dc38c537eb82e1797634ff3c85b2f502c386d0a2c41284e6c2dc42075eaab1","8f5ec8180fef173ef49bba3555961699c8394cb3b56f59043b48bef17eb12eae","fbc83ea3f323a853561b2d18a7d5d816b1a8631e4674525eac3ed9b0d77501a2","ebe1651655c8b61b6b5364f1f9c2df6d3d2570b884eb1475b1f154f5054feeba","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:everand/durability/en","quote":"Also, spent more time helping them fix the app than having it work.","rating":1,"review_date":"2026-03-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.scribd.app.reader0","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.