PDF Metadata & Edit Traces

How to Tell if a PDF Was Edited — What the Metadata Reveals

For risk, compliance, and underwriting teams checking submitted PDFs

Every PDF carries an invisible data layer: the generating program, the creation and modification dates, the XMP packet, and the xref chain. You cannot see an edit in the rendered document — but it leaves traces in exactly this layer. HTPBE? reads them and answers the one question that matters: was this file changed after it was created?

~3 sec
per document
62 checks
forensic layers
From $15
per month
1,500+
docs / month on Growth
Scope

HTPBE? analyzes the structural and metadata layer of the PDF file — the layer that records every change, including the invisible ones. We do not check the content for truthfulness and we do not replace identity verification; we establish whether this specific file was edited after it was created.

When HTPBE? returns INCONCLUSIVE for a document, it was typically exported from consumer software rather than an institutional system — which is itself a risk signal.

The problem

Modern document fraud is invisible to visual review

A growing class of document fraud opens a genuine PDF, edits a balance, a date, or a beneficiary, and re-saves it. Visually nothing changes — the document passes pixel-level review, layout review, and KYC.

Structural PDF analysis reads the layers rendering engines never expose: revision history, object structure, signature coverage maps. That is where edits leave fingerprints they cannot wipe.

Common tampering patterns

  • Modified balances or totals after export
  • Swapped IBAN or beneficiary on invoices
  • Post-signature edits on contracts
  • Backdated issue and modification dates
  • Fabricated documents from consumer PDF tools

What this looks like

How an edit shows up in the metadata

Three real fraud mechanics we catch at the structural PDF layer.

01

PDF opened in an editor and re-saved

When a finished PDF is opened in an editor and saved, the ModDate updates and the file gains an additional xref table. The document looks unchanged — the metadata layer shows the second write pass.

02

Producer field does not match the claimed origin

A document that is supposed to come from an institutional system suddenly carries Microsoft Excel, an online PDF service, or an image editor in its producer field. That gap between claimed and actual origin is a direct editing signal.

03

XMP packet and Info dictionary contradict each other

Metadata lives in two places inside a PDF — the Info dictionary and the XMP packet. Editing tools often update only one of them. When the dates or producer values disagree between the two, the file was touched after creation.

The analysis

62 checks
structural and metadata signals per file
~3 sec
per document via API
From $15
per month — pays for itself with the first fraud case avoided

Why a metadata viewer is not enough

A metadata viewer shows you the fields — it does not tell you whether their combination proves an edit

Reading the raw values is easy. Interpreting them is the actual work.

A metadata viewer lists the producer, the dates, and the XMP fields — and leaves the judgment to you. HTPBE? interprets the same fields in context: it matches the generating program against known tools, checks the date logic, counts the xref tables and incremental updates, and issues a deterministic verdict — INTACT, MODIFIED, or INCONCLUSIVE, each with named markers. If you only want to see the raw metadata, use the free viewer. If you need a defensible verdict, this is that analysis.

Results in under 3 seconds30 to 1,500+ documents/monthFrom $15/mo

What HTPBE? checks

Detection capabilities

Deterministic structural signals. No probabilistic scores, no model training.

Producer and Creator fingerprint

HTPBE? matches the creating and last-processing program against a database of known PDF tools. An editor or spreadsheet fingerprint on a document that is supposed to come from an institutional system is a clear signal.

CreationDate versus ModDate skew

The ModDate field updates automatically as soon as a PDF is edited. When the modification date lands hours or days after the creation date, that points to a second editing pass.

XMP versus Info dictionary contradiction

When the metadata in the XMP packet does not match the Info dictionary, a tool updated only one of the two layers — a typical pattern after a later edit.

Multiple xref tables

A PDF produced in a single pass contains exactly one xref table. Every additional table means the file was reopened and saved again after the original export.

Incremental-update chain length

PDF editors append changes without overwriting the original bytes. HTPBE? measures the length of this update chain — on a document that should be untouched, even a single update is notable.

Font inconsistencies after an edit

Later text changes often introduce font subsets that do not match the rest of the document. That inconsistency is measurable on the metadata and structural layer.

Share with engineering

Wire this into your intake pipeline in under a day

Two API calls — one POST to submit the PDF, one GET to retrieve the verdict. Forward this page to your engineering team; the full API reference, quotas, and copy-paste examples in cURL, JavaScript, Python, PHP, Go, and Ruby are one click away.

Pricing

Self-serve plans, no sales call

All plans include the same forensic checks. Pick the quota that matches your monthly document volume.

manual

Starter

$15/mo

30 checks/mo

Manual spot-checks and integration testing

most common

Growth

$149/mo

350 checks/mo

Active document processing pipelines

high volume

Pro

$499/mo

1,500 checks/mo

High-volume automation and API integrations

Enterprise (unlimited, on-premise available) see full pricing

API key on signup. Free test environment on every plan. No card required.

Customer Stories

Teams that stopped document fraud

Compliance, finance, and risk teams use HTPBE? to catch manipulated PDFs before they become costly mistakes.

Caught an invoice where the total had been changed by less than a thousand dollars. Without this I would have approved it without a second look.

Sarah M.

AP Manager

United States

We had three applicants in the same week with bank statements that looked completely fine. Two of them were flagged as modified. You simply cannot see this by reading the document — it is in the file structure.

Lars V.

Risk Analyst, Online Lending

Netherlands

Salary slips were coming with altered figures. We identified two problematic files before the placement was finalised.

Priya K.

HR Operations Lead

India

Since we started checking documents this way, we stopped two applications early in the process that would have been very difficult to reverse later.

Julien R.

Fraud Analyst, Fintech

France

Some applicants were sending PDFs that looked authentic but had been edited in ways not visible to the eye. We now ask for checked originals when something is flagged. Already saved us from a few bad decisions.

Marta S.

Compliance Coordinator

Spain

One invoice was caught because there was a mismatch between the document dates and structure. That particular case would have cost us significantly.

Tariq A.

Finance Manager

United Arab Emirates

FAQ

Frequently asked questions

Which metadata fields reveal an edit?

The most telling are the producer and creator fields (which program generated and last processed the file), the CreationDate and ModDate, and the XMP packet. HTPBE? also evaluates structural signals that are not metadata fields at all — the number of xref tables and the length of the incremental-update chain.

What if a forger deletes or resets the metadata?

Missing or conspicuously reset metadata is itself a signal — genuine exports from institutional systems carry a complete, consistent metadata packet. Independently of that, HTPBE? evaluates the structural layer: xref tables and incremental updates remain detectable even when the metadata fields have been tampered with.

How is this different from a metadata viewer?

A viewer shows you the raw field values. HTPBE? interprets them in context, matches the generating program against known tools, and issues a deterministic verdict with named markers. For the raw read-only view, use the free PDF metadata viewer.

What does “inconclusive” mean?

A verdict of inconclusive means the PDF was exported from consumer software — such as Word or Google Docs — rather than an institutional system. That is not an acquittal but a risk signal: for many document types, such an origin is already unusual.

Secure your workflow

Create your account — API key on signup, free test environment on every plan.
From $15/mo. No sales call. Cancel any time.