A perfect forgery
extracts perfectly.
A retouched document reads without effort: the fields come out clean, the amounts line up, nothing looks wrong on the page. Holofin checks what cannot be seen — the issuer's signature, the totals recomputed from scratch, and what the documents in a file say about each other.
A weak signal decides nothing on its own. What deserves a second look is three of them converging on the same document while every other document in the file checks out.
The problem
"Fake document"
means five different things.
They are not detected the same way, which is why a single check always lets something through. Someone reviewing a document by eye will catch one or two of these; the other three leave nothing to see on the page.
The fabricated document
Created from nothing, often by an online generator. The layout is plausible; it is the identifiers it carries that do not hold up.
Example: an invoice whose IBAN fails its mod-97 check digits and whose VAT number does not validate. Nobody recomputed either one.
The retouched document
A genuine document with exactly one value changed. Everything else on the page is authentic, the issuer's seal included.
Example: a bank statement whose closing balance went from 1,485.51 to 11,485.51 in a consumer PDF editor.
Someone else's document
A genuine document, untouched, whose seal verifies. Only the person is wrong.
Example: a sibling's bank statement, a parent's tax assessment, submitted as the applicant's own.
The expired or superseded document
The document was accurate on the day it was issued. It is not accurate today.
Example: a company registration extract from last year, a tax assessment for a superseded year, a certificate that has since been reissued.
The fictitious or inactive issuer
A company that never existed, or whose registration is no longer active. The document itself is perfectly well formed.
Example: a payslip whose named employer can confirm nothing, because it stopped trading eighteen months ago.
Only the second of these leaves a trace in the file itself. The third leaves no trace anywhere on the page — it is a true document, and nothing short of comparing it to the rest of the case will show it.
Documents controlled
Each kind of document
carries its own proof.
A sealed tax assessment is verified by the signature its issuer put on it. A bank statement is verified by its own totals. A company registration extract is verified by the check digits in its identifiers. The control cannot be the same for all of them, and a tool that applies one generic check to every document is really only checking the ones that happen to suit it.
Bank statement
Opening balance + credits − debits = closing balance. The running balance is recomputed line by line, and duplicated or out-of-order entries are flagged.
Payslip
Gross − deductions = net, recomputed from the lines the document itself prints. The named employer has to be the employer the rest of the case names.
Tax assessment
The most favourable case, when the issuer seals it: the signature is verified first, then every sealed value is compared to the value printed on the page.
Identity document
The machine-readable zone is validated for internal consistency: its own check digits have to agree with the names, dates and document number printed above them.
Company registration extract
Check digits on the registration number, agreement between the identifiers the extract carries, and how old the extract is. A generated forgery usually forgets the check digit.
Invoice
VAT arithmetic recomputed from the net and the rate, mod-97 check digits on the payment IBAN, and the issuing company checked against an official registry.
Steps
From a pile of documents
to signals you can argue with.
Five steps, always the same. Authenticity controls are not a separate pass: they run on the same case as the completeness controls, and they return a single verdict.
Intake and classification
The case arrives over the API, through an upload portal, over SFTP or in a dedicated mailbox. A bundled file is split into separate documents, then each document is recognised for what it is — which is what decides which controls apply to it. The filename plays no part in that decision.
Extraction
Every document returns its fields, each one with the region of the page the value was read from. Without this step there is nothing to recompute and nothing to compare: a fraud inconsistency is observed on values, not on a visual impression of the page.
Controls
The five levels run against the document and against the case: issuer verification, registry verification, recomputed internal consistency, cross-document consistency, file forensics. They are independent of one another, and that independence is exactly what makes it informative when several of them agree.
Signals and risk level
Failed controls become explained signals: what was compared, both values, the page each one came from. They are grouped by document and by level, then turned into a risk level — from a document whose signature verifies to one where several levels converge on the same value.
Decision
Yours. You set what passes unattended, what goes to review and what stops, according to what is at stake on the case. Holofin assembles the evidence; it does not issue the refusal.
The levels stack
No single level
catches everything.
That is why
there are five.
The five controls are independent, and each one is blind to what the others see. A spotless file clears level 01 without raising anything; it is its signature that fails at 02. A genuine, untouched document passes the first four; it is the rest of the case that contradicts it at 05.
On the diagram, each document that is stopped carries the mark of its own defect, and the trail behind it shows every mesh it had already crossed. The tighter the mesh, the more the control proves: the issuer's signature and the registry let almost nothing past them, while an analysis of the file mostly opens a line of enquiry.
So the five levels are not equal. The next section re-orders them, strongest to weakest — and says which one spoke.
Controls
The five levels are not equal.
Here is which ones prove, and which ones indicate.
The framework presents them by scope, from the bytes of a file up to the whole case. In front of an alert that is not the useful question: what matters is the strength of the evidence. So here they are again, re-ordered from the most solid to the most fragile.
A tool that melts these five levels into a single score leaves you with no way of knowing whether the alert came from an invalid signature or from a harmless re-export. We keep them apart, and we say which one spoke.
Verification at the source
ProofThe only control that depends neither on how the document looks nor on the honesty of whoever sent it. Where the issuer has sealed the document, you read the seal: it holds mathematically, not statistically.
- Where a document is cryptographically sealed — a digitally signed PDF, or a signed barcode an issuer prints on the page — the signature is verified against the issuing certificate, and the file is checked for any change made after signing. A seal regenerated by a fraudster fails, because no issuer signed it.
- Every sealed value is then compared to the value printed on the page. That second step is what catches the most frequent case of all: an amount retouched on top of a seal that itself remains perfectly valid. Where an issuer seals a document, you verify the signature rather than the appearance — and then you check that the two agree.
- On identity documents, passports and residence permits, the machine-readable zone is validated for its internal consistency: its check digits have to agree with the names, dates and document number printed above them.
- This is also the level where the issuer's fingerprint is compared: producer software, embedded font subsets, logo position, page geometry. A bank or a payroll system produces its documents the same way every time, and a statement that does not look like that issuer's own output is a signal even when nothing printed on it is wrong.
- Some issuers operate a verification service of their own, where a reference printed on the document can be confirmed directly with them. That confirms the fields the service covers, and no others — which is worth knowing before treating it as a verdict on the whole document.
Verification against official registries
ProofA perfectly consistent document can describe a company that does not exist, has stopped trading, or is run by somebody else. No analysis of the file will tell you that: you have to leave the document and ask the source of record. This is our own ground — in France, enrichment runs on Origami Entreprises, our own registry built from the official sources and refreshed daily: we do not buy that data from a third party, we produce it. Elsewhere the same checks run against the official register for the jurisdiction, through our data partnerships.
- Registration and status: the company registration exists, and it was active on the date the document claims. Legal form, incorporation date, activity, establishments, and the history of events declared to the register.
- Officers and beneficial owners: compared to the names on the identity documents in the case. A signatory who appears nowhere in the register is a discrepancy, not an administrative detail.
- Address check: the registered office and the establishments reconciled against the address printed on the document, allowing for spelling variants.
- VAT number validated and consistent with the registration number the document carries.
- This is the level that catches the fictitious or inactive issuer: a payslip from an employer that no longer exists, an invoice from a supplier that closed eighteen months ago.
Beyond France the same checks run against the official register for the jurisdiction, reached through our data partnerships — company registries, VAT validation and beneficial-owner sources, added per market as you need them. The checks are the fixed part; the source behind them is configurable, so a case file that mixes jurisdictions is verified company by company rather than held to whichever register happens to be connected.
Recomputed internal consistency
StrongThe document has to agree with itself. A fraudster who changes one figure then has to make everything that follows from it agree: the totals, the lines below, the check digits. They rarely do, and never all of it at once.
- Bank statement: opening balance + credits − debits = closing balance. The continuity of the running balance, the ordering of the dates and duplicated entries are checked line by line.
- Payslip: a net that does not follow from the gross and the deductions printed above it is a signal, not a rounding error.
- Identifiers: IBAN check digits (ISO 13616, mod-97), the Luhn algorithm on identifiers that carry a Luhn check, and VAT arithmetic recomputed from the net and the rate. These are calculations, not estimates — a retouched IBAN does not survive the arithmetic.
- Dates and periods: a period that does not match the year the document announces, an extract older than the freshness rule the case applies.
Consistency between the documents in the case
StrongThe only control that catches the fraud in which every document is genuine: somebody else's document. It leaves no trace in the file, no failed calculation and no invalid signature. It gives itself away purely through what the documents say about each other.
- The account holder on the bank statement is the person on the identity document.
- The employer on the payslip is the employer on the employment contract, and the declared salary is the salary the payslips actually show.
- The tax assessment covers the applicant and not another household, and the declared address is the address on the proof of address.
- Every discrepancy is reported with both of the values compared and the document each one came from — not a bare "inconsistency detected".
Analysis of the file itself
The analysis that does not read the document but the way it was built: metadata, revision history, font tables, internal structure, image statistics. Deterministic detectors spread across independent forensic domains. It is the one level that needs no issuer seal, no registry and no second document — so it runs first, and it runs on everything.
It is also the weakest of the five as proof, and that is precisely why the levels are kept apart. A re-scan, a print-to-PDF or a legitimate re-export rewrites the metadata and erases the revision history, and a consumer PDF producer never proved anything about anybody — plenty of honest applicants re-export a statement before sending it. So this level opens a line of enquiry and localises it on the page; it never refuses a case on its own. What it is uniquely good at is reach: it is the only control still available on a document whose issuer seals nothing and whose company appears in no register.
- Content integrity: traces of text overlaid, rewritten or inserted after the document was created — including text laid on top of a masking rectangle, which hides the old value on screen while leaving both of them in the file.
- Typography: a font subset or a letter spacing that changes on the line carrying an amount, while the rest of the page stays homogeneous. Mixed subsets on one line are a fingerprint of text that was typed in a second time.
- Metadata and structure: incremental saves and the revision history they leave behind, the producer and creator chain, an impossible timeline between the creation date and the modification date, hidden layers, multiple content streams, unusual complexity.
- Images and digital signatures: cloned or resampled image regions, a recomposed photograph, a fabricated image, and any modification made after an electronic signature was applied.
Worked example
A lending case
where one figure moved.
Four documents, all genuine but one. On the March bank statement the closing balance went from 1,485.51 to 11,485.51: a single "1" inserted in front. To the eye the page is flawless, and it extracts flawlessly too.
What the document says, and what its own figures say
Whoever did this corrected the closing balance but not the three numbers it follows from — nor the running balances on the lines above it, which stay on the old trajectory. The gap is exactly 10,000.00: the signature of an inserted digit.
The signals, and what each one is worth
The accounting equation does not hold
A calculation, not an estimate. A genuine statement cannot fail this control: the bank produced all three of the numbers it is built from.
The running balance is broken
The balance on the last line does not lead to the closing balance shown. Two independent controls point at the same value.
Different font subset on the balance line
Corroborating: it puts the retouch on the exact line the two previous controls had already called into question.
PDF producer: consumer editor
Worth nothing on its own. Thousands of honest customers re-export their statements. Here it adds a detail of context and no more.
The other three documents check out
The tax assessment's signature is valid and its sealed values match the printed ones, the identity document's machine-readable zone is consistent, and the payslips' net recomputes from the gross. The suspect document is isolated, and that is what makes the report precise.
What a reviewer receives is a named document, a sum to check and a page to open — not an overall score they would then have to interpret.
Decision
Holofin reports and explains.
The decision stays with your teams.
A fraud signal is not an accusation, and an engine has no business drawing the consequences on your behalf. You set the thresholds: what passes unattended, what goes to review, what stops — and those thresholds depend on what is at stake on the case, not on the technology.
Nothing is refused automatically on your behalf
The GDPR regulates decisions based solely on automated processing that produce legal effects concerning a person, or similarly significantly affect them: that is its article 22. Refusing credit or declining a claim falls squarely inside that perimeter. The verdict prepares the decision; it does not take it.
A signal is not a legal finding
Whether a document is a forgery, and what should follow from that, is a matter for a court under whichever law applies where you operate. Calling it is not an engine's job. What we produce is the material evidence: a calculation that fails, a signature that does not verify, two values that contradict each other and the page each one came from.
An ambiguous case is escalated, never filed in silence
A married name against a birth name, a company that has since been renamed, a re-exported document whose metadata was rewritten on the way: these go to review with their reason attached. A control that cannot conclude has to say so, rather than decide in place of the person handling the case.
Every signal is contestable because it is explicit
The level that fired, the values compared, the page they came from. A reviewer who disagrees has to be able to demonstrate it — and a customer who challenges the outcome has to be able to receive an answer other than "the algorithm said so".
What is kept behind every signal
- Level that fired
- issuer, registry, internal consistency, case or file
- Values compared
- both of them, with the document and page of origin
- Seal verification result
- issuing certificate and signature validity
- Control engine version
- hololang 4.2
- Date the controls were frozen
- 2026-10-02
- Decisions and reclassifications
- kept append-only
A case challenged a year later can be re-read with the controls that applied at the time, and every signal traced back to the value and the page that produced it. That is what makes the decision defensible — in front of an auditor as much as in front of the customer.
Integration
The signal arrives
before the case moves on.
A fraud alert is no use at all once the funds have been released. The controls plug in where documents already enter your chain, and the signals go back out into the tool your teams actually work in.
REST API
You post the document or the whole case, you read back the signals. Extracted fields, control results and pages of origin in the same response.
Webhooks
A signal surfaces as soon as a document lands or a value is corrected; you are told without polling in a loop.
SFTP
Batch drop and collect, for chains that already run overnight — including re-checking a back catalogue of cases that were decided before the controls existed.
Document management
Documents go back filed, with the recognised type and the control results attached: the audit trail stays where the documents are archived.
Upload portal
The control runs at the moment of upload. This is the most useful point in the whole chain: an unreadable or inconsistent document can be asked for again before the case is ever opened.
Frequently asked
On document fraud detection
Nearby
Fraud is rarely verified on its own
Process
Case completeness and compliance
The other half of the question: is everything there, is it valid, and does it agree from one document to the next? Both controls run on the same case.
Capability
Dossier Intelligence
The layer that assembles loose documents into a case, which is what makes level 05 possible at all: there is no cross-document check without a case.
Run Holofin on your own cases
Send us a handful of real cases, and above all the frauds you have already identified: it is the only honest way to judge this. We give you the signals back document by document, with the level that spoke — and what we did not see.