Home // FORENSIC UNITS // DIGITAL EVIDENCE

Digital Questioned Document Examination

Every file carries its own history: metadata, layers, versions and dates. The examination reads what the document shows and what it tries to hide.

The first question of the examination

Was this document born as a file or born on paper?

Before any analysis, the examination answers the question that defines the whole method: is the file born-digital, created and completed on a computer without ever existing on paper, or is it the scan of a physical document? Confusing the two natures is one of the most common errors in the field: "examining the PDF" when what is actually under examination is the image of a sheet of paper nobody has seen.

In a born-digital document, the file itself is the document, and its internal structure holds the whole story. In a scanned one, the file is merely the portrait: the graphic content (signature, text, layout) calls for the method of classical forensic handwriting and questioned document examination, while the examination of the file establishes when and how the portrait was produced, and whether it was edited afterwards.

Born-digital or scanned: the same document, two natures of examination
Born-digitalThe file is the document: metadata, fonts, layers and electronic signatures tell the story from the inside
ScannedThe file is a portrait of the document: the examination establishes whether the portrait is faithful and whether it was staged or edited
HybridPaper signed, scanned and then signed electronically again: each stage receives the examination appropriate to it
Common errorTreating the image of a sheet of paper as though it were a born-digital document, and concluding more than the copy allows
ConsequenceA report vulnerable to challenge: the nature of the file delimits what the examination can and cannot assert
The right methodTriage of the file's nature before any conclusion, with the limits stated in the report itself

Digital questioned document examination is a discipline unique to VALLIM Perícias: the bridge between the Doc Lab and the Data Lab.

From paper to pixel: examining the document that was born a file
What is examined

The scope of the examination, item by item

Metadata

Metadata and internal structure

Far beyond the "File properties" panel: the Info dictionary (/Author, /Producer, /CreationDate, /ModDate), XMP metadata and the consistency between the declared authoring software and the actual structure of the objects. When the label and the content do not match, there is a story to uncover.

Fonts

Embedded fonts and anachronisms

A PDF carries the fonts it uses. A typeface released after the document's declared date is a digital anachronism: the file's equivalent of ink that did not yet exist at the time of the paper.

Hash

Integrity through hashing

A hash is the cryptographic fingerprint of the file: any later change, of a single bit, produces a different hash. Recorded on receipt, it demonstrates that the object examined is exactly the one delivered.

Timing

Timeliness

Did the document exist on the date it declares? Time stamps, filing records, e-mail trails and cloud version histories make it possible to test the alleged date against the traces left in the systems the file passed through.

AI

Documents generated or retouched by AI

Synthetic receipts, certificates and contracts: generation artefacts, typographic and layout inconsistencies, and comparison against the issuer's legitimate template. The fraud has become easier to produce, and it still leaves traces.

Custody

Digital chain of custody

How the file reaches the examination matters as much as the examination itself: receipt of the original (never a "screenshot of the PDF"), a hash recorded at first contact, and documented preservation and mirroring through to the report.

The technical gem of this practice

Incremental editing: earlier versions are still inside the PDF

In the Middle Ages, parchments were scraped clean and written over; under the right light, the old text reappears beneath the new. That is the palimpsest. A PDF can behave in exactly the same way: when saved by appending (what is called incremental editing), the file does not erase what was there, it merely writes over it, keeping the earlier versions inside itself.

Structural examination identifies the traces of that process (multiple cross-reference tables, overwritten objects) and reconstructs the file's internal timeline: what was there before, what was added and in what order. An altered figure, an interpolated clause or a signature inserted later may be recorded inside the very document that hides them.

Not every PDF keeps those layers: a full save discards them. That is why the chain of custody is decisive: every conversion and every forward can destroy the layer that would decide the case.

Multiple xrefMore than one cross-reference table and more than one startxref: the mark of a file saved by appending
Old objectsOverwritten content that remains in the body of the file, often recoverable in full
OrderThe sequence of the additions: what came in first, what came in later and over what
TimelineThe internal history of the document, reconstructed and illustrated in the report in a verifiable way
Screenshots and conversations

The screenshot is not the conversation

WhatsApp and other app conversations reach the case file in three forms, and they are not worth the same. The evidential hierarchy is stated in the report:

Screen captureAn image, editable like any other: on its own, it is the most fragile rung of conversation evidence
ExportThe history exported by the app itself: more consistent, yet generated outside any forensic procedure
Forensic extractionThe conversation extracted from the source device, with metadata, hash and chain of custody: the standard that withstands a challenge
The hierarchy of conversation evidence: from the fragile screenshot to hash-verified forensic extraction

When the conversation is at the centre of the dispute, digital questioned document examination and computer forensics stop being two examinations: here, they are a single piece of work, conducted under one and the same method. See the Computer Forensics practice →

Method

How the examination unfolds

01

Receipt with hashing

The original file is received through the channel advised, and the hash recorded at first contact. From then on, any later alteration is demonstrable.

02

Structural triage

Nature of the document (born-digital or scanned), authoring software, metadata and layers: the map of the file before any specific examination.

03

Specific examinations

As the case requires: incremental editing, font and layout anachronisms, timeliness, comparison against the legitimate template, indications of staging or of AI generation.

04

Reproducible report

Every finding documented so that another expert, following the same steps on the same file, reaches the same result. That is what sustains the evidence in court.

Do not print it. Do not photograph it. Send the file.

Every print, conversion or forward through an app destroys metadata and layers that may decide the case. The questioned document must reach the examination as a file, in its original format, through the channel indicated at the initial consultation.

Get guidance on sending it correctly
Frequently asked questions on this practice
Can a digital document be forged without leaving a trace?
It is far harder than it looks. Edits leave traces in the internal structure of the file, in the metadata, in the embedded fonts and in the trails of the platforms it passed through. The technical challenge is knowing where to look, and that is exactly what the examination does, while also stating what it was not possible to verify.
Can earlier versions of a file be recovered?
In many formats, yes. A PDF saved by appending keeps its earlier versions inside itself (incremental editing), and cloud documents keep a version history. But not every file preserves layers: feasibility is assessed case by case, before any commitment.
Can the software that generated the document be identified?
Frequently, yes. The file declares the generator in fields such as /Producer and /Creator, and the structure of the objects itself carries the "accent" of each piece of software. Where the declared program does not match the actual structure, that discrepancy is in itself a relevant finding.
Can the exact creation date of the file be established?
The dates declared in the metadata can be manipulated, and the report treats them with that reservation. The strength of the conclusion comes from cross-checking: embedded fonts, time stamps, e-mail and cloud trails, internal layers. The degree of certainty reached is always stated.
Can it be established who altered the document?
The file usually points to the machine, account or software involved in the alteration. Tying that to a specific person generally requires correlation with other traces (logs, devices, access trails), work that connects to the Computer Forensics practice.
Does a screenshot of a conversation work as evidence?
A screenshot on its own is fragile: it is an image, editable like any other. What sustains the evidence is extraction of the conversation from the source device, with metadata, hash and chain of custody. Where only the screenshot exists, the examination states what can and what cannot be concluded.
Does digital forensic evidence carry the same weight in court as physical evidence?
Yes. What gives evidence its validity is the method: chain of custody, stated methodology and reproducibility. It is the same rigour as a physical examination, applied to the digital medium.

See also

Electronic Signatures →   Forensic Handwriting and Questioned Document Examination →   Computer Forensics →

Completed cases
ANONYMISED CASE

Dispute over a digital contract signed on the DocuSign platform

Forensic analysis of metadata and logs revealed that the signature had been applied from a device the contracting party had never used.

Does the document also exist on paper?

Pen signatures, inks, printing processes and the physical substrate are examined under Forensic Handwriting and Questioned Document Examination, in the same laboratory and under the same method: both worlds of the document, one technical expert in charge.

See conventional questioned document examination →
Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination