Home / ProofShield / ProofShield Specification
ProofShield
The Shield Against Document Fraud
ProofShield is an open-source document authenticity and fraud prevention specification designed to protect digital and physical documents from forgery, unauthorized alteration, image manipulation, and AI-generated document fraud.
ProofShield establishes a trusted source of truth for a document through certified mirror images, cryptographic identity, provenance records, alteration detection, and verifiable authenticity seals. The system is designed to make unauthorized changes visible and provide a reliable method for determining whether a document is authentic, altered, or unverifiable.
Core Objectives
- Establish a trusted representation of an authentic document.
- Detect unauthorized document alterations.
- Identify AI-generated and AI-assisted manipulation.
- Preserve document provenance and version history.
- Make detected alterations visibly identifiable.
- Provide cryptographically verifiable authenticity.
- Protect sensitive information during verification.
- Support hardware-backed document security.
- Provide universal verification across devices and platforms.
- Create an open-source foundation for document trust and fraud prevention.
Core Modules
Certified Mirror Image System
The Certified Mirror Image System establishes a certified representation of the original document.
The module shall:
- Register an original document as a trusted source.
- Create a Certified Mirror Image representing the authentic document.
- Associate the mirror image with a unique document identity.
- Preserve the original document’s visual characteristics.
- Establish cryptographic identifiers for the certified representation.
- Detect divergence between submitted documents and the certified mirror image.
- Preserve evidence required to verify the authenticity of the registered document.
Certified Authentic Seal
The Certified Authentic Seal provides a visible and verifiable indication that a document has been registered and validated.
The module shall:
- Generate a Certified Authentic Seal for verified documents.
- Associate the seal with the document’s cryptographic identity.
- Prevent unauthorized reproduction from being treated as authentic.
- Support digital and physical representations.
- Allow verification systems to validate the seal.
- Indicate when a document’s current state no longer matches its certified state.
Pixel-Level Alteration Detection
The Pixel-Level Alteration Detection module analyzes submitted document images against certified originals.
The module shall:
- Compare document images at the pixel level.
- Detect modified regions.
- Identify inserted, removed, replaced, or reconstructed content.
- Highlight altered regions visibly.
- Preserve alteration evidence.
- Distinguish expected rendering differences from potentially material alterations.
- Support configurable sensitivity levels.
- Produce a verification result describing detected changes.
Document DNA Fingerprinting
The Document DNA Fingerprinting module creates a persistent identity for each registered document.
The module shall:
- Generate cryptographic document fingerprints.
- Incorporate relevant document characteristics into document identity.
- Detect changes that affect document integrity.
- Support multiple representations of the same document.
- Maintain relationships between original documents, certified mirrors, and verified copies.
- Prevent document identity from depending solely on filenames or metadata.
AI Manipulation Detection Layer
The AI Manipulation Detection Layer identifies manipulation associated with image generation, generative editing, synthetic reconstruction, and other AI-assisted document alteration techniques.
The module shall:
- Detect AI-generated document imagery.
- Detect generative fill and synthetic replacement.
- Detect AI-assisted text replacement.
- Detect fabricated signatures.
- Detect fabricated seals, stamps, and official markings.
- Analyze reconstruction artifacts.
- Analyze rendering and compression anomalies.
- Compare suspected synthetic regions against certified document evidence.
- Provide confidence assessments.
- Preserve evidence supporting AI manipulation findings.
- Clearly distinguish detection confidence from definitive proof.
Privacy-Preserving Verification
The Privacy-Preserving Verification module enables authenticity checks while minimizing unnecessary disclosure of document contents.
The module shall:
- Support selective disclosure.
- Support cryptographic proofs of authenticity.
- Allow verification without exposing the complete document when technically feasible.
- Protect personally identifiable information.
- Minimize retention of sensitive document data.
- Support privacy-preserving provenance queries.
- Separate authenticity verification from unnecessary content disclosure.
- Provide configurable verification policies.
ProofShield API
The ProofShield API provides standardized interfaces for document registration, verification, provenance, and fraud analysis.
The module shall support operations for:
- Document registration.
- Certified Mirror Image creation.
- Document verification.
- Certified Authentic Seal validation.
- Provenance lookup.
- Alteration analysis.
- AI manipulation analysis.
- Document fingerprint generation and validation.
- Verification report generation.
- Version history retrieval.
- Fraud reporting.
- Privacy-preserving verification.
- Hardware-backed verification.
- Integration with external document systems.
Hardware Security Integration
The Hardware Security Integration module connects ProofShield verification with trusted hardware security capabilities.
The module shall support integration with:
- Trusted cameras.
- Secure scanners.
- Trusted acquisition devices.
- TPM-backed identity.
- Hardware security modules.
- Secure enclaves.
- Hardware-backed cryptographic keys.
- Tamper-resistant key storage.
- Device identity verification.
- Secure document capture.
- Hardware-backed signatures.
The module shall allow trusted hardware to establish evidence about the origin and integrity of captured documents.
Camera and Device Compatibility
The Camera and Device Compatibility module provides a universal acquisition framework.
The module shall support:
- Mobile cameras.
- Digital cameras.
- Document cameras.
- Scanners.
- Multifunction printers.
- Secure capture devices.
- Desktop devices.
- Embedded devices.
- Trusted hardware.
- Other document acquisition systems.
The module shall account for expected differences caused by resolution, optics, lighting, compression, scanning, and other capture conditions without automatically classifying those differences as fraud.
Software Compatibility
The Software Compatibility module provides interoperability with systems that create, process, store, transmit, display, or verify documents.
The module shall support integration with:
- Document management systems.
- Image processing software.
- PDF systems.
- Office productivity systems.
- Identity systems.
- Financial systems.
- Government systems.
- Educational systems.
- Enterprise systems.
- Real estate systems.
- AI systems.
- Digital signature systems.
- Document verification services.
Provenance Registry
The Provenance Registry maintains a verifiable history of document origin and significant document events.
The module shall:
- Record document registration.
- Record certification events.
- Record verification events.
- Record authorized versions.
- Record provenance relationships.
- Preserve timestamps and verification evidence.
- Support provenance queries.
- Detect unexplained provenance gaps.
- Support privacy-preserving provenance verification.
Document Version Control
The Document Version Control module maintains the relationship between authentic documents and authorized changes.
The module shall:
- Create document versions.
- Identify authorized modifications.
- Preserve previous document states.
- Associate versions with provenance records.
- Identify unauthorized divergence.
- Compare document versions.
- Maintain integrity across document lifecycle events.
Fraud Detection and Reporting
The Fraud Detection and Reporting module identifies, documents, and reports suspected document fraud.
The module shall:
- Identify suspicious alterations.
- Classify alteration types.
- Record affected regions.
- Preserve verification evidence.
- Generate fraud reports.
- Provide confidence assessments.
- Support authorized reporting workflows.
- Maintain an audit trail.
- Distinguish suspected fraud from confirmed fraud.
- Prevent verification results from being presented as legal conclusions unless independently established.
Universal Verification Framework
The Universal Verification Framework provides a standardized method for determining document status.
A verification result may identify a document as:
- Certified authentic.
- Authentic with expected transformation.
- Authorized modified version.
- Altered.
- Suspected manipulated.
- AI-manipulated.
- Unable to verify.
- Conflicting with certified evidence.
The framework shall provide sufficient evidence for users and systems to understand why a verification result was produced.
Modular Architecture
ProofShield shall use a modular architecture that allows individual capabilities to operate independently while supporting coordinated verification.
The architecture shall:
- Permit modules to be enabled or disabled.
- Allow independent module development.
- Support optional plugins.
- Support multiple verification workflows.
- Provide defined interfaces between modules.
- Permit future detection methods to be added without redesigning the entire system.
- Support deployment across different environments.
- Maintain interoperability between compatible implementations.
Security Features
The Security module shall provide protections for document identity, verification records, provenance, cryptographic material, and system operations.
Security capabilities shall include:
- Cryptographic integrity verification.
- Secure identity management.
- Authentication.
- Authorization.
- Key management.
- Tamper detection.
- Audit logging.
- Secure provenance records.
- Verification integrity.
- Protection against replay and substitution attacks.
- Protection against unauthorized modification of verification records.
- Secure handling of sensitive document information.
Open Source Principles
ProofShield shall remain an open-source specification designed to encourage transparent development, interoperability, independent verification, and community participation.
The system shall prioritize:
- Transparency.
- Auditability.
- Interoperability.
- Portability.
- Reproducibility.
- User control.
- Privacy.
- Security.
- Modular development.
- Independent verification.
Optional Plugin Modules
Blockchain and Distributed Ledger Plugin
Provides optional distributed ledger capabilities for document provenance, certification events, and verification records.
Advanced Forensics Plugin
Provides additional forensic analysis for typography, layout, compression patterns, rendering artifacts, metadata inconsistencies, and image reconstruction.
Signature Verification Plugin
Provides specialized verification for handwritten signatures, digital signatures, seals, stamps, and other authenticity indicators.
Optical Character Recognition Plugin
Provides document text extraction for comparison between certified and submitted documents.
Watermark Verification Plugin
Provides detection and verification of visible, invisible, cryptographic, or machine-readable document watermarks.
Secure Capture Plugin
Provides enhanced trusted capture workflows for supported cameras and scanners.
Device Attestation Plugin
Provides optional hardware and device identity verification for trusted acquisition and verification environments.
Enterprise Integration Plugin
Provides integrations with enterprise document management, compliance, identity, financial, government, and records systems.
Government Verification Plugin
Provides workflows for government-issued documents and institutional verification systems.
Financial Document Plugin
Provides specialized analysis for financial statements, checks, lending documents, transaction records, and related financial documentation.
Identity Document Plugin
Provides specialized verification capabilities for identity-related documents while maintaining configurable privacy protections.
Real Estate Document Plugin
Provides specialized verification for deeds, contracts, disclosures, inspection documents, appraisals, mortgage documents, title records, and other real estate documentation.
Legal Document Plugin
Provides specialized document integrity and provenance workflows for contracts, court filings, notices, agreements, and other legal records.
AI Threat Intelligence Plugin
Provides continuously updated detection intelligence for emerging AI-generated manipulation techniques and document fraud patterns.
Privacy Proof Plugin
Provides advanced cryptographic proof mechanisms for proving document properties without disclosing the complete underlying document.
Fraud Intelligence Plugin
Provides aggregated analysis of recurring manipulation patterns, fraud indicators, and related verification events while maintaining applicable privacy controls.
External Registry Plugin
Provides interoperability with trusted external registries and independent certification authorities.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/proofshield/
License & Notice Requirements
ProofShield is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to any ProofShield project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to Roxanne Ardary and roxanneardary.com.
- ProofShield specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – ProofShield
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com | July 9, 2026
Created the repository for ProofShield. Designed the modular document authenticity and fraud prevention system, including certified mirror images, AI manipulation detection, privacy-preserving verification, ProofShield API architecture, and hardware security integration. - [Add other contributors here] | [Date]
[Describe contribution in one sentence]
License – ProofShield
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
