A live run, end to end
We take a document through all four layers in real time and read the output line by line — which signal fired, what it measured, and where on the page it sits.
Document forensics · For banks, lenders and insurers
Bank statements, mobile-money confirmations, card slips and invoices — born-digital PDF, forwarded screenshot or a phone photo of paper. The engine runs a multi-signal pipeline over each one — document metadata and AI-edit provenance, image forensics, amount & balance arithmetic, and format checks — and returns a composite score with the exact signals behind it. Not a fraud verdict. A risk screener you can act on.
This pipeline runs inside a client’s perimeter on their own documents, so we show it live on a call rather than as a public sandbox.
Seeing it in action
There is no public upload form on this page. The pipeline lives inside the perimeter of the organisation that deploys it and reads that organisation’s own material — so the honest way to show it is a call: bring the documents your team actually argues about, and we put them through the engine in front of you.
We take a document through all four layers in real time and read the output line by line — which signal fired, what it measured, and where on the page it sits.
Statements, mobile-money receipts, card slips or invoices out of your own flow — including the ones your reviewers disagreed about. Redacted copies work perfectly well.
Where the check sits in your KYC, lending or merchant-onboarding flow, which rule packs your issuers need, and what the human-review escalation looks like.
Risk screener, not a verdict. The output is informational — not proof of fraud. A skilled forgery can still pass, and a genuine document can trip a flag. Anything suspicious is confirmed with the issuing bank or operator on a number you find independently.
Where the documents live. Nothing on this page uploads anything. In a deployment the engine sits inside your own environment: the document, the rasterised page and the forensic overlays stay on your infrastructure under your retention policy, and we do not train models on your material.
How we check
A genuine document passes all four. A naive forgery fails one. A sophisticated forgery might pass everything except the arithmetic — most forgers don’t recompute running balances when they edit a row.
PDFs: Producer / Creator strings, modification-date drift, incremental-update count, digital-signature and XMP editor traces. Images: an EXIF / XMP sweep for editor fingerprints plus the IPTC / C2PA content-credential that on-device AI editors — Apple Clean Up, Google Magic Editor, Samsung Galaxy AI, Adobe Firefly — stamp into any image they touch.
PDF object tree, xref tables, page count, font diversity,
presence of suspicious active content (/JS, /Launch,
/AcroForm) on a document that claims to be a passive statement.
Light qpdf --check pass.
Does the maths add up? Balance roll-forward on statement tables and amount / fee reconciliation on receipts — a high-signal check, since most forgers edit one figure and forget the totals. Plus format checks on transaction-ID shape, currency string, wording, date layout and name casing, with extra rules for known operators (M-Pesa, MTN MoMo, Tigo Pesa, Airtel Money…).
Error Level Analysis, JPEG-ghost double-compression scan, blockwise noise residual consistency. For PDFs, page 1 is first rasterised at 200 dpi so the forensic layer sees what a human eye sees on screen.
Two case studies
We took two genuine documents and forged each one with a different state-of-the-art method, then ran the originals and the fakes through the full pipeline blind. Every verdict below is a composite of dozens of signals across four independent forensic layers. Tap any document to enlarge it — the real and the fake are visually identical.
Two real Bank of Kigali card receipts, shot on a phone. We changed only the amount on one using Apple’s “Clean Up” generative editor — nothing else.
Untouched photo. RWF 6,600, no edits applied.
Decisive signal: a complete iPhone camera fingerprint — lens, exposure, GPS — and no AI-edit provenance. Pixel forensics came back clean.
Amount changed to RWF 6,750 with Apple Clean Up. Visually flawless.
Decisive signal: the file’s own metadata carries an IPTC/C2PA “AI-composited” content credential and an Apple Clean Up tag — it declares that generative AI edited it.
Why it’s hard: a full generative re-render leaves no paste-in seam, so the pixel-forensics layer (ELA, noise) scored the two almost identically. The verdict instead leaned on the metadata-provenance vector — the editor stamped the forgery with the IPTC/C2PA “AI-composited” content credential, while the original kept an intact camera trail.
A genuine Bank of Georgia payment confirmation. We covered the amount with a white box and printed a higher figure on top — the way most PDF forgeries are actually made. (Account, card and document numbers are redacted here for privacy.)
Original PDF, straight from the bank. 304.80 USD.
Decisive signal: a clean text layer — every amount appears exactly once, nothing drawn over anything — with intact metadata and structure.
Amount overlaid with 634.80 USD. Pixel-perfect to the eye.
Decisive signal: the original 304.80 still sits in the text layer, its coordinates overlapping the 634.80 printed on top — the signature of a white-box overlay.
Why it’s hard: the metadata is pristine — same Producer, single-pass save, valid structure — so the metadata vector saw nothing. This time the text-layer geometry vector caught it: the original figure survives in the PDF underneath the patch, its bounding box overlapping the number printed on top. Two different amounts in the same place is something no genuine document contains.
Notice that each forgery defeated a different naive check and was caught by a different specialist. That is the entire point: no single signal is trusted on its own. Every document is scored across four independent layers — metadata & AI-edit provenance, document structure, content & arithmetic plausibility, and pixel-level forensics — and the layers cross-validate one another. Evade one and you almost always trip another.
Defence in depth
The image forgery slipped past pixel forensics but not provenance; the PDF forgery slipped past metadata but not text-layer geometry. Different attacks, different tripwires — that overlap is what makes the composite hard to beat.
Explainable, not a black box
Every verdict ships with the exact signals behind it — which layer fired, what it measured, the coordinates and metrics. You audit the reasoning, not just a number, which is what makes it defensible in a lending or KYC decision.
Honest about limits
A determined forger who scrubs metadata and rebuilds a PDF from scratch can still beat any screener. That is precisely why the output is a calibrated risk score and “confirm with the issuer” is always the last word.
Genuine documents we forged ourselves for this demonstration. Personal data was redacted and image metadata stripped before publishing; the scores and signals shown are exactly what the live pipeline returned when each file was submitted blind.
If in doubt — do this
Whether it’s a mobile-money screenshot, a card slip, a paper receipt or a bank PDF, the same four habits catch the overwhelming majority of forgeries. None of them need software.
Don’t just read the headline amount — check it against everything else on the page. On a statement, each running balance must equal the one above it plus or minus that line. On a receipt, amount + fee should land on the new balance. Forgers almost always change one figure and forget the totals downstream — that mismatch is the single most reliable tell you can spot by eye.
Every issuer uses a fixed shape for its codes — length, case,
character set, sometimes a date prefix. M-Pesa is 10 uppercase
characters like TFK6XAQ8MN;
a card slip carries RRN /
STAN /
AUTH fields. A code in the
wrong case, the wrong length, or one that’s identical across
two supposedly different payments is a red flag.
A screenshot or photo can be edited; the original can’t be
re-issued by the sender. Ask for the original SMS from the
operator’s alpha-sender ID (for M-Pesa that’s
MPESA, never a phone number),
the in-app transaction detail, or a statement downloaded fresh
from the bank’s own portal — then cross-check against your own
SIM’s message log or merchant dashboard. Only the receiving
side can truly confirm that money landed.
If a photo looks edited, ask the sender to retake it — a different angle, the desk or their hand in frame, or a short video panning across the document. Edits and paste-ins rarely survive a second capture: lighting, perspective and reflections won’t line up the same way twice, whereas a genuine document reproduces perfectly. It costs the sender ten seconds and is very hard to fake on demand.
Why it matters
Independent figures from regulators, central banks and consumer watchdogs. Document-level fraud sits at the centre of nearly all mobile-money and lender-onboarding scams.
TSh 5.3B
Reported losses across 4,091 incidents — a 9.6% YoY increase and a 33% surge in attempts Dec 2024–Mar 2025.
Source: The Citizen / Tanzania Communications Regulatory Authority
₦52.26B
Annual fraud losses across Nigerian banking — up 196% over five years, much of it on digital rails.
Source: NIBSS / Businessday 2025
11,000+
FCCPC complaints from 2021–2023 alone. Many turn on forged "statement" screenshots used to qualify victims.
Source: FCCPC / AInvest 2025
33B
Single-year transaction volume across 66.2M Safaricom M-Pesa customers — the scale of the screenshot fraud surface.
Source: Safaricom FY2024 Investor Brief
36%
10M+ adults — the lender-acquisition incentive that drives statement forgery in B2C lending.
Source: NCR Annual Report 2024/25
8,255
Of which banking 3,173 and fintech 1,442 — and ₦10B recovered for consumers.
Source: FCCPC 2024
Coverage
The universal layers — metadata, AI-edit provenance, image forensics and amount / balance arithmetic — work on any document, photographed or digital, regardless of issuer. On top of that, format-specific rules add extra checks for the dominant mobile-money rails and the major commercial banks across Nigeria, Kenya, Tanzania and South Africa.
Questions we get
It runs four independent layers on every document, whatever the type. (1) Metadata: PDF Producer/Creator strings, modification date, incremental-update count, digital-signature presence; on images, EXIF/XMP editor fingerprints (Photoshop, Snapseed, Picsart, GIMP, Lightroom) and — importantly — IPTC/C2PA AI-edit provenance written by on-device generative editors such as Apple Clean Up, Google Magic Editor, Samsung Galaxy AI and Adobe Firefly. (2) Structural consistency: PDF object tree, page count, suspicious active content. (3) Content plausibility: balance roll-forward and amount/fee arithmetic, plus format / currency / transaction-ID / wording / casing checks — with extra rules for known operators like M-Pesa, MTN MoMo, Tigo Pesa and Airtel Money. (4) Image forensics: Error Level Analysis, JPEG-ghost map, noise residual consistency. The four scales are aggregated into a composite authenticity score from 0 to 100.
No — and no public tool can, for any operator or bank. There is no open API to verify someone else's transaction. What we do check is whether the document follows the expected format (code shape, currency string, wording, date layout) and whether its own metadata or arithmetic betrays an edit. For mobile money this means checking the canonical wording and transaction-ID format (e.g. M-Pesa's 10-character uppercase code); for a card slip, the structure of the RRN / STAN / AUTH fields. Strong signals against naive edits — but never a substitute for confirming with the issuer.
PDF, JPEG and PNG. Statements are best as the original PDF the bank emitted, since the engine reads structural metadata directly. Receipts — mobile-money, card/POS or paper — work either as a forwarded screenshot or a phone photo. Plain photos that are not financial documents are short-circuited and handed off to the Fake Image Detector, which is the right tool for them.
No. This pipeline runs inside a client's perimeter on their own documents, so we show it live on a call rather than as a public sandbox. Write to am@appcraft.pro and we will walk through it on your own material.
Nothing is sent anywhere from this page — it holds no upload path at all. In a deployment the engine sits inside your own environment: the document, the rasterised page and the forensic overlays stay on your infrastructure under your own retention policy, and we do not train models on your material.
It is an informational risk screener, not a fraud verdict. The balance roll-forward check catches naive edits, where a figure is changed and the totals downstream are left alone; the metadata layer catches consumer-PDF-editor re-saves and on-device AI edits that stamp their own provenance; image forensics catch obvious paste-ins. A sophisticated forger who edits the source PDF, recomputes the balances and re-emits through a real PDF pipeline can defeat the screener. Always confirm a suspicious document with the issuing bank or operator before acting.
Production deployment
On-prem, in your VPC, or as a managed REST/gRPC API behind your own ingress. Batched throughput, custom rule packs per issuer and country, human-review escalation hooks. We help banks, lenders, insurers and B2B marketplaces cut manual document review by 60–80%.