Document Tampering Detection
Detect altered docs using file forensics, with evidence a reviewer can actually understand.
Document forensics is the first compliance checkpoint, before a single field is extracted. Staple inspects the file itself for signs of tampering, scores how trustworthy it is, and shows exactly why it was flagged, so fraud is caught at intake, not discovered in an audit.

The threat model
The document can lie before the data does
Not every bad document is obviously fake. An altered PDF, a manipulated image, or a visually clean fabrication can pass a human review and sail straight into your systems.
Once extracted, a forged figure looks exactly like a genuine one. The only reliable place to catch it is the file itself, before extraction gives it a clean appearance.
How Staple detects tampering
Inspection methods
What Staple examines
Staple checks multiple signals on every document: file metadata such as creation date and modification history, software-origin signals that reveal editing tools, text-layout inconsistencies, and pixel and image-level anomalies.
Together these catch alterations no single check would find on its own.

The result
A score and a clear verdict
Each document receives a configurable confidence score and a classification: genuine, suspicious, or fraudulent. You set the thresholds, so the definition of "suspicious" matches your own risk tolerance.

Evidence view
See why a document was flagged
When Staple flags a document, it shows the reviewer the evidence behind the decision, which signals fired and what looked wrong, in plain terms. A reviewer doesn't need to be a forensics expert to understand why a file needs a second look.

Operational action
Block, route, or continue, by your policy.
Based on the classification, Staple can block a document, route it for human review, or continue processing, according to the policy you set. Genuine documents flow through untouched, and only genuine edge cases reach a person.

See what Staple catches before extraction.
Book a 30-minute demo. Bring real documents, including tricky ones, and we'll run tampering detection live.
FAQ
What is document tampering detection?
Document tampering detection is the process of checking whether a file has been altered, forged, or fabricated before its data is extracted. Staple inspects the document itself, its metadata, structure, and image, rather than just reading its contents, so a manipulated file is identified at intake and never treated as genuine downstream.
How does Staple detect a document that looks completely normal?
Some fabrications are visually clean and pass human review. Staple catches these by analyzing signals a person cannot see: file metadata, software-origin traces from editing tools, text-layout inconsistencies, and pixel-level image anomalies. A document can look perfect to the eye and still fail these forensic checks.
What does the confidence score mean?
Every document receives a score reflecting how likely it is to be genuine, along with a classification of genuine, suspicious, or fraudulent. The thresholds are configurable, so your team decides what level of doubt counts as suspicious and what should be blocked outright.
Can a reviewer understand why a document was flagged?
Yes. Staple shows the evidence behind every flag in plain terms, which signals triggered and what appeared wrong. This means a compliance or operations reviewer can act on a flag without needing forensic expertise, and the reasoning is documented for audit.
What happens to a document once it's flagged?
Based on your policy, Staple can block the document, route it for human review, or allow it to continue. Genuine documents proceed without friction, and only suspicious or uncertain ones are escalated, so tampering checks add protection without slowing legitimate processing.
