How we examine your documents
Every document you submit is inspected for physical traces of alteration — in how it was built, where it came from, how its text sits on the page, and how its images were compressed.
Your result
Every document comes back as one of four results
The four results form a scale. They describe how much evidence of change we found — not how serious that change was, and not whether anyone did anything wrong.
Not Modified
We found no meaningful evidence that the document changed after it was created. Everything we examined is consistent with an original file.
Possibly Modified
We found only faint, circumstantial traces — the kind ordinary handling can leave behind. The file is not perfectly clean, but nothing we found points to deliberate alteration.
Likely Modified
We found at least one substantive trace that the document was changed after it was created. This is more than routine handling leaves behind.
Modified
We found evidence strong enough to conclude the document was changed after it was originally created. One or more findings are serious enough to carry this result on their own.
“Modified” does not mean “fraudulent”
Documents change for entirely legitimate reasons. Someone opens a PDF to fill in a field. A stamp is added. A file is re-saved to email it. Our analysis reports evidence of change — it does not judge intent, and it cannot tell an innocent edit from a dishonest one.
This is why every result carries its findings with it. The verdict tells you how much we found; the findings tell you what it was. Read both.
Examination
What we examine: 22 checks across six areas
A document is not just what it displays. Underneath, it carries a record of how it was made, what software touched it, how its text is positioned, and how its pictures were compressed. Forgery is easy on the surface and hard underneath — which is where we look.
Digital signatures
PDF3 checksA digital signature is a mathematical seal: it guarantees a file has not changed by a single byte since it was signed. When that seal is broken or missing, we say so.
The signature is broken
The document presents itself as signed, but the underlying signature data is corrupted or has been stripped out. Whatever guarantee the signature once offered is gone.
Signatures were removed
No signatures remain, yet the file’s internal structure still carries their traces. The document was signed once, and something took the signatures out.
Signature fields were left empty
The document sets aside places for signatures that were never filled. Someone was expected to sign this and did not.
Origin and authoring history
PDF3 checksEvery PDF records the software that created it and the software that last wrote it, along with its own timestamps. Documents rarely lie about their own paperwork.
Opened in a PDF editing tool
We recognise a broad range of software whose purpose is to change the contents of a finished PDF — its text, its images, its pages. The document records having been through one.
Created in a graphic design application
The document was drawn in design software rather than produced by a document or records system. Genuine certificates, statements and invoices are almost never made this way. Fabricated ones frequently are.
Changed after it was created
The file’s own record of when it was created and when it was last written disagree. It was revisited after it was first made.
Internal structure
PDF2 checksA PDF is assembled in layers, and it keeps its own construction history. That history is difficult to forge convincingly, because it is written by the software rather than the author.
Saved repeatedly after creation
Each time a PDF is edited and saved, it appends a fresh layer rather than rewriting itself. Those layers accumulate, and they are visible to us — a document that has been worked on carries the marks of it.
Contains embedded code
The document carries executable instructions inside it. This is legitimate in interactive forms, and it is also a way to change what a document shows depending on how it is opened.
Typography
PDF1 checkWhen software embeds a typeface into a document, it leaves a fingerprint in how it does so. Two tools working on one file leave two fingerprints.
Text was added by a different tool
The same typeface is embedded twice, in two different ways, inside one document. This is what happens when text is inserted by software other than the program that originally produced the file — a signature of later editing that is invisible on the page itself.
Page content and layout
PDF6 checksThis is where alteration usually shows itself. We examine where every piece of text physically sits, what lies beneath it, and whether the page’s composition matches how it claims to have been produced.
Text was replaced at a specific location
Two different pieces of text occupy the same position on the page — one sitting directly over the other. The original wording is still there, underneath the replacement.
The document was recreated from a screenshot
The page is a picture of a document with fresh text typed on top of it. This is one of the most common forgery methods we see: photograph or screenshot a real document, then lay new details over the old ones.
Text was added on top of a scan
The page is a scan of a physical document, but typed text sits above the scanned image. That text was never on the paper that went through the scanner. We distinguish this from the searchable text layer that scanners legitimately produce.
Extra images were added to a scan
A scanner produces one image per page — that is simply how scanning works. This page carries more than one, which means images were placed onto it after it was scanned.
Annotations were placed over the content
Stamps, boxes, or text notes sit on top of the page rather than being part of it. They may be covering what lies underneath.
Invisible text was found
Text exists in the document that has been rendered effectively unreadable against the page — present in the file, absent to the eye.
Image forensics
Images7 checksPhotographs and scans compress in a consistent, predictable way across the whole picture. Editing disturbs that consistency, and the disturbance survives even when the edit is invisible. These checks run on image files you submit; our compression-consistency analysis also runs on pictures embedded inside PDFs.
Regions that do not match the rest of the image
We analyse the picture in small blocks and compare each against the whole. Areas that have been worked on stop matching their surroundings. This check surfaces in four distinct forms:
- Localised editing — a region has been altered while the rest was left alone.
- Smoothing or filling — a region was blurred, cloned, or filled in, typically to remove something.
- Mixed compression — a region was processed differently from the image around it.
- Copy-paste boundaries — sharp edges appear where one area was pasted over another.
Parts of the image come from different sources
We re-examine the picture at several compression levels at once. Areas that originated elsewhere respond differently from the rest, revealing content that was brought in from another image.
The image was processed by editing software
Photographs carry hidden data recording the equipment and software that handled them. This image’s record names image editing software.
Editing software named in the image’s metadata
The same finding, drawn from a different place in the file. Different image formats keep their history in different compartments, and we read all of them.
The image was modified after it was captured
The moment the image was originally taken and the moment it was last written are not the same. Something happened to it in between.
Traces of Adobe software
Professional image tools embed their own working data into files they touch. Those traces remain even after the visible edit is complete.
The image’s dates disagree
The file’s creation and modification timestamps conflict with one another, indicating the image was changed after it was first made.
Weighing
How findings become a verdict
Counting findings would be a poor way to judge a document. A stamp on a contract and a broken signature are not the same kind of evidence, and a system that added them up like items on a receipt would be wrong constantly. Four principles govern how we reach a result.
Findings are not equal
Each carries its own weight, set by how strongly it indicates real alteration rather than ordinary handling. Some are decisive alone. Others mean little by themselves and only matter in company.
Related findings are counted once
A single editing session leaves several traces at once — the tool’s name, a shifted timestamp, an added save layer. These are not three discoveries; they are one event seen from three angles. We group findings that describe the same underlying event and let the strongest of them speak for the group. Without this, one ordinary edit would look like a conspiracy.
Independent findings accumulate
Traces that cannot be explained by a single event reinforce one another. Several unrelated weak indicators can together outweigh one moderate one — because coincidence gets less believable the more of it there is.
The verdict follows the evidence, not the tally
The result reflects the combined strength of what we found. A document with one serious finding can rank above a document with several trivial ones.
Restraint
What we deliberately do not flag
A detector that suspects everything is worth nothing. Much of the work in this system is spent recognising the ordinary — the legitimate things documents go through on their way to you — so that genuine documents come back clean.
Scanning and text recognition
Scanned documents carry an invisible searchable text layer. We recognise it for what it is, rather than reporting it as text added to a scan.
Compression and merge utilities
Tools that shrink a PDF or combine several into one pass through the file without changing what it says. We distinguish them from editing software.
Extra save layers on signed documents
Digitally signed PDFs legitimately record additional layers as part of signing. We account for that instead of counting it against them.
Missing camera data
Screenshots, crops and images from the web carry no camera record. That is normal, and it is not held against them.
Everyday production quirks
Most PDFs are created by one program and written by another. Ordinary discrepancies of this kind are noted as context, not raised as findings.
Confidence & limits
What the numbers do and do not say
Confidence answers a different question
Alongside the verdict, each analysis carries a confidence figure. It is easy to mistake it for a measure of suspicion. It is not.
Confidence measures how much there was to examine. A document rich in metadata, embedded fonts, signatures and structure gives us a great deal of material to work from. A bare image stripped of its history gives us far less.
So low confidence does not mean a document is doubtful — it means our reading of it rests on thinner material. Confidence describes the evidence available; the verdict describes the evidence found.
What this analysis cannot tell you
We would rather state our limits than have you discover them.
We examine the file, not the facts. We can tell you a certificate was rebuilt in design software. We cannot tell you whether the marks printed on it are the ones the student earned. Verifying facts means going to the issuer.
Finding nothing is not proof of anything. A forgery that is printed and rescanned may carry no digital traces at all, because the traces were left behind on the old file. “Not modified” means we found nothing — not that nothing happened.
We report change, never intent. No part of this analysis knows why a document was altered, or by whom. That judgement is yours, and the findings exist to inform it.
Questions
Frequently Asked Questions
My document is genuine, but it came back as modified. How?
Can I see why a document was flagged?
Does a clean result mean the document is authentic?
Why not simply tell me the exact thresholds you use?
Run this analysis on
your own document
Upload a PDF or image and see the verdict, the confidence figure, and every finding behind them — free, no signup for the first check.
Leading AI-powered document verification platform trusted by enterprises worldwide.
For Technical Query
Quick Links
Use Cases
Solutions by Industries
INDIA
Office No. C2-501/502, SAUDAMINI COMPLEX, Survey Number- 101, 1, Kothrud, Maharashtra 411038
Ph:+91 95525 86428
USA
1100 Fern St SW,
Olympia, WA 98502
Phone : +1 (360) 742-0870