Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Ich habe gerade eine betrügerische E-Mail erhalten, die sich als Deezer ausgibt.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
d10b69169272b2ba3ccb86caf6b5a7765e64ee995b7f770a6e12cf7087832d6e
Signature (Ed25519, base64)
j8RiOhfRrOH0pXxsVVpsBclRL2F3ys5Ki99uaf4l9i/hQ6Z43e6YHID4VNK9iHZw6T+ZoZXWcvWY7Sj0nDWfCA==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["d10cf5833d43462e404247f4d8d64b650268d15bf67fff2a67595871ea9e2cc1","afc2124a534a1f48990df13101ff18eecb8432cb75f868c7acafb5ac47f7d1d1","1a7555558c105a70353a2a44b295d9dbfda9fbe9b49043a6720a0aec49c73e73","513d697daa5894dbd9e42d1c4c8055e853d19797f406196daa3e22d446aef833","7c5a65824915e7d169d713ac4abfe1cec5ff434cb33698d9e17ef4298ef7a4ef","cf74dcaf22ed81a63e696ee3535f343321cc4c084a7728d0936aca1f67e621bc","79338ec9b70b1f0de9f5ba686a1e5be932cc736cefa449db1815875e1997ddd5","edc147e48f150e3f9bcdc9d6c57a439a93aaf5b7688c5780430efcb468c5d951","3ec58310fba3bcb5df96a580124711a59177af51f8e6110fc8b9bf45b537acc1","5da23f172d5ea136773e24ed99f9928e85691f4631db46f2d02ab6cd785d2e93","965c6f3504d9254a43c0d710c5dfd4832048329c4849a13b039d2f9d992a09ed","88c1267a6d70047cee180b9815247bc1da5a16a96b57f3fe20a9c2533caa110d","44c8cb0eec3d4c66924c6271a9a32942cc950a307a9339cedf9246ffe3125d65","b763ea1ef84637e764decc45acddfba68cbd65e2d958f57cfeabc8af53520b04","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"de","page":"theme:deezer/billing/de","quote":"Ich habe gerade eine betrügerische E-Mail erhalten, die sich als Deezer ausgibt.","rating":1,"review_date":"2026-09-13","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=deezer.android.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.