Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I've been using it for 5 years and it works very well.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
edcbdb56a5e07f1adb94459276d31907b2338065979f429c194d07d0643b0e3f
Signature (Ed25519, base64)
Wcxh7KN1fRg19wgE0g0euxIeVruPqitQ0aL2U8Tpup46vmzqs5RbR2oAZiEZDJ9JBsnzj2EElND2ZWdpKJBYBw==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["edcd19c120473ae86dc3ca8970ac73185b4f3009ae3f6aba8f005f5d816a551f","2df73b785ed16ccdbd0a5e076a452646aeca35f43df5cd35b51b5d050db50a8e","6ff36c2c2c3b815bab02cb9a26e5cb7880d63fb0296e309a8515c6100c3f775d","68b50a91db58501d7bba9571e4da970fae8fbfd364630ce1e01dbc33bcdcdf1d","c4484902d22cdfd4e6944b049f893c28813f95845473c5bce9fb7ac6559e0af3","384e846f1dded9368c308b8350c4b5556daa6efe444c4d3ec9863bf4dad8f3db","03e5b05dabcdefc81bda7a88f7404e34858787d0f0c597cb183b1c01dae60f9c","be3ffe0c9efbe274c917f278b113dd4bd5c872ace8aa14dc79ab2ad0cad8087d","89f96de914557acba977a672d7b7e1dfe70dab66295b5d0319aa6e237a068ac1","0d4e3a64b73f4ec4a16f91c21f23e86eefb07bfcbca9631a096a42c84e2ffa4b","8d86c589eb2eee8874e11ac8667476155b0a0d09f41ce045f571cfca33f7602d","adfb7af951ab6d82fe2ac7465e5f822234f3eb32c74ff914d3090db1700baa73","34bf35d805c4f7af315854dc10a7a10ae0ea054d46dee40b360c3f04f8b8e60c","58a3dfc9ad8696e92f5fc9960e9c6bc4cc04e270091b574a948593298b33d1f5"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:rappi/durability/en","quote":"I've been using it for 5 years and it works very well.","rating":5,"review_date":"2026-07-10","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.rappi.restaurants","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.