NotChanged

Early access · Prove bank PDFs without the bank

Prove a PDF was downloaded from a real bank site.

Applicants install a Chrome extension. When they download a statement from their bank, NotChanged records the exact bytes and the HTTPS hostname they came from. Lenders and landlords verify later — no bank partnership required.

Verification result

↓ Verified download

HTTPS · hash match
Fetched from
online.bankofscotland.co.uk
Known institution: Bank of Scotland
Captured
6 Oct 2026
Record
Ed25519 valid

How it works

Two modes: (B) download-origin proof without bank partnership — our lead — and (A) issuer-signed PDFs when a payroll platform integrates. Anyone can verify.

1

Download

The applicant downloads a statement from their bank or opens a PDF on the bank site — as they already do today.

2

Prove

The NotChanged extension records the HTTPS hostname and SHA-256, then downloads a stamped -verified.pdf with a QR badge. Lenders verify that file alone.

3

Verify

The lender drops the PDF on our verify page and sees “Fetched from online.bank….co.uk”. Altered copies fail the hash check.

For issuers

Lenders, landlords & platforms

  • • Ask applicants to install the free Chrome extension before downloading bank PDFs.
  • • Verify uploads in seconds — see the source hostname, not just a green tick.
  • • Optional later: payroll platforms can still issuer-sign at creation via API.
  • • We store hashes and signed records, never the documents.

For receivers

Landlords, lenders & HR teams

  • • Scan the QR code or upload the PDF. No sign-up.
  • • See where it was downloaded from, when, and any details the applicant provided (with verified email).
  • • A single edited digit is detected: the cryptographic fingerprint no longer matches.
  • • Uploaded files are checked in memory and never stored.

One API call to sign

Send the PDF you already generate. Get back the same document with a verification badge and an embedded, signed provenance record. Public keys are published at /.well-known/docproof-keys.json so anyone can check our signatures independently.

Read the API docs →
curl -X POST https://notchanged.com/api/v1/sign \
  -H "Authorization: Bearer $DOCPROOF_API_KEY" \
  -F "file=@payslip.pdf" \
  -F "documentType=payslip" \
  -F "reference=EMP-0042/2026-09" \
  -o payslip-signed.pdf

# Verify (anyone, no key needed)
curl -X POST https://notchanged.com/api/v1/verify \
  -F "file=@payslip-signed.pdf"
# => { "status": "GENUINE", "document": { "issuer": ... } }

New · Chrome extension

Prove PDFs straight from your browser

Download a statement as usual and NotChanged saves a stamped -verified.pdf. Optionally add My Details (name, verified email) so the verify page shows who saved it.

Get the extension

Request early access

We're onboarding a small number of payroll and invoicing platforms, and receivers who want to verify documents at scale. Tell us a little about you.