consulting-agreement-signed.pdf (6 pages)
This document was modified after it was signed.
This file was signed and then changed: the records show content added after the signature was applied.
Verified checks
These checks are cryptographic. They can be proven or disproven.
Modified after signingNeeds attention
This document was changed after it was signed. The signature covers an earlier version of the file, not the file you have now.
Why it matters: The signature may protect an earlier version, while the current file contains material added later.
Next step: Compare this file against the originally signed copy before relying on the added content.
Technical detail
The signature's ByteRange ends before the end of the file. Content was appended after the signature was applied, using a PDF incremental update. The signed bytes may still verify, but they do not cover the current document.
Digital signatureInformational
A digital signature from Jordan Reyes is present on April 02, 2026.
Why it matters: Unsigned PDFs can still be useful, but the file cannot prove that its bytes were sealed by a signer.
Next step: Use the metadata and timeline observations below, and request a signed original when the document depends on signer proof.
Technical detail
Signer (from certificate): Jordan Reyes. Certificate issuer: Jordan Reyes. Certificate validity: 2025-11-02 to 2027-11-02. Recorded signing time: 2026-04-02T16:45:10. Signature format: /adbe.pkcs7.detached. Verifier output: Signature valid over its covered range.
All pages coveredVerified
The signature covers every page of the document.
Why it matters: A signature only protects the pages and bytes it covers.
Next step: Review any uncovered pages manually and ask for a version where the entire document is signed.
Technical detail
All 6 pages fall inside the signature's coverage.
File fingerprintInformational
This is the file's unique fingerprint. Any change to the file, even one byte, produces a different fingerprint.
Why it matters: The fingerprint lets another person prove they are looking at the exact same file later.
Next step: Keep this hash with the file, email, or case note so later copies can be matched byte for byte.
Technical detail
SHA-256: 2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e
Observations
These are signals from the file's records. They suggest, but never prove, how the file was made and handled.
Re-save layers presentInformational
This file was saved 2 more times after it was first written. Save layers are normal for signed or edited documents.
Why it matters: Save layers are the file's own record of how many times it changed after the first export.
Next step: Match the layer count against the file's story: a single export should have one, a signed document gains one per signature.
Technical detail
The file contains 3 generations. PDFs save changes by appending a new generation, so each layer marks a save event after the original export. The signature and date findings show what each layer most likely was.
Creating softwareInformational
This file reports it was made with Microsoft Word for Microsoft 365, Microsoft Word.
Why it matters: The software trail often shows whether a file came from a source system, an editor, a converter, or a print step.
Next step: Compare the software named here with the document's claimed source and ask for an original export if they do not fit.
Technical detail
Producer and creator fields are written by the software that created the PDF. They are informational and can be edited.
Edited after creationInformational
The file was created on April 01, 2026 and last modified on April 15, 2026, about 14 days later.
Why it matters: Creation and modification dates are editable, but their order often exposes rebuilt or re-saved files.
Next step: Check whether these dates fit the document's story, email timestamps, and any source-system records.
Technical detail
Gap between PDF /CreationDate and /ModDate. A gap is common for documents that were edited over time.
Edit historyInformational
The file's edit history records 2 edit events. Software seen in the history: Microsoft Word, PDF Editor 11.2.
Why it matters: Revision history can show how many times editing software recorded changes to the file.
Next step: Match the software and edit gaps against the expected workflow for this document.
Technical detail
XMP metadata keeps a revision history written by editing software. Largest gap between recorded edits: 318.5 hours.
Reconstructed timelineInformational
The file's internal dates span from April 01, 2026 to April 15, 2026.
Why it matters: A timeline makes date conflicts easier to see than isolated fields.
Next step: Compare this sequence with emails, version history, signatures, and the date the file was received.
Technical detail
Events recorded inside the document: April 01, 2026: PDF creation date; April 02, 2026: Digital signature time; April 15, 2026: PDF modification date.
Filename signalsInformational
The filename uses words common in final or issued documents (SIGNED).
Why it matters: Filenames are weak evidence, but they can explain whether a file looks like a draft, final copy, or issued record.
Next step: Treat the filename as context only and rely on the file records above for the stronger checks.
Technical detail
Filename pattern analysis. Matched keywords: SIGNED. Filenames are easy to change, so this is a weak signal.
What this means and what to do next
Treat the signed version and the later additions as two different things. Request the originally signed copy and compare it against this file before relying on anything the additions changed. For a dispute, preserve this exact file and record the fingerprint above.
Keep this report. It records this file's fingerprint as verified on June 10, 2026.
DocVerdict reports document evidence and classifications. It does not determine fraud, authenticity, or legal validity. Decisions belong to qualified professionals.