Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“neither the recovery key or QR Code would work sighting “incorrect information””

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
c9cd06affcf135608d817be2b3767cdb0243e4afae657166e21176ca6bbcc7ca
Signature (Ed25519, base64)
yGdS6Weu766x9qzMhPMN7ziqHn+fAVb5Q1v5ZUsRm+z4jJZVvOoMd3LhitShwh1u5d5tOIYEaUnz2Vl7jupOCA==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["c9c94ecc72924e1eab9283f062e2279860a44fec64073246739dcceb5ecdb16a","c77e6dffca9e2f8b3f1a9429712249d3f1f56b5580f7e4ef25b43a61ba288aba","5e2f932837da1d57899c990b532c3d0090389b71efae252e4b404119e380cdb3","1f8b49761f8bdcd0002a3c1495c9d68029916f8a1cf6a517d61a5d93526fe6d8","7e5c67de541ec7415f2c35fc646f0205f1522b7749be579703556da29508310a","fed5e3384cc0c56c45272453d67d13cc50a967cf7f131efdd8d4ba8bb911ae02","db1cadfe1b7e655bd1e822df7905391498760af0cdf1bd2742e41bb992ba82ad","52b5a5e521b19f833ef6936898dc00f888e3839a8bb53dcd9b5dcda0bf285093","4c0e3ddc8435fd435b817a25dc7d9a0c420f16fbb80a9a18c1e1a89e16c504b4","f0401f6668c1e53131a7091e45e0838dcca72534cd5ad98e9579977ca82cd5e3","8c9100cbddd92135ea974aa1de801700e80705582bb520a7570452dddc6d977e","754ce755e6ee05c3f3abf3d61f526c095312c78b178503de17a63bff0979655f","054c6c39d1f97397366b9a1b659a373f0607ed1b3f28fe998d444aa71461fa00","fb01c9b29e184d558c43a512ba05af475ec20eceeace4dde365559da92299892","46bcfbc656e0e2a380a8a94cdc0be3d8b4c668e5f9e54a10ba396a45b371339b"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:tuta/returns/en","quote":"neither the recovery key or QR Code would work sighting “incorrect information”","rating":1,"review_date":"2026-03-28","source":"Apple App Store","source_url":"https://apps.apple.com/au/app/id922429609?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.