Who runs Tamperlens

One named person, in the open — and, for now, no company. What that means and what is changing.

Before you send customer documents to an API, you are entitled to know who is on the other end of it. This page answers that in plain terms rather than with a team-photo grid: who builds and operates the service, under what legal identity, and where to write when you need a person to answer.

The person

Tamperlens is built and operated by Douglas Haruo, in Curitiba, Brazil. He came to it from KYC/AML and tax-compliance work — the side of the table that receives bank statements, payslips and proofs of address and has to decide whether to act on them. Tamperlens is the tool that work was missing: not a system that answers approve or decline, but one that reads a file's own structure and reports what a trained reviewer would want pointed out, with the evidence attached and the benign explanation listed next to it.

Everything here is one person's work: the inspection engine, the infrastructure, the documentation, and the support inbox. That has a cost — the security page lists what a one-operator service does not have, by name — and a benefit: when you write in, the person who answers is the person who wrote the parser.

Elsewhere: haruo.dev, and the engineering write-ups on the blog.

What Tamperlens is, and refuses to be

Tamperlens reports risk signals, never verdicts. It is on the footer of every page because it is a real position, not a hedge: the engine can establish that a PDF carries three revisions and that the last one drew a box over a number; it cannot know whether that was a forger or a payroll system doing its job. So every finding ships with its evidence and its innocent explanation, and the decision stays with the reader — or with the caller's own written policy, applied under the caller's name, never ours.

The legal entity

Today the service is operated by its individual owner — the same wording you will find in the Terms. A Brazilian legal entity (CNPJ) is being registered. When the registration completes, this section will carry the company name and number, and the Terms and Privacy pages will be updated to name it.

Until then, the absence is stated here rather than papered over. If your procurement process needs an entity name before you can sign anything, write to [email protected] and you will get the current state of the paperwork, plainly.

The practice the product is built on

The habit this service asks you to judge it by is publishing its own measurements, especially the inconvenient ones. The engine's false-positive rate was measured on 1,728 documents nobody here curated, and the number that came back was published, not filed. Uptime is measured from outside the box and shown at status.tamperlens.com. The security page ends with the certifications we do not hold. If a claim on this site ever outruns what was measured, that is a bug — report it like one.

Contact

[email protected] — read and answered by the operator. For security reports, the disclosure section has its own instructions.