Data Integrity & Tamper Evidence
A document that has been altered is worse than a document that is missing, because it looks trustworthy. For regulated enterprises handling invoices, claims, and identity documents, integrity has two halves: proving a file was genuine when it arrived, and proving no value was changed after Staple processed it. Staple covers both, and attaches the evidence to the data so the next system can check it too.
Tamper Checks Before Extraction
Before a single field is read, Staple runs document tampering detection on the file. The forensic layer combines several signals a human reviewer cannot see, however experienced.
• File metadata forensics: creation date, modification history, and software origin, which expose post-creation edits even when the document looks clean.
• Pixel and image anomaly analysis: copy-paste artefacts, font inconsistencies, and compression anomalies left behind by editing tools.
• PDF properties and text-layer analysis: structure and embedded-object checks that catch digitally manipulated files.
The result is a tamper confidence score and a classification of genuine, suspicious, or fraudulent, with thresholds configurable per queue. A flagged document arrives with the specific indicators that triggered it, not a bare verdict, so fraudulent files are held with evidence before they ever reach a credit officer, a claims handler, or a downstream system.
Sealing Values After Extraction
Once a value is captured, Staple applies field-level sealing. Any change made afterward is immediately visible and recorded in the per-field audit trail with the before-and-after value and the reviewer who made it. Integrity is not a one-time gate at ingestion, it is maintained across the life of the record. This matters because most fraud and most honest error enters after a document is accepted, when a value is edited in review or in a downstream system, which is exactly the window a one-time ingestion check leaves unguarded.
How The Seal Is Computed
The seal is not a checksum a downstream editor could quietly recompute. It starts from a SHA-256 hash of the original source file, so the proof is bound to the exact bytes that arrived. The structured result and its context are canonicalized to a stable byte form and signed with an Ed25519 cryptographic key, which means verification is exact: alter a single figure and the signature no longer matches. Anyone holding the data can check it, and the check runs offline because the proof lives in the artifact rather than on a server they have to reach. There is also a distinction the standard makes explicit, a signature can be technically valid yet come from an unknown key, so trust additionally requires a key endorsed through the MSD Network, giving a chain back to a known root.
Proof That Travels With The Data
For data that leaves Staple, integrity is carried by Metastructured Data: a cryptographically signed record bound to the value itself. Because the seal is computed from the original source file, if any figure is altered downstream, in transit, in storage, or inside an ERP, the signature breaks and the change is detectable by the next reader without calling Staple. The Metastructured Data standard describes how the envelope and signature work, and the open side of it is documented under Open Trust Infrastructure.
Where Integrity Meets Reconciliation
Integrity checks feed the business rules and anomaly detection engine and cross-source reconciliation, so a suspicious document, a total that does not add up, and a line item that fails a three-way match are surfaced in one reviewer view rather than three disconnected alerts. A reviewer sees a single, ranked picture of why a document is risky, instead of stitching signals together by hand.
Built For Regulated Environments
The forensic record is fully reconstructable for internal audit, regulatory inspection, and dispute resolution, with every check and classification timestamped. Staple is SOC 2 Type II and ISO 27001 certified, with data residency options across Singapore, Malaysia, the UK, and the EU, supporting BNM, MAS, FCA, and equivalent AML and CFT fraud-prevention requirements.
What This Does Not Do
Staple detects and evidences tampering and change. It does not certify a document as legally authentic on your behalf, and it does not overwrite a suspicious file. It gives your team the evidence to make that call and the record to defend it.
Proven In Production
A global security and cash management company operating in more than 50 countries processes high volumes of invoices and tax documents, where a single altered figure carries real financial exposure. Staple screened documents for tampering before extraction and matched values three ways before release, so a manipulated figure was caught with evidence rather than paid.
Related Capabilities
• Document Tampering Detection
Test Integrity On A Tampered Document
Send us a genuine file and an altered copy. We will show you the tamper score, the evidence, and how the change is surfaced. Book a demo.
Related Topics
See Staple process your documents
Book a 30-minute demo with a document processing specialist.
Not ready yet?
Take your time to decide.