validar.iti.gov.br is the government's official validator, and on an ICP-Brasil-signed document nothing beats it: any later alteration breaks the signature and it says so. The question is how many of the documents on your desk it can examine at all.
This page answers both halves: what the validator covers, stated with the respect a well-built public service deserves, and what is left for structural analysis when the signature simply is not there.
Summary
- ICP-Brasil-signed document: use the official validator. It is free, official, and cryptography catches any change made after signing. No structural heuristic competes with that, and this page does not pretend otherwise.
- Unsigned document: the validator has nothing to say. Pay stubs, bank statements and utility bills arrive, as a rule, with no signature at all, and "no signatures found" is not a pass. Everyday document fraud lives almost entirely here.
- A valid signature is not true content. The legal presumption is rebuttable and runs to the signatories, not to what the document states. A document false from the start, signed by whoever fabricated it, validates cleanly.
What the official validator does, and does well
The ITI service validates ICP-Brasil signatures in the formats
Brazilian electronic documents actually use: PAdES in PDF, attached
CAdES (the .p7s) and XAdES in XML. For each signature it
answers what a relying party needs: whether the certificate was valid
and chained to the ICP-Brasil root, whether the timestamp holds, and, the point of this page. whether the file was altered after it
was signed.
That last check is cryptographic. A signature stores the hash of a defined byte range; if any byte in that range changed, the hash no longer matches and the signature breaks. Content appended after signing, via incremental update, is judged against what the signer permitted (the document-modification rules. DocMDP): when that does not hold together, the result is reported as indeterminate rather than valid. There is no heuristic in any of this, which is why no structural reading, ours included, competes with the validator on the documents it can examine.
The recommendation, plainly: if the document you received carries an ICP-Brasil signature, validate it at validar.iti.gov.br first. It is free, and its answer is better than any commercial tool's, on what it covers.
The document it cannot see
A validator needs a signature to validate. The pay stub a payroll system generates, the statement downloaded from internet banking, the utility bill used as proof of address, the supplier's PDF invoice, as a rule, none of them carries an ICP-Brasil signature. Submitted to the validator, the answer is that the document contains no signatures. That is not a fail; it is not a pass either. It is the statement that this tool has nothing to say about this file.
And that is exactly where everyday document fraud happens. Whoever doctors a pay stub for a screening desk does not need to defeat any cryptography: the document never had a signature, the analyst never required one, and the identity checks pass, because the identity is real; the document is not. What is left to examine on that file is its structure: how many times the PDF was written after creation, whether the producer matches the claimed issuer, whether its two internal metadata records agree. That is what the free checker reads, and what the API returns as JSON.
The signature disappears along with the fraud
There is a second, less obvious limit. Editing a signed PDF breaks the signature, but a fraudster does not edit: they regenerate. Printing the document to a fresh PDF, or rebuilding it in a generator, produces a clean file with no signature at all, which a desk that already accepts unsigned documents receives without a second look. The cryptography was not defeated; it was discarded along with the original file, and the validator has nothing left to examine.
In that scenario the structure still speaks, with limits we prefer to state outright: a file regenerated from scratch in a single tool is structurally coherent and raises no editing signal. The edit-detection guide is honest about that. What remains is context: the absence of a signature on a document whose issuer usually signs is, in itself, information, and the Tamperlens report describes the presence, coverage and permissions of signatures when they exist (the three signature signal families), without validating the certification chain, which is the official validator's job.
What Brazilian law actually says
Worth stating precisely, because the two halves are usually blurred into one argument:
The presumption is rebuttable: it shifts who has to prove what, and it is not a finding of fact about the document's contents.
- MP nº 2.200-2/2001, art. 10, §1º. Documents signed with an ICP-Brasil certificate "are presumed true with respect to the signatories". The presumption is rebuttable and runs to the signatories. It does not assert that the document's content is true, and it does not reach what happened to the file in later copies and reprints.
- Law nº 14.063/2020, art. 4º: three tiers of electronic signature (simple, advanced, qualified). Only the qualified tier is ICP-Brasil; the advanced tier promises that later modification is detectable, but without the public certification chain.
- CMN Resolution nº 4.753/2019, art. 7º, I, account-holding institutions must assure "the integrity, the authenticity and the confidentiality [...] of the electronic documents used". The rule speaks of the documents customers hand over, and those, as a rule, arrive without a qualified signature. The obligation to look at them exists even when the official validator has nothing to validate.
A workflow that uses both
- Does the document carry a digital signature? Validate it at validar.iti.gov.br. A valid ICP-Brasil signature settles "did this file change after signing?" better than any structural signal would.
- Did the signature validate? Remember what it does not cover: the truth of the content. Income, employment and plausibility checks are still yours.
- No signature: the common case? Read the structure: revisions after creation, producer versus claimed issuer, conflicting metadata records. A strong signal becomes a specific request ("could you download it again straight from the system and resend?"), not an accusation. Tamperlens reports risk signals, not verdicts.
- Issuer usually signs, and this file arrived unsigned? Treat the absence as a question to ask, with the original document back as the ideal answer.
Frequently asked questions
Does Brazil's official validator detect any PDF edit?
No. It validates ICP-Brasil digital signatures, and on a signed document it catches changes made after signing, because any altered byte breaks the signed hash. On an unsigned document there is no hash to check: the validator reports that it found no signatures, and that is neither a pass nor a fail. It is silence.
Does Tamperlens validate ICP-Brasil signatures?
Not cryptographically. Tamperlens reads the structure of a signature (how much of the file it covers, what was appended after it, and what the signer permitted to change), but it does not verify the ICP-Brasil certification chain or check revocation lists. That is what validar.iti.gov.br exists for, and it is official and free. If your document carries an ICP-Brasil signature, start there.
Can a document with a valid signature still be fraudulent?
Yes. The legal presumption attached to ICP-Brasil signatures (MP 2.200-2/2001, art. 10, §1º) is rebuttable and runs to the signatories, not to the truth of what the document states. A pay stub with an invented salary, digitally signed by whoever invented it, validates without complaint. The signature proves who signed and that the file has not changed since; it does not prove the content is true.
Do Brazilian pay stubs and bank statements arrive digitally signed?
As a rule, no. Some banks sign PDF statements, and documents from Brazil's electronic court systems usually arrive signed, but the pay stub a payroll system generates, the utility bill used as proof of address, and most PDFs that reach a screening desk carry no ICP-Brasil signature. That is exactly why the official validator does not solve document screening: the documents that matter are rarely eligible for it.
Do I need to upload the document to a server? Is that safe?
In the Tamperlens checker, the file travels over HTTPS, is read in memory and discarded once the response is written. No document is written to disk, nothing is logged, there is no human review and nothing is shared with third parties. The privacy policy spells this out. validar.iti.gov.br is a Brazilian federal government service with its own rules: read its terms before submitting sensitive documents.
Run an unsigned document through the checker
The free checker takes a dragged-in PDF and shows the same report the API returns, no account, nothing stored. Start with a document you know is genuine, from the issuer you receive most; then run one you have opened and re-saved in an editor yourself. The difference between the two reports is what decides whether the signal is useful in your workflow. Need it inside your own system? One HTTP call returns the same report as JSON, API quickstart, 50 documents per month on the free plan, and paid-plan amounts are on pricing.
Tamperlens reports risk signals, not authenticity verdicts. Signals can have legitimate causes; combine them with your own decision logic, and, on ICP-Brasil-signed documents, with the official validator, which is what answers for the cryptography.
Related reading
- Signature signals What a signature covers, what came after it, and what the signer allowed to change.
- Bank statement fraud signals The same method applied to the document that arrives by upload most.
- Check a pay stub The screening desk's typical document, straight into the checker.
- Detect an edited PDF The structural checks by hand, with terminal commands.