Verification

Document fraud detection before you commit

CAVRIX examines submitted documents for technical signs of tampering and checks the claims against the issuing source. You get a defensible answer instead of a hunch.

A forged document rarely fails on layout. It fails at the source nobody bothered to check.

Where document fraud actually starts

PDFs edited after issue: amounts, dates and names can be changed with freely available tools. Quotes, contracts, insurance confirmations and invoice attachments are the usual targets.

Forged evidence during onboarding: diplomas, certificates, tax clearance letters and commercial register extracts are often glanced at rather than verified in hiring and supplier processes.

Visual inspection misleads. Judging by layout, seals and typography misses the technical traces entirely, while over reading optical oddities that have perfectly harmless causes.

What CAVRIX checks

Technical file analysis

  • Analysis of the PDF structure and incremental save history, since later edits leave traces inside the file
  • Metadata analysis covering producer, revision states and timestamps
  • Comparison of text, image and font layers to identify inserted elements

Signatures under eIDAS

  • Validation of electronic signatures with a clear distinction between simple, advanced and qualified signatures
  • Checks on certificate chain, validity period and revocation status
  • Assessment of whether the signature covers the full current content or only a state before the last edit

Verification at the source

  • Checks against registers and issuing bodies rather than against the submitted document
  • Insurance confirmations and certificates verified directly with the issuer
  • A documented verification record with source, timestamp and outcome for your file
What you get out of it
Before you commit

Doubts get resolved before a contract, a hire or an approval

Defensible

The result rests on the issuing body, not on image interpretation

Documented

Every step is recorded and can be shown if the case is ever disputed

FAQ

Verification

  • Can you reliably detect tampering from the image itself?

    Only to a limited degree, and we are deliberately conservative here. Techniques such as error level analysis are considered unreliable and produce many misreadings, caused by nothing more than re-saving, scanning or compression. We treat image forensics as an indicator at most, never as standalone proof.

  • So what is the strongest step?

    Almost always verification at the primary source. A register extract is checked against the register, a certificate with the issuing body, an insurance confirmation with the insurer. A perfectly executed forgery is still a forgery the moment the source says something different.

  • Is an electronically signed document not enough on its own?

    It depends on the level. Under eIDAS, simple, advanced and qualified signatures differ substantially in evidentiary weight and in how the signer was identified. A simple signature says very little about identity. We therefore check the level, the certificate chain and whether the signature covers the current content in full.

  • Are we legally required to verify documents technically?

    No. There is no obligation to use software for this. What is relevant are the supply chain security and access control requirements in Sec. 30 (2) no. 4 and no. 9 BSIG, controls A.5.7 and A.5.17 of ISO 27001:2022, the German GoBD rules on process documentation, and Sec. 130 OWiG on management supervisory duties, with fines of up to 1 million euro. Documented verification is one way to meet those expectations.

  • How does this fit our existing processes?

    We attach it where documents already arrive: supplier onboarding, recruitment, contract acceptance, claims intake. Checking is risk based rather than blanket, so the effort goes where real money or liability is at stake. Questions to info@cavrix.de.

Check the document before it becomes the basis of a decision

We look at which documents reach you and where source level verification can be built in with reasonable effort.