logologo
  • How it works
  • Why It Matters
  • Statistics
  • Pricing
  • FAQ
  • API
logologo
  • How it works
  • Why It Matters
  • Statistics
  • Pricing
  • FAQ
  • API
HTPBE?

Structural PDF tamper detection API. Catches edits your KYC stack misses.

Product

  • How It Works
  • Use Cases
  • Metadata Viewer
  • Pricing

Developers

  • API Reference
  • GitHub/docs
  • Changelogv2.44.3

Resources

  • About
  • Blog
  • Comparisons
  • Legal & Imprint

ยฉ 2024โ€“2026 TMI Iurii Rogulia ยท VAT ID: FI29845875 ยท Made in Finland ๐Ÿ‡ซ๐Ÿ‡ฎ

Status

Algorithm v2.44.3

Back to FAQ
FAQ

What is a credit, and how many credits does one check cost?

A credit is the unit HTPBE? bills in. Right now the rate is fixed: one check costs one credit, whether the check runs from the web app or the API.

Credits exist because web uploads and API calls draw from a single shared balance instead of two separate quotas. That balance can come from three places: a monthly subscription allowance, a one-time credit pack, or the 5 free credits every new account gets on signup. All three land in the same pool and spend in that order — subscription balance first, since it resets each billing period, then packs, then welcome credits, held back as a reserve.

Credits don’t expire while your account stays active; they’re only forfeited after 12 months with no login, upload, or API call. Test API keys are free and unlimited and never draw from your balance — use them to integrate before you spend a real credit.

โ† Previous

Do you offer test API keys?

Next โ†’

Can I check bank statements submitted by loan applicants?

Related questions

Keep reading

3 answers

Verifying Specific DocumentsReading Your Results

Verifying Specific Documents

Can I check bank statements submitted by loan applicants?

Yes — this is the primary use case for lending teams. HTPBE? detects edited bank statements at the file structure level: multiple xref tables indicating post-export editing, producer field showing Excel or a consumer PDF tool instead of a banking system, and modification timestamps that differ from creation timestamps.

See the fake bank statement detection guide for integration details.

Why would I need to check payment confirmations and receipts?

Payment confirmation fraud is a real problem in online transactions. When someone sends you a PDF screenshot or receipt as “proof of payment”, it could have been digitally edited to fake the transaction details.

Common fraud scenarios:

  • Marketplace sellers: A buyer sends a fake payment confirmation to receive goods before actually paying
  • Freelancers: A client shows an edited bank transfer screenshot claiming payment was sent
  • Rental/accommodation: A tenant provides a modified payment receipt to avoid actual payment
  • Online businesses: Customers submit altered invoices or receipts to claim refunds or discounts
  • Peer-to-peer transactions: Someone shows fake payment proof to receive goods or services

How HTPBE? helps: By checking if the PDF has been modified, you can quickly identify suspicious payment confirmations. If a payment screenshot shows as “modified” in our analysis, it’s a red flag that the document may have been tampered with.

Important: Always check payment through your actual bank account or payment platform. HTPBE? is an additional fraud-detection tool, not a replacement for checking your real account balance.

Reading Your Results

Why does my official document show INCONCLUSIVE?

If your document was issued by a real institution — a state register, a court, a bank, a payroll system — and HTPBE? returns INCONCLUSIVE instead of INTACT, that does not mean the document is forged. It means HTPBE? cannot structurally prove that the file was not modified after creation. The document may well be genuine; the verdict reflects the limits of structural analysis, not the document itself.

Why a clean file can still be inconclusive

HTPBE? promises only one thing: detect post-creation modification of the PDF file. To say INTACT we need positive evidence that the file is structurally indistinguishable from the moment it was generated. That evidence does not exist when the document was produced by a tool that anyone can install or use:

  • HTML-to-PDF renderers — wkhtmltopdf, Chrome / Chromium print-to-PDF (Skia/PDF), Headless Chrome, Puppeteer, Playwright, WeasyPrint, Prince. A government registry that serves PDFs through wkhtmltopdf produces output that is byte-for-byte reproducible by anyone with the same template and the same wkhtmltopdf build.
  • Consumer office software — Microsoft Word, LibreOffice, Pages, Google Docs “Download as PDF”, generic print-to-PDF drivers. The same software that an institution might use is freely available to a forger.
  • Online PDF editors and converters — iLovePDF, Smallpdf, PDF24, ILovePDF, Sejda. These services strip original metadata as part of their normal pipeline, so the provenance of any document that passed through them is gone.
  • Scanned images — a PDF that contains only raster pages (photos or scans) and no selectable text. Anyone can print a document, alter the printout, and re-scan it. The scanner has no way to record “this is the original physical paper that left the issuer’s office.”
  • Filled-in PDF forms — Acrobat’s “Fill & Sign”, online form fillers. Filling a form is a legitimate edit, but at the file level it is indistinguishable from a malicious edit, so we do not call the result intact.
  • Unverifiable metadata — the producer or creator field is missing, blank, or stripped, leaving nothing for the engine to compare against known institutional patterns.

In every category the same logic applies: the production tool is public, the output is reproducible, and there is no cryptographic anchor (a digital signature, an issuer’s certificate) that ties the file to a specific source. We refuse to call that file INTACT because doing so would let forgers run the same public tool and inherit a green check.

What you should do with an inconclusive verdict

  • Get the document from the source. If it is a state-register extract, download it yourself directly from the registry. If it is a bank statement, log in to the bank and re-download the original. A copy received from a third party is the part of the chain you cannot trust; replacing it with a fresh copy from the issuer eliminates the question.
  • Look for a digital signature. Many institutional PDFs (court filings, EU eIDAS-compliant invoices, tax filings) carry a cryptographic signature from the issuer. If the signature is present and validates, that is far stronger evidence of authenticity than any structural analysis.
  • Use the issuer’s official verification API or portal when one exists. Government registers, eInvoicing networks, and academic credentialing bodies often expose a query interface that returns the canonical record by document number.
  • Check the visible content yourself. Compare names, dates, amounts, registration numbers against your own records or a trusted directory. HTPBE? does not read content — it cannot tell you whether the values printed on the page are the values the issuer originally produced.

What HTPBE? does well, and where it stops

HTPBE? is built to catch the most common attack: a contractor or counterparty receives a legitimate institutional document, opens it in an editor, changes a number or a name, and forwards the modified file. That category leaves structural fingerprints — multiple xref tables, mismatched generator strings, font-subset divergence, signature-coverage gaps — and HTPBE? is designed to surface them as MODIFIED.

What HTPBE? cannot do is verify fabricated-from-scratch documents. A forger who builds a counterfeit registry extract from scratch in wkhtmltopdf produces a structurally clean file. That is exactly the case we mark INCONCLUSIVE rather than INTACT: structural cleanliness is not authenticity, and we will not pretend otherwise.

For details on the categories themselves, see Can someone create a fake document from scratch? and How HTPBE? determines whether a PDF was modified.

Secure your workflow

Create your account โ€” check PDFs on the web or with an API key, both ready on signup.
From $15/mo. No sales call. Cancel any time.

Start Free โ€” Close the Structural Fraud GapSee Pricing
Read API Docs โ†’