Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“It's a good app, but it sometimes fails to pop up when needed, which is annoying.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
e1836a7a695c6356cffad7034c485b205acab53d11333df90f84535c4eb31a58
Signature (Ed25519, base64)
JuYcx7iroQd2VTF3tgiI00Tz4clafUUFJQPAbGyv2GmzZGfoXgZtS/4twbNOoBbrtSm8Hob7SmH6BqausNfnBA==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["e17e32fc481cb34c2537ddd575521a0a7401ccc682ce42320a472662b341935d","36e89f7d1e6df2d465036e8205cf9468b8e61a7075aa0a8a4443f298bb08e4f1","4258f4676739d1ff4a1dfd126f5d988cff25add51c3657d3c61daf30f4ea57c1","83e39a5d9ee69d59c2d04d6a91950b708c21139af3ca75457ac08b395a29c406","ef5f12fd97735f587b1ad34831e90a081c1374d3645f8377692cdccefb490d82","bd6a25014b73cb92b9e3b4d790909f2d217422bed3d3c79140804860d26467e5","795482bc35cf50fbd3c260be5765dee9940709b2f228011242f4bc96452c5704","465d7e67fd3e3acc5c9cc0f1cb933311808305e30a80f14b5bae04e95d0d47f5","11651711677f93094f00c8263b86c08d0a0a0cffa775f60c7b2a57aee816e1ad","000f7eef031ca038d3066c97b177f6dd0ae6af8f09805ef3eae4f1a18cda7dec","341cca8d51d1839f5f1c76313bc70c42466b2a8f28fbb1520e70fae87c581435","640b197bc6c52e1ae889c0e8b7a59a99fcc90984c8b3bd71fee23168c95ccff5","6a087565eaa0768d4c576fd78f88585a902d61259a245be7f47bc24b1ead4c18","fb01c9b29e184d558c43a512ba05af475ec20eceeace4dde365559da92299892","46bcfbc656e0e2a380a8a94cdc0be3d8b4c668e5f9e54a10ba396a45b371339b"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:keeper/quality/en","quote":"It's a good app, but it sometimes fails to pop up when needed, which is annoying.","rating":3,"review_date":"2026-07-06","source":"Trustpilot","source_url":"https://www.trustpilot.com/reviews/6a4b9c1a201842ff34145098","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.