Coverage · local and AI workflows

Exact support beats “any document.”

Ocolta publishes what each workflow can inspect, when evidence is limited, and which conclusions remain unsupported.

InputStatusIntegrity Scan evidence
Digital PDFSupported

File signature, metadata, PDF version, page markers, revisions, scripts, attachments, signature containers, SHA-256

PNG, JPG, WebPAccepted

File signature, embedded editor markers when exposed, EXIF presence/absence, pixel dimensions, SHA-256. PDF revision, scripts, attachments, and producer are not applied. Not issuer provenance. Not OCR.

Bank statementSupported workflow

PDF checks plus user-confirmed opening, deposits, withdrawals, and closing-balance math

PaystubSupported workflow

PDF checks plus user-confirmed gross, deductions, net-pay math, and bank-deposit consistency

W-2, 1099, tax returnFile checks only

Generic PDF structure only; no form-specific validation or issuer verification

Identity, degree, license, insuranceNot supported

No authenticity, identity, registry, issuer, or coverage validation

Password-protected PDFNot supported

Integrity Scan stops without returning findings and requests an authorized unlocked copy. Deep Review cannot unlock encrypted content

Scanned image or photoAccepted

Same checks as PNG, JPG, or WebP. Phone photos, scans, screenshots, and messenger shares are accepted. No OCR or pixel-tamper conclusion. Do not ask for a PDF.

Document-generator metadataSupported

Deterministic PDF Producer/Creator matching against the generator-signature database; high confidence only for self-described generator tools, medium for generic HTML-to-PDF stacks

Covered institution claimSupported

Detects when a file's text names one of the 20 fingerprinted institutions and links its genuine-format guide; records a claim, never verified provenance

Deep Review coverage

Model-readable is not the same as verifiable.

Accepted inputs

One PDF up to 25 pages, or one PNG, JPG, or WebP file, with a 5 MiB maximum per purchased review. Images are also limited to 10,000 pixels per side and 40 megapixels.

Password-protected PDFs

The workspace rejects password-protected files before model review. Use an authorized decrypted copy.

Visible evidence only

The model reviews what is visible or extractable from the submitted file. It does not contact an issuer, follow document links, query a registry, or establish ownership.

Inherent model limits

Output can be incomplete, inaccurate, variable, refused, or unable to determine. A style or metadata anomaly can have a benign cause; no indicator proves fraud, authenticity, or AI generation.

Institution fingerprint coverage

Exactly twenty institutions, named.

See how fingerprints are built and maintained.

Bank statements (12)

Chase, Bank of America, Wells Fargo, Citi, U.S. Bank, PNC, Truist, Capital One, TD Bank, Regions, Chime, Navy Federal

Payroll providers (8)

ADP, Gusto, Paychex, Workday, QuickBooks Payroll, Paycom, Paylocity, TriNet

Not fingerprinted

Every other issuer. An institution outside this list is reviewed with the general ruleset only; that is a coverage limit, not a signal about the document.

Deep Review+ corroboration coverage

What the appendix can and cannot check.

Researched

Institution-level entities only: the employer, the bank or statement issuer, and the payroll provider named by the document. At most four entities and six searches per review.

Sources

A public web-search API, public domain-registration (RDAP) data, and Ocolta's published table of payroll ACH descriptor conventions. Every finding cites its sources.

Excluded from research

Ocolta accepts institution-typed entities, drops person-typed entities, rebuilds queries from institution fields, and screens sensitive patterns. Automated classification can be wrong, so remove unnecessary personal data before upload. Ocolta is not a consumer reporting agency and does not produce consumer reports.

Not supported

No issuer, employer, credit bureau, identity service, or government records system is contacted. Public RDAP may supply domain-registration data, but Ocolta does not verify employment, income, account ownership, identity, or document authenticity.

“Not found” means inconclusive

Small, new, family-run, and offline organizations frequently have no public web presence. Absence of results is reported as inconclusive and must not be used as an adverse finding.

Hard limits

Ocolta does not authenticate an issuer.

A file can be internally consistent and still be fabricated. A legitimate issuer file can also carry edits or revisions. For high-impact decisions, obtain authorized source evidence and apply a consistent policy.

See how findings are scored

Start with evidence

Use the strongest supported evidence first.

Run a private, browser-based integrity scan. Your file never leaves your device.

Scan a document