Method

Every check, by name

Every check by name, in plain words. Method v0.1, 2026-09-07. The version is printed on the cover of every exhibit; the same files, the same version and the same edits produce the same exhibit hash.

Proof

Balance identity
Printed opening balance plus every credit minus every debit must equal the printed closing balance, to the cent. On a card statement: previous balance plus charges minus payments and credits equals the new balance.
Running-balance chain
Where the statement prints a balance per line, each printed balance must equal the previous one plus the line. The first row where it does not is shown with the difference.
Month chain per account
The closing balance of one statement must be the opening balance of the next statement of the same account. A day missing between two statements is a gap; a day shared is an overlap; a balance that does not carry over is a break. Each is listed with the two exhibit numbers.
Read in part
When some pages could not be read, the rows read are still proven against the printed balances and the entry says which pages were not read.

Trace

Transfer matching
A debit in one account and a credit in another account of the matter, equal in amount and within two banking days, are paired one to one. Transfer wording and a cited account number rank rival candidates. Both citations are printed.
Unmatched outflows
Debits with transfer or wire wording, or naming another account of the matter, for which no credit of the same amount was found in any account of the matter.
Counterparty totals
Descriptions reduced to a payee label, grouped per statement, largest first, with a sample of the raw description so the grouping can be judged.
Ledger comparison
A QuickBooks, Xero or plain-sheet export is matched line by line with the bank rows of the account it names, within its own date range: bank lines with no ledger entry, ledger entries with no bank line, both cited.
Payment-app links
A transfer to or from the bank in a PayPal, Venmo or Cash App export is linked with a bank row of the matter: the amount the bank sees (net of the app's fee on a payout), the same direction, within three days; an account number named in the export ranks rival candidates. Payouts with no bank line, and bank lines that name the app with no line in the export, are listed. The app's person-to-person lines are grouped by the name or handle as the app printed it, with the app's transaction ids as citations.

Structure of the file

File identity
SHA-256 of the bytes as received, size, page count, PDF version, producer and creator, creation and modification dates, end-of-file markers and incremental saves, fonts, encryption state, text layer per page, image pages with their pixel dimensions, presence of a signature dictionary.
Producer and creator class
Office and design applications, consumer online PDF editors, backend PDF libraries, browser and OS print-to-PDF, PDF editors and re-savers, reprocessors, scanners and OCR tools each carry a stated weight. A re-saved file is reported as provenance not assessable, never as altered.
Modified after creation
A modification date later than the creation date means some tool re-saved the file after it was written.
Incremental saves
End-of-file markers beyond the one (or two, for a linearized file) that a single write produces; the footprint of editing a PDF in place, and also of signing one.
Template fingerprint
For a layout the method knows by name, the production stack (producer, fonts, page geometry) is compared with known specimens of that layout.
Mixed production stacks
Statements claiming the same bank produced by different software stacks.
Months created on one day
Statements for several months that were all written on the same day. Weak on its own (a portal session does this); weighed with the rest.

Typography of the page

Earlier revision inside the file
A PDF saved in place keeps its earlier version inside the bytes. The earlier version's text is compared with the final page line by line; replaced or added text is weighted high, removed text (a redaction) is a review note.
Row typography
Every transaction row on a page is drawn from the same font subsets at the same size. A row set in a different face, a second subset of the same face, or a different size is listed with its text. Bold total rows and footnote marks are not odd.
White-out over text
A small filled light rectangle painted after text already on the page, covering it. Painting order is read from the page's own content stream.
Text over text
Two different texts sharing one baseline and span on a transaction line.
Row geometry on scans
On a scanned page, word baselines, letter heights and row edges are measured from the OCR word boxes. Two neighbouring words shifted off their row's baseline together, one word further off or a different height, or a few words read as a short line of their own inside a row, are listed. Thresholds come from the scan's own noise and were set on real scanned statements so that clean pages produce no note; the entry says which pages were measured and which had too few rows to test. A line inserted on a text line of its own is not seen.

Content of the rows

Duplicated lines
Identical credit lines on the same day whose printed balances cannot confirm them as separate transactions.
Repeated identical deposits
The same deposit description and amount recurring on three or more days.
Summary box against the ledger
Where a statement prints deposit and withdrawal totals, they must equal the rows; tested only when the rows already tie, so a misread row can never produce this note.
ACH on a non-banking day
A line labelled ACH posted on a weekend or a US federal holiday.

Reading

Text layer first, OCR second
A PDF with a text layer is read from the text layer. Only when that read does not tie, or there is no text, are image pages read by OCR on our own server, in memory, and the OCR read is kept only when it is the one that ties. OCR-read rows are marked.
Never a refusal
Every file dropped into a matter gets a register entry: read, read in part, or examined but not read, with the reason in plain words and the list of checks that could not run on it.

Weights

Every note is a review signal. A note is weighted high only where the checks have shown, on real files, that no ordinary explanation remains; everything else is marked review. A new check ships at review weight and earns a higher weight only after real matters show where the line sits.

What is not checked

Docuritas proves the numbers and flags what broke a check. What stays with the examiner:

  • Whether a statement is altered. The exhibit reports what the arithmetic, the calendar and the file itself show, and what to ask the bank for. Reading those facts into a finding is the examiner's work.
  • Provenance of a printed-and-rescanned statement. A rescan carries none, the register says so, and the proof rests on the arithmetic and the month chain instead.
  • Visual inspection. Logos, layout and image content are not compared to a genuine specimen; the method reads the file's own structure, fonts and row geometry, not how the page looks to the eye.
  • Identity and screening of any party, and the purpose of a transfer. Counterparty labels are grouped from the printed description; what they mean is the examiner's call.
  • The opinion. The exhibit is a mechanical record with a hash. The report that rests on it, and its conclusions, are signed by the examiner.

Version log

The version is printed on the cover of every exhibit. A check added, removed or re-weighted is listed here with its date, so an exhibit can be read against the method that produced it.

v0.1 · 2026-09-08
Row geometry on scans withdrawn, recalibrated on real scanned statements the same day (zero notes on clean pages is the bar) and returned at review weight; raster pages that carry an OCR text layer are now measured too. Exhibit entries say which pages were measured.
v0.1 · 2026-09-08
Line-level checks added at review weight: row typography, white-out over text, text over text, earlier revision inside the file, row geometry on scans. Payment-app exports (PayPal, Venmo, Cash App) and ledger comparison added. Calibrated on real bank exports: zero notes on clean files is the bar.
v0.1 · 2026-09-07
First method: balance identity, running-balance chain, month chain per account, transfer matching, unmatched outflows, counterparty totals, file identity, producer class, modified-after-creation, incremental saves, template fingerprint, months created on one day, duplicated lines, ACH calendar.

Benchmark

The engine is scored on an open corpus of altered and genuine statement sets with published labels; the corpus and the scoring script are public so anyone can rerun the result. The one unsolved case in the corpus, a fully re-cascaded final month with no neighbour, is documented as unsolved.