Algorithm Updates
Changelog
Latest updates and improvements to HTPBE?
Latestv2.43.1
- Verdicts shown in list, dashboard and summary views now match the verdict returned for the same document on its own. Some documents that previously appeared in a list as an untouched original, or as modified, now show there the inconclusive result they already returned when retrieved individually, and some older records that carry no stored result now show no verdict rather than a clean one. Individual document results are unchanged, and detection itself is unchanged.
v2.43.0
- Added a new check that catches documents whose page content was produced in one application and then rebuilt by a second, unrelated tool that rewrote the file’s stated origin — including files that try to hide this by claiming to come from an unrelated generator. Such documents are now reported as modified — a class that previously passed as unmodified or inconclusive. Genuine documents are unaffected and continue to be judged as before.
- Extended origin handling to a further class of documents whose origin cannot be established firmly enough to certify them as an untouched original: some files that previously returned a clean, untouched-original result now correctly return inconclusive and route to human review. Structural modification detection is unchanged.
- Broadened detection of documents whose pages were assembled from multiple separate sources rather than produced as a single original, catching a further class that previously passed as unmodified or inconclusive — including packages combined by an otherwise legitimate tool. Such documents are now reported as modified, because a document built from more than one source is never certified as an untouched original. Genuine documents are unaffected and continue to be judged as before.
v2.42.1
- Fewer genuine templated documents, such as government-issued certificates and other form-based documents, are mistakenly reported as modified.
- Modified verdicts that the evidence does not fully support now report at a lower confidence level instead of as a certain result.
- Fewer genuine digitally-signed documents are mistakenly reported as modified, while edits made after signing are still detected.
v2.42.0
- Added a new check that catches documents where part of a page was covered over to substitute content after the document was created. Such files are now flagged as modified — a class that previously passed as unmodified.
- Reduced over-certification on a class of documents whose origin cannot be established firmly enough to certify them as an untouched original: some files that previously returned a clean, untouched-original result now correctly return inconclusive. Structural modification detection is unchanged.
v2.41.0
- Added a new check that catches fabricated documents that were assembled rather than genuinely produced by the source they present as coming from. Such documents are now flagged as modified — a class that previously passed as unmodified. Genuine institutional documents are unaffected and continue to be judged as before.
- Reduced false positives on a class of genuine hardware-scanner output that was occasionally reported as modified. Files in this class are now correctly recognized as scan-origin and reported as inconclusive rather than modified. Their verdict is never raised to unmodified, and edited scans or documents merely disguised as scans continue to be reported as modified.
- Broadened detection of image-only documents that merely reproduce a document rather than being the authentic original file, catching a further sub-class that previously returned an inconclusive result rather than being reported as modified. Such documents are now reported as modified. Genuine documents are unaffected and continue to be judged as before.
v2.40.0
- Broadened detection of documents that were altered after their original creation, catching a further sub-class that previously returned an inconclusive result rather than being reported as modified. Such documents are now correctly reported as modified. Genuine documents are unaffected and continue to be judged as before.
v2.39.0
- Added a new check that catches documents whose metadata claims a scanner or optical-character-recognition capture origin that the file cannot genuinely have. Such documents are now flagged as modified — a class that previously passed as unmodified. Genuine device scans and OCR captures are unaffected and continue to be judged as before; the flag is reserved for documents whose claimed capture origin does not hold up.
- Added a new check that catches documents that were altered after their claimed original creation even though the file is presented as an untouched, natively-produced original. Such documents are now flagged as modified — a class that previously passed as unmodified. Genuine documents, including ordinary format conversions and re-saves, are unaffected and continue to be judged as before.
v2.38.3
- Reduced false positives on a class of legitimate documents — such as freshly captured mobile-scanner or photo PDFs — that were occasionally reported as modified because of an innocuous discrepancy in their recorded timestamps. Documents in this class are no longer flagged on that basis alone, while documents with genuinely inconsistent dates continue to be detected and no correct modified verdict is affected.
v2.38.2
- Reduced false positives on a class of legitimately digitally-signed documents that were occasionally reported as modified even though their content had not been changed. These documents are no longer misjudged this way, while any document that was actually altered continues to be detected and correct modified verdicts are unaffected.
- Strengthened detection of genuine post-creation content edits, so that more documents whose figures or text were substituted after the original was created are correctly flagged as modified rather than left inconclusive. Documents that were never altered are unaffected and continue to be judged as before.
v2.38.1
- Broadened detection so that more documents where content is concealed behind an opaque blackout box are correctly flagged as modified. A range of such documents that previously passed as unmodified — including altered financial statements whose figures were hidden behind blackout boxes — are now reported as modified. Covering content on the page with a blackout box alters the document and is reported as a modification regardless of why it was applied.
- Reduced false positives on a class of legitimate print-to-PDF documents that were occasionally reported as modified without actually indicating tampering. Documents in this class are no longer flagged on that basis alone, while genuinely altered documents continue to be detected and no correct modified verdict is affected.
- Reduced false positives on a class of legitimate digital documents that embed graphics such as logos, banners or letterheads and were occasionally misread as scan-based. Documents in this class are no longer flagged on that basis alone, while genuine scan-based forgeries continue to be detected and no correct modified verdict is affected.
v2.38.0
- Added a new check that catches documents which pass themselves off as having come from a physical scanning device when they were in fact produced by software. Such documents are now flagged as modified. This targets one-click tools that dress up software-made files to look like genuine scans.
- Genuine device scans are not affected by this new check and continue to be judged as before; the flag is reserved for documents whose claimed scanner origin does not hold up.
- Reduced false positives on a class of genuine documents captured with mobile scanning apps that were previously flagged as modified. These are now returned as inconclusive rather than flagged — and are never reported as untouched originals — while genuine post-production edits continue to be flagged as modified.
v2.37.5
- Reduced false positives on a class of legitimately produced documents that were being flagged as modified because their page layout resembled that of an altered file, when in fact it does not indicate tampering. Documents in this class are now held as inconclusive instead of being flagged. This never makes a document pass as an untouched original — such files stay inconclusive — and it never forces a modified verdict; documents held by any other check remain flagged. A genuine post-production content edit still fires and stays modified.
- Extended the same relief to another class of legitimately produced documents whose appearance, on its own, resembled that of an altered file without actually indicating tampering. Such files are now held as inconclusive when nothing else is amiss, never passed as untouched originals, and any independent sign of a real edit still keeps them flagged.
v2.37.4
- Reduced false positives on a class of legitimately generated documents whose internal characteristics coincidentally resembled those of an unrelated tool. Documents in this class are no longer flagged on that basis alone. This never lets a genuinely edited document pass as an untouched original, and documents held by any other check stay flagged.
v2.37.3
- Some documents whose origin cannot be reliably established were being treated as untouched originals. They are now held as inconclusive instead of passing clean, because origin alone is not enough to confirm an intact original. This never forces a modified verdict — documents flagged by any other check stay flagged.
- Closed a narrow case where a document carrying strong evidence of tampering could still be softened to an inconclusive result. Such documents are now flagged as modified, consistent with how the same evidence is already treated elsewhere.
- Reduced false positives on a class of legitimately generated documents that were flagged as modified because of an internal metadata quirk that, on its own, does not indicate tampering. A document positively recognised as legitimately generated is no longer flagged on that basis alone. This never lets a genuinely edited document pass as an untouched original, and documents held by any other check stay flagged.
v2.37.2
- Removed a false basis that was flagging a class of genuine scans as modified. A document positively recognised as an authentic scan is no longer flagged as modified on that basis alone. This never makes a document pass as an untouched original — such files stay inconclusive — and it never forces a modified verdict; documents held by any other check remain flagged.
v2.37.1
- Closed a route where a document carrying strong evidence of tampering could be under-reported. When such hard evidence is present, the document is now flagged as modified.
v2.37.0
- Added a new detection that catches a further class of documents which were edited and then disguised to advertise a harmless, untouched origin they do not actually have — a laundering shortcut used in forged statements and letters to make an altered file look like it was never touched. Documents in this class are now flagged as modified.
- Reduced false positives on a class of legitimately-generated enterprise reports that were previously flagged in error. Documents in this class no longer receive a false modified flag. No document passes as an untouched original on this basis alone.
v2.36.1
- Removed a false basis that was flagging a legitimate class of print-to-PDF documents as modified. Documents in this class no longer receive a false modified flag on that basis. This does not by itself make a document count as an untouched original — the final verdict still depends on our other checks.
v2.36.0
- Extended detection of institutional documents — enterprise statements, payslips and official letters — that were altered after issuing, closing a laundering route that previously let some edited files pass as originals. Documents in this class are now flagged as modified.
v2.35.0
- Added a new detection for documents where information that appears removed from the page was not genuinely removed, even though it looks concealed when the page is viewed. This is a common shortcut in forged statements and letters, where sensitive figures are only made to look gone. Documents in this class are now flagged as modified.
v2.34.4
- Refined origin handling so a class of legitimate institutional report and statement documents is no longer automatically capped at inconclusive when no other modification signal is present. This never forces a modified verdict on its own.
v2.34.3
- Broadened detection of documents that were edited and then re-rendered to pose as a plain scan — closing a laundering route that let a further class of such files slip through as inconclusive scan-origin rather than modified. Files in this class are now correctly flagged as modified.
- Refined how the result report names a class of form-based documents, separating genuine fillable forms from documents that carry a digital fill-and-sign overlay so each is labelled accurately in the report. This is a reporting-clarity improvement only — no document changes verdict as a result, and both categories are treated exactly as before.
v2.34.2
- Tightened origin classification for a further class of web-rendered documents that cannot be certified as untouched originals — these now correctly settle at inconclusive rather than passing as untouched originals. This never forces a modified verdict on its own.
v2.34.1
- Tightened origin classification for a further class of documents that present as institutional — bank and wallet statements, payslips and official letters — but were exported straight out of consumer desktop office software rather than an issuer's production system. Because a file anyone can produce in desktop office software cannot be certified as an authentic institutional original, such files previously passed as untouched originals and now correctly cap at inconclusive. This never forces a modified verdict on its own.
v2.34.0
- Added a new detection for documents that carry a genuine institutional body — enterprise payroll, statements and official letters — but whose metadata layer was fabricated to forge the producer identity and hide that the file was changed after its original creation. Files in this class previously passed as untouched originals and are now correctly flagged as modified.
- Fixed a false positive in our signed-document check on a class of correctly signed institutional documents that were previously read as modified. Legitimate signing from more signer implementations is now recognised correctly, so these documents pass.
- Extended our value-substitution check on scanned institutional documents to catch a further forgery: an official scan whose original substantive values were removed and replaced with different ones before it was saved as a single clean file. This class previously passed as an untouched original and is now correctly flagged as modified.
- Added a new detection for institutional and enterprise statements whose declared origin contradicts the rest of the document — indicating it was rebuilt and re-labelled after its original creation. Files in this class previously passed as untouched originals and are now correctly flagged as modified. In the same pass we fixed a paired false positive: genuine statements from that same class of automated report generator were previously misread and wrongly flagged, and now correctly pass.
v2.32.0
- Improved classification accuracy on scanned and image-based documents, cutting false modification flags on a class of legitimate exports that were previously misread as edited.
- Recovered detection on a further class of documents that were altered after their original creation — closing a case where some such files previously slipped through.
v2.31.3
- Improved accuracy on a class of legitimate table-styled documents — invoices and statements whose normal design was previously misread. These now correctly pass.
- Reduced false positives on a class of legitimate enterprise renders that were previously misread as assembled from multiple sources. These now correctly pass.
- Tightened origin classification for a further class of documents that present as institutional — payslips, statements and official letters — but were produced by consumer desktop office software rather than an issuer's production system. Such files previously passed as untouched originals and now correctly cap at inconclusive, because that class of file cannot be certified untouched. This never forces a modified verdict on its own.
- Reviewed the published check catalogue and consolidated a few checks whose outcome was already covered by a stronger, more specific check — folding them into that check so every published entry now maps to one distinct outcome, and began publishing the number of distinct structural signals those checks evaluate. No document changes verdict as a result; this is a clarity pass on how our coverage is presented, not a change to what we detect.
- Reduced false positives on a class of legitimate documents produced by automated report generators, whose ordinary output was previously misread as evidence of editing. These now correctly pass.
v2.31.2
- Improved accuracy on a class of legitimately signed documents that were previously flagged as changed after signing when they had not been. These now correctly pass.
- Tightened origin classification for a further class of web-rendered documents that cannot be certified as untouched originals — these now correctly settle at inconclusive rather than passing as originals. Structural tamper checks continue to run independently.
v2.31.1
- Broadened detection to catch a further class of documents that were rebuilt after their original creation but still passed off as untouched originals — a laundering step used to dress up a forged payslip or statement. Files in this class previously slipped through and are now correctly flagged as modified.
- Tightened origin classification for a further class of documents that present as institutional but show consumer-grade origins — these now correctly cap at inconclusive instead of passing as untouched originals. This never forces a modified verdict on its own.
v2.31.0
- New detection class for documents that were digitally rendered into a single full-page image and then presented as a scan — a way a forged file is dressed up to look like a camera or scanner capture. Such files previously passed as inconclusive and are now correctly recognised as modified.
v2.30.0
- Expanded detection of documents that were edited after their original creation — closing a case where some such files previously slipped through.
- Extended scanned-document recognition to a class of multifunction scanner/copier devices and their companion apps that were previously misread as born-digital originals — their output now correctly caps at inconclusive instead of passing as an untouched original.
- Made verdicts fully deterministic, so a document always receives the same verdict regardless of which server analysed it.
- Tightened origin classification for a class of consumer office-suite exports that present as institutional documents — such files previously passed as untouched originals and now correctly cap at inconclusive, because that class of file cannot be certified untouched.
- Recovered detection on a class of fixed-template institutional statements that were rebuilt after the issuer originally produced them — a rebuild path used to alter a value on an otherwise authentic statement. These are now correctly flagged as modified.
v2.29.0
- New detection class for documents that were reworked in an interactive PDF editor after their original creation — a common way a forged statement or letter is built, where an authentic document is opened in an editing application, a value is altered, and the file is saved back. Files reworked this way previously passed as untouched; they are now recognised as edited after the fact, surfaced under the same edited-in-an-editor outcome as our other content-editing checks.
- Reduced false positives on a class of genuine machine-issued enterprise bills and statements that carry light printed mailing marks — these authentic documents were previously flagged as modified and now pass.
- Broadened our edited-in-an-editor detection to recover a further class of documents reworked after their original creation — the kind of post-creation editing behind a forged statement or report. The recovery works independently of which editing application was used, so this class is caught no matter the tool that produced it, and is surfaced under the existing edited-in-an-editor outcome.
- Reduced false positives on a class of genuine machine-composed institutional financial and retirement statements that were wrongly flagged as modified.
v2.28.0
- Added a new proprietary integrity signal to the detection suite. We are publicly acknowledging that this signal exists, but — unlike our other checks — we are deliberately not disclosing how it works. The detection method is held back on purpose so that forgers cannot read a description of it and engineer their way around it. When it fires, it contributes corroborating evidence that the file is a modified derivative rather than an untouched original.
- This is the first check in the catalogue whose mechanism we keep undisclosed by design; every other check continues to be described in plain outcome terms.
v2.27.1
- Reduced false positives on a class of genuine table-layout documents that were wrongly flagged for concealed content.
v2.27.0
- Reduced false positives on a class of genuine government and corporate forms whose normal issue process previously caused them to be mistaken for modified files. Authentic forms of this kind are no longer flagged on that basis alone.
- New detection class for documents reassembled by a person in a design tool rather than produced by the named issuer — a construction pattern no institution uses for its statements, certificates, or forms.
- New detection class for documents whose origin records were regenerated by a separate tool after the original authoring.
v2.26.1
- Broadened detection of documents assembled by merging pages from more than one source file — recovering a class of plainly-built merges that previously slipped through certified as a single original, including documents with extra pages glued on after the fact.
v2.26.0
- Retired a standalone metadata check that produced false positives on genuine documents without adding coverage beyond our structural modification checks.
- New detection class for an institutional document that was opened and re-saved by a second tool after its original creation, with no digital signature to account for the change — a post-creation re-stamp pattern that is now caught on its own structural evidence.
- Restored detection of documents assembled by merging pages from more than one source file — now recovered on its own structural evidence, including on merges that were subsequently rebuilt to look like a single original.
- New detection class for a stamp-overlay edit — substitute values layered on top of an otherwise-untouched original page to alter what it appears to say.
- New detection class for a cover-and-replace edit — original content concealed and replaced with substitute values to change what the page reads.
v2.25.3
- Reduced false positives on a class of genuine documents produced by physical scanning hardware whose output was previously being misread as a synthetically-rendered imitation of a scan — authentic scans of this kind now correctly settle at the not-certifiable scan-origin ceiling instead of being flagged as modified.
v2.25.2
- Widened the class of re-rendered documents we decline to certify as unmodified, so this class is now consistently treated as not-certifiable rather than passed as clean. Structural tamper detectors continue to run independently.
- Recovered scanned-document recognition on a class of scanned files that were previously slipping through certified as clean — a scanned document can never be confirmed unmodified, so this class now correctly returns the not-certifiable ceiling rather than an intact verdict.
v2.25.1
- Reduced false positives in our generator-origin check on a class of legitimate institutional documents produced by a newer generation of an established generator.
v2.25.0
- New detection class for documents that misrepresent which tool produced them — flagging origin that was rewritten to disguise where the document actually came from.
- Broadened generator-identity-forgery detection to a further class of documents whose stated origin contradicts the rest of the document.
- Reduced false positives on a class of legitimate institutional documents that embed a company logo.
v2.24.2
- Reduced false positives in our metadata-consistency analysis on a class of legitimate institutional documents whose records differ purely as a generation-time artifact.
- Reduced false positives in our template-assembly detection on a class of legitimately print-rendered documents that were previously misread as a pieced-together template.
v2.24.1
- Reduced false positives in our design-tool / template-assembly detection on a class of legitimate modern documents that were previously being mistaken for pieced-together templates.
- Refined how the page-assembly analysis reads the document so a legitimate modern layout is no longer misread as reused template scaffolding.
v2.24.0
- New detection class for documents showing that an embedded component was quietly stripped out while the document was reassembled.
- Hardened structural-integrity checks to flag traces left behind when a document is rebuilt from an original, without relying on any single tool fingerprint.
v2.23.3
- Recovered tamper detection on a class of edited institutional documents — including documents altered well after their original issue date — that previously slipped through.
- Reduced false positives on legitimate enterprise report outputs, whose normal generation-time characteristics were previously mistaken for post-export tampering.
v2.23.2
- Reduced false positives on a class of legitimate documents that were previously mistaken for tampered files.
- Hardened analysis so a class of legitimate files is no longer misread as tampered.
- Broadened the class of re-rendered documents that can no longer be certified as unmodified — the integrity ceiling now matches our existing rule for other re-rendered document classes.
v2.23.1
- Withheld the integrity guarantee on a class of programmatically-rendered documents whose origin cannot be corroborated — aligns the verdict ceiling with the same rule already applied to other re-rendered document classes.
- Brought the algorithm into line with our previously-documented stance that this family of rendering pipelines cannot ground an integrity guarantee on its own.
- Withheld the integrity guarantee on a further class of programmatically-rendered outputs whose origin cannot be corroborated — characteristic of unattended document-generation scripts rather than first-party institutional pipelines.
v2.23.0
- New detection class for documents rebuilt by a third party but dressed up to look like a genuine institutional export — a disguise used to pass off an altered file as an authentic original. Files in this class are now flagged as modified.
- Hardened this check so a document claiming a high-trust institutional origin is no longer certified on that claim alone. Files whose claimed origin does not hold up are correctly flagged as modified rather than passing as untouched originals.
v2.22.1
- Reduced false positives on a class of legitimate institutional documents that were previously being mistaken for incrementally re-edited files
- Reduced false positives so a class of legitimate institutional documents is no longer treated as post-creation edited
v2.22.0
- New detection class for a font-layer inconsistency characteristic of non-genuine institutional documents
- Hardened the integrity ceiling for a class of re-rendered outputs whose edit history cannot be reconstructed
- Hardened detection against reassembled documents impersonating a trusted origin
- Extended scanner-origin recognition to an additional device variant — recovers correct origin classification for a class of smartphone-scanner outputs
- New detection class for synthetic edit-history patterns inconsistent with any genuine authoring workflow
v2.21.1
- Withheld the integrity guarantee on a class of documents whose authenticity cannot be independently corroborated by our other detection layers.
- Recovered correct origin classification on a class of legitimately-generated documents that the previous heuristic was over-flagging.
v2.21.0
- Added detection for institutional documents re-printed after editing to flatten authoring history — recovered evidence of the underlying edit despite the re-print
- Added a detector for documents whose declared generator contradicts other evidence of how the file was built — characteristic of re-rendering a document that originated in a different pipeline
- Extended font analysis to catch overlay edits that tamper with embedded font identity
- Recovered a structural-consistency check that was previously over-suppressed
- Removed two detector branches that did not produce unique findings — their coverage is preserved by adjacent markers
- Hardened signature-workflow handling so it can no longer conceal a post-signature overlay edit
- Recovered standalone detection of metadata timestamp contradictions that were previously suppressed
- Strengthened detection of deliberately blanked origin records against a case that previously hid the evidence
- Reduced false positives in font analysis for an additional class of legitimate authoring pipelines
- Reduced false positives on enterprise reports generated by institutional reporting pipelines.
v2.19.3
- Reduced false positives on documents from browser-rendered print pipelines
- Reduced false positives on enterprise reports that use several weights of one typeface
- Reduced false positives on enterprise statement composition pipelines that embed pre-rendered design components
v2.19.2
- Hardened detection against documents impersonating a trusted origin
- Hardened detection against attempts to disguise an edited document as an older original
- Refreshed the registry of online editing and conversion services consulted during origin classification
- Reduced false positives on multi-pass enterprise document-assembly pipelines
- Recovered detection on a class of full-rebuild assembly patterns that previously escaped corroboration
v2.19.1
- Recovered tamper detection on documents where original authoring records were deliberately erased post-process
- Broadened metadata-laundering detection to cover a wider family of browser-rendered print pipelines
- Broadened multi-source assembly detection to a wider range of documents
- Hardened detection against editing tools impersonating a trusted scan origin
- Broadened detection of documents flattened from multi-session edits
v2.19.0
- Retired four detection paths whose underlying signals could not be reliably distinguished from legitimate authoring behaviour — keeps the verdict surface honest and removes false-positive risk on bona-fide enterprise documents
- Simplified incomplete-redaction analysis to the single structurally-precise annotation path
v2.18.2
- Improved origin classification of documents produced by online HTML-rendering services and post-creation PDF reprocessing tools — both now resolve to software-origin and cannot certify an unmodified verdict
v2.18.1
- Improved origin classification of documents produced by server-side HTML-layout rendering pipelines — these now fall under software-origin and cannot resolve to an unmodified verdict
v2.18.0
- Added detection of editing history collapsed into a single revision to mask prior modification rounds
- Added detection of programmatically generated pages disguised as a captured scan
- Added detection of annotations layered onto a document that has no genuine origin history
- Improved origin classification accuracy for documents derived from screen-resolution raster sources
v2.17.1
- Improved coverage of editing-tool fingerprint analysis on additional document layouts
- Reduced false positives in embedded image analysis for certain enterprise customer-communications rendering pipelines
v2.17.0
- Added detection of documents presented as a scan whose image content is inconsistent with genuine physical capture
- Reduced false positives on consumer-origin single-page raster documents
- Added detection of documents rebuilt by consumer print-driver utilities to strip authoring history
- Improved origin classification of consumer virtual print drivers
- Improved scan classification on documents wrapped by programmatic generators in ambiguous cases
v2.16.0
- Improved how embedded media metadata is separated from the document’s own origin metadata
- Reduced false positives on low-information machine-printed labels
- Added detection of interactive-form documents whose stored values do not match what the page displays
- Added detection of forms flattened after being filled in
- Added detection of content appended after the document’s normal end
- Reduced false positives on browser print-to-PDF pipelines
- Reduced false positives on genuine machine-generated documents whose normal output was misread as appended content
- Further reduced false positives in metadata-consistency analysis on server-rendered enterprise reports
v2.15.1
- Reduced false positives in metadata-consistency analysis on server-rendered enterprise reports
- Broadened metadata-tampering detection to cover an additional class of self-written rewriter scripts
- Reduced false positives on vector-rendered institutional statements
v2.15.0
- Added a cross-layer metadata consistency check
- Improved precision of font analysis to reduce false positives on legitimate embedded fonts
- Reduced false positives on documents produced by certain markup-flattening tools
v2.14.0
- Expanded multi-source assembly detection across additional structural layers
- Reduced false positives on enterprise document-composition platforms
- Strengthened synthetic-scan detection against an additional class of forgeries
- Added detection of inconsistent tool-origin declarations in document metadata
- Added detection of additional anti-forensic post-processing
- Added detection of additional desktop-tool tampering patterns
- Added detection of further fraud-kit metadata fingerprints
- Added additional cross-layer consistency checks
v2.13.25
- Tightened verdict semantics for additional editor-workflow patterns
- Reduced false positives on certain native-export authoring tools
- Improved origin classification for documents touched by a commercial desktop PDF editor
- Strengthened synthetic-scan detection
- Reduced false positives on additional open-source library variants
v2.13.24
- Improved metadata-date parsing for documents from certain diagram-authoring tools
- Improved reliability of metadata extraction for documents from certain image-pipeline tools
- Expanded font analysis to catch additional editor field-replacement patterns
v2.13.23
- Added new detections targeting additional classes of post-creation content modification
- Strengthened cross-layer metadata analysis
- Improved multi-source assembly detection
- Reduced false positives in cross-layer metadata analysis on documents from enterprise variable-data publishing platforms
- Reduced false positives in metadata-consistency analysis on outputs from certain enterprise form-rendering pipelines
- Detection extended to documents that have passed through online PDF editing and conversion services
- Reduced false positives on genuine signed documents whose updates are part of the signing process
- Detection extended to programmatic PDF processing libraries
- Reduced false positives in cross-layer metadata analysis on documents containing branded design assets
- Added detection of additional multi-source page assembly patterns
v2.13.22
- Improved accuracy of page-content analysis on documents whose content lives in compressed streams
- Reduced false positives on legitimate low-text documents
- Reduced false positives on consumer browser-print outputs
v2.13.21
- Improved accuracy of page-content analysis on documents using nested layouts
v2.13.20
- Added detection of an additional template-field substitution forgery pattern
v2.13.19
- Added detection of an additional synthetic-raster substitution pattern
- Reduced false positives in mixed-origin page-assembly analysis on additional rendering pipelines
- Consolidated overlapping findings to report the most specific one
- Reduced false positives in font analysis on additional rendering pipelines
- Improved multi-source assembly detection to cover a previously-undetected pattern
- Extended generator-origin coverage to additional programmatic page-assembly libraries
v2.13.18
- Added detection of additional metadata-tampering tool markers
- Added detection of additional post-processing tool artifacts
- Added detection of script-injection patterns on top of re-emitted documents
- Reduced false positives in structural page-content analysis on large exports from certain rendering pipelines
- Reduced false positives in cross-layer date analysis
- Reduced false positives on legitimate low-text documents
- Reduced false positives on documents using multi-byte font encodings
- Refined verdict semantics for documents whose state cannot be authenticated structurally
v2.13.17
- Reduced false positives in structural page-content analysis on documents containing embedded native-format data streams
- Reduced false positives on documents from enterprise variable-data composition platforms
- Reduced false positives in metadata-consistency analysis on documents from enterprise document-processing pipelines
- Reduced false positives on documents carrying legitimate fill-and-sign markings from browser-rendered base documents
v2.13.16
- Reduced false positives in multi-source page assembly detection on documents from certain rendering pipelines
- Reduced false positives on documents containing decorative background fills
- Reduced false positives in font analysis for server-rendered enterprise reports
- Improved accuracy of signature analysis across reader-specific save patterns
- Improved accuracy of structural page-content analysis on documents containing non-page-content data streams
- Improved accuracy of hidden-content analysis for documents from certain browser-rendered environments
- Improved origin classification for documents from additional online form-editing platforms
v2.13.15
- Refined verdict semantics for a class of documents whose structural origin cannot establish institutional authenticity on its own — the API response now includes actionable guidance to verify such documents with the issuing organisation
v2.13.14
- Reduced false positives on documents processed through multi-party digital signing workflows
- Reduced false positives in multi-source page assembly detection for certain office productivity output
- Reduced false positives on certain office productivity output
v2.13.13
- Reduced false positives on documents produced by standard print-stream-to-PDF pipelines
- Reduced false positives for documents produced by an additional widely-used office suite whose normal library behaviour was previously misidentified
v2.13.12
- Expanded recognition of tools used for document re-processing
- Improved generator-origin mismatch detection
- Added a metadata consistency check across the document’s origin records
- Reduced false positives in scan classification for certain programmatic certificate and report generators
- Expanded detection to cover an additional family of PDF editing tools — documents edited by tools in this family are now correctly identified as modified
v2.13.11
- Expanded detection of document assembly patterns — additional structural markers are now identified when pages within a single document appear to originate from independent source files
- Expanded detection of manipulation techniques used to alter document meaning without changing its visible appearance
- Added detection for incomplete redaction — documents where content marked for removal remains present and recoverable in the file structure are now identified
- Expanded structural consistency checks to cover additional page-level properties that can indicate post-creation document assembly
- Added detection of internal timestamp inconsistencies
v2.13.10
- Improved separation of embedded-image metadata from the document’s own metadata — preventing spurious inconsistency markers
- Expanded recognition of hardware scanner devices — documents produced by an additional family of multifunction printer units are now correctly classified as inconclusive rather than intact
- Improved structural classification of scanner output that has been lightly post-processed — these are now correctly classified as inconclusive
v2.13.9
- Expanded recognition of hardware scanner and multifunction printer devices — documents produced by an additional family of office scanners are now correctly classified as inconclusive
- Improved structural scan detection across a broader range of scanner firmware variants
- Improved handling of web-optimised (linearized) PDFs — reducing false positives for documents optimised for fast web delivery
v2.13.8
- Reduced false positives for documents created with certain web-based design tools whose automated export pipeline is now recognised, so they no longer incorrectly signal post-creation modification when no other evidence is present
- Reduced false positives on a class of programmatically generated documents whose normal output was misread as evidence of post-creation editing
- Improved robustness of browser-origin rendering detection on certain page layouts
- Added recognition of an additional online document workflow platform — documents exported by its automated HTML-to-PDF pipeline are now correctly classified as inconclusive rather than modified, since no structural integrity guarantees apply to browser-rendered output
- Improved metadata consistency handling for documents whose titles or author names contain non-ASCII characters — eliminates a class of false positives for internationalized documents
v2.13.7
- Reduced false positives in metadata-consistency analysis on documents generated by enterprise reporting frameworks
- Extended the above fix to additional members of the same document generation library family across different programming languages and forks
- Reduced false positives in metadata consistency checks for known generator artifacts
- Improved coverage of structural page-content analysis on documents with multi-stream content
- Extended detection of documents rebuilt from prior templates
v2.13.6
- Significantly expanded recognition of design, publishing, and editing tools — documents created with a broader range of non-institutional applications now correctly return inconclusive instead of intact
- Added detection for additional online document editing tools
- Improved self-check sampling to exclude documents already classified as inconclusive, reducing false discrepancy reports
v2.13.5
- Improved detection of documents assembled from pages of different origins — more cases are now correctly identified as modified
- Improved detection of documents pieced together from images that do not share a common origin
- Improved detection of documents rebuilt from scratch by editing tools
v2.13.4
- Improved classification of documents that appear to be scanned images of physical pages — these now consistently return inconclusive regardless of the declared software origin
- Improved recognition of additional scanner device types
- Improved detection of documents with evidence of post-creation text editing
- Improved detection of documents where identifying metadata has been replaced
v2.13.3
- Refined verdict semantics for documents that lack a sufficient temporal baseline for authenticity analysis
- Fixed false positives for documents generated by server-side browser automation — these were incorrectly classified as consumer software
- Improved detection of additional metadata-tampering patterns
- Improved detection of selectively-edited tool-identity fields
v2.13.2
- Reduced false positives in structural page-content analysis on documents containing binary data streams
- Reduced false positives in structural page-content analysis on a class of legitimate documents
- Reduced false positives in metadata analysis on documents using non-standard string encoding
- Reduced false positives for documents generated by enterprise print pipelines with non-standard file framing
v2.13.1
- Reduced false positives in structural page-content analysis on documents with embedded fonts
v2.13.0
- Added structural detection of scanned documents
- Added detection of hidden text layers associated with OCR processing
- Added detection of content edited in a document editor after initial generation
- Added detection of byte-level structural manipulation in document files
- Added detection of post-modification inconsistencies in optimized document structure
v2.12.0
- Added detection of binary image substitution in scanned documents
v2.11.9
- Improved detection of documents rendered by a browser print pipeline
- Improved parsing of non-standard date formats in document metadata
v2.11.8
- Improved tool identity checks
v2.11.7
- Expanded online converter recognition
v2.11.6
- Improved detection of inconsistencies between metadata layers
v2.11.5
- Reduced false positives for documents with incomplete metadata
- API is now available at the dedicated subdomain api.htpbe.tech/v1
- The previous base URL (htpbe.tech/api/v1) continues to work — no migration required
v2.11.4
- Expanded consumer software recognition
v2.11.3
- Print-to-PDF documents are now correctly classified as consumer software origin
v2.11.2
- Reduced false positives on a class of legitimate generators whose recorded timestamps differ only as a normal generation-time artifact
v2.11.1
- Expanded the list of office software recognized as consumer origin — previously unrecognized editors now correctly return inconclusive instead of intact
v2.11.0
- Added detection of structurally impossible metadata dates
- Added detection of minimal edits consistent with metadata-only tampering
- Improved detection reliability for modern PDF formats (PDF 1.5+)
- Improved detection of digitally signed documents with long-term validation data
- Reduced false positives on legitimately signed documents
- Encrypted PDFs now return a clear error instead of an unreliable result
- Previously analyzed files may benefit from re-analysis
v2.10.0
- Fixed misclassification of several server-side PDF generation tools as consumer software — documents generated by institutional automation pipelines were incorrectly returned as inconclusive
- Improved distinction between browser-based consumer printing and programmatic server-side rendering pipelines that share underlying rendering technology
- Previously analyzed files from affected institutional pipelines may benefit from re-analysis
v2.9.0
- Introduced detection of mixed-origin page assembly based on structural rendering pipeline characteristics detectable at the content stream level
- Documents with pages of confirmed mixed rendering origin are now flagged as modified when corroborated by additional structural evidence
- Previously analyzed files may benefit from re-analysis
v2.8.0
- Added detection of an additional anti-forensic rasterization pattern used to destroy text extractability while preserving visual appearance
- Previously analyzed files may benefit from re-analysis
v2.7.0
- Added detection of an additional mixed-origin page-assembly forgery pattern
- False-positive guards prevent flagging of legitimate scanned annexes
- Previously analyzed files may benefit from re-analysis
v2.6.1
- Improved scan classification reliability — fixed a false-negative where certain compressed image streams could cause scanned PDFs to be misclassified as institutional instead of inconclusive.
v2.6.0
- Introduced detection of documents assembled from pages rendered in independent sessions
- Previously analyzed files may benefit from re-analysis
v2.5.3
- Reduced false positives for documents using the ISO 32000-1 fast-web-view format
v2.5.2
- Reduced false positives in design-tool forgery detection for documents from certain office productivity software
v2.5.1
- Fixed two parsing issues in assembled-document detection that caused certain multi-page documents to pass as intact
- Previously analyzed assembled documents may benefit from re-analysis
v2.5.0
- Fixed a parsing gap that caused certain non-standard PDF files to bypass stream-based analysis
- Added detection of an additional PDF editing tool that previously evaded fingerprinting
- Introduced detection of documents assembled from multiple independently imported pages
- Previously analyzed files may benefit from re-analysis
v2.4.0–2.4.2
- Fixed false "scanned document" classification for modern PDF formats (PDF 1.5+)
- Removed false-positive alpha-channel detection — PDFs with images using transparency are no longer incorrectly flagged
- Closed a detection gap where signature-removal could go undetected in certain re-emitted documents
- Expanded consumer-software origin recognition to include common image and design editors
- Previously analyzed files may benefit from re-analysis
v2.3.0
- Improved analysis consistency: all detection signals are now evaluated uniformly without special-case exceptions
- Structural anomalies are now included in the analysis output
- Reduced false positives for PDFs generated with certain metadata-only workflows
- Previously analyzed files may benefit from re-analysis
v2.2.1
- Fixed detection reliability for PDFs using modern compressed object streams (PDF 1.5+)
- Resolved edge cases in content stream parsing and font subset analysis
- Previously analyzed files may benefit from re-analysis
v2.2.0
- Introduced detection of template-assembly document forgeries
- Expanded coverage to identify composites built from design-tool templates
- Previously analyzed files may benefit from re-analysis
v2.1.7–2.1.8
- Improved detection accuracy: fixed rare false negatives where a real modification marker was missed
- Improved post-signature tampering detection using cryptographic verification
- Fixed false positives for PDFs with an invalid creation date that was still present in metadata
v2.1.6
- Added "Cannot Determine" result for PDFs created with consumer office and word-processing software
- New origin detection: API now returns origin.type and origin.software fields
- New primary status field in API: "intact", "modified", or "inconclusive"
- Result page now shows a grey "Cannot Determine" badge and explanation for consumer-software PDFs
v2.1.5
- Improved detection accuracy for documents from certain office productivity software
- Previously analyzed files may benefit from re-analysis
v2.1.2–2.1.4
- Improved detection accuracy for documents from certain word-processing software
- Reduced false positives for common PDF creation tools
- Previously analyzed files may benefit from re-analysis
v2.1.1
- Improved compatibility with modern PDF formats (PDF 1.5+)
- Enhanced verification for digitally signed documents; significantly reduced false positives on legitimately signed PDFs
v2.1.0
- Redesigned the detection engine with a new approach to identifying document modifications
- Improved accuracy by replacing simple metadata comparison with a more robust analysis method
- Introduced detection of known PDF editing tools
- Previously analyzed files may benefit from re-analysis
v2.0.4
- Fixed timezone bug in date display (dates no longer shown in the future)
- Improved UTC timestamp handling for accurate relative time display
v2.0.3
- Fixed false positive bug in PDF modification detection
- Improved accuracy for metadata analysis
v2.0.2
- Added user dashboard with API key management
- Implemented passwordless authentication (Google, GitHub, Magic Links)
- Created billing and subscription management interface
v2.0.1
- Enhanced API infrastructure with monthly quota management
- Improved typography and visual consistency
- Updated documentation for PDF metadata analysis
v2.0.0
- Major platform update — rebuilt application infrastructure
- Migrated to Turso database with Drizzle ORM for improved reliability
- Comprehensive UX improvements across the application
- Enhanced error handling and stability
v1.0.0
- Initial public release
- Core PDF analysis features