By the time the final fifteen pages appeared online, the argument had outrun the documents. One public account treated the material as leaked FBI handwritten notes, while another soon warned that the same pages might belong to a disinformation campaign. The survivor at the center of the record had no role in creating that confusion, yet every unsupported claim about authenticity risked landing back on her credibility. I did not want to choose between two loud descriptions of the same files. I wanted to know what the government's own record could establish before anybody asked the reader to believe the next version of the story.
The Maxwell non-testifying witness-material index supplied the first public anchor before any forensic work began. It lists 3501.045-002, -004, and -006 as Interview Notes produced to Ghislaine Maxwell's defense on April 12, 2021, and places them between four numbered FBI interview reports from the same record family. That index does not authenticate an internet copy, and it says nothing about whether the allegations inside the notes are true. It establishes something more basic and more useful: three handwritten note sets existed in the discovery record, their positions were known, and their expected page counts could be derived from the official pages around them.
The first useful clue was not handwriting at all; it was the government's own bookkeeping, which is less dramatic and considerably harder to argue with. The released 3501.045 files preserve an older production sequence in which official 3501.045-001 runs from EFTA_00057707 through EFTA_00057715, -003 begins at EFTA_00057731, -005 begins at EFTA_00057759, and -007 begins at EFTA_00057767. The spaces between those records create three precise intervals rather than a loose collection of missing pages. That architecture existed before any circulating handwritten page was asked to fit inside it.
I calculated those gaps first because the sequence needed to predict the evidence instead of bending itself around evidence I already wanted to accept. The first interval requires fifteen pages, the second eighteen, and the third four. Those are the exact page counts of the three circulating note sets associated with -002, -004, and -006. A coincidence is still possible at this stage, but the direction of the test is important: the official neighboring records produced the numbers before the circulating pages were placed into them.
Once the handwritten sets are inserted into those independently predicted intervals, the older production sequence runs continuously from EFTA_00057707 through EFTA_00057771. The pattern also alternates the way the Maxwell index says it should - interview report, interview notes, interview report, interview notes - across the four sessions. That does not prove custody, and it does not convert a later copy into a government original. It gives the investigation a record architecture that later tests can either reinforce or break.
Before comparing a footer, a font, or a handwriting sample, I froze the evidence I actually had. The exact -004 and -006 PDF binaries were preserved, all fifteen -002 JPEGs were retained, and cryptographic hashes were recorded so later processing could not quietly replace the objects being tested. Working copies were used for extraction and rendering while the preserved files stayed untouched. That sounds procedural until a document begins changing in public; then the difference between 'the file I saw' and 'this exact file' becomes the entire argument.
The preserved -004 PDF contains eighteen pages and identifies OpenPDF 3.0.0 as its producer, with a March 6, 2026 creation time of 15:20:17 UTC. The four-page -006 file reports the same producer and a creation time of 15:20:03 UTC, fourteen seconds earlier.
Those timestamps do not tell us who created the files or where they traveled afterward. They do show that the two surviving PDFs were generated as closely timed derivatives in the same software environment, which becomes useful only when the older material inside them is examined separately.
I then checked the same binaries in Acrobat because I did not want one PDF parser validating its own interpretation. The visible #349 identifiers were already present in the preserved final generation of both files, and neither binary contained an incremental save showing those labels being appended afterward. That result narrowed the question from whether the labels were a late edit to what system had generated the wrapper containing them. The #349 text belonged to the March 2026 wrapper generation we actually possessed, while ownership of the numbering system remained unresolved.
Inside each OpenPDF page, however, the newer wrapper carries an older source-page object. That inner page already contains the 3501.045 identifier, the old EFTA_ production number, and the red CONFIDENTIAL footer before the outer wrapper adds its newer labeling. The distinction is easy to miss on a flat screenshot because both generations are visible at once. At object level, they are separate processing stages occupying the same final page.
I searched the frozen provenance record for a documented owner of the #349 numbering system and found none, including exact searches for the known values, filenames, and hashes against the source material available in this project. The result is deliberately narrow because a failed search cannot identify a system by exclusion. It prevents me from assigning #349 to DOJ, the FBI, a court, a vendor, or a particular litigation platform without evidence. The wrapper still remains useful for technical comparison even while its institutional owner remains unknown.
The most important control came from a file nobody was disputing. I took the official DOJ copy of 3501.045-001, preserved the original, and made a working copy that ended at the file's first internal end-of-file marker. The earlier revision opened as a valid PDF rather than as a broken fragment. It already carried 3501.045-001, the old EFTA_00057707 production number, and the red CONFIDENTIAL footer, while the later public EFTA01245620 stamp had not yet been added. For the first time, the investigation had an official before-and-after example of the processing stage the circulating note pages appeared to preserve.
The complete official -001 file shows the next stage in the same document's life. The older markings remain in place, while a later incremental revision adds the final public EFTA01245620 identifier at the bottom of the page. That means an official DOJ PDF can preserve an earlier production layer inside the later public file rather than flattening every stage into one image. The note pages no longer had to be compared with a hypothetical workflow; they could be compared with a workflow visible inside a known official neighbor from the same record family.
That comparison is strong because it supplies a real control, although it still cannot authenticate the circulating note pages by itself. A skilled person could start with a genuine older production page and build a later derivative around it, which keeps reconstruction on the table. The control tells us what a genuine earlier 3501.045 production stage can look like and gives the later footer, sequence, object, and handwriting tests something concrete to challenge. Visual resemblance alone would not have been enough to do that work.
It also separates two questions that public discussion repeatedly collapsed. An official PDF can contain an older 612-by-792 production page and a later public Bates layer in the same file, while the circulating -004 and -006 copies can contain that older-style page inside a separate March 2026 OpenPDF wrapper.
The existence of a later wrapper is therefore not evidence that the older page beneath it was invented at the same time. The wrapper and the source page have to be tested on their own histories.
The next clue lived in the source-page processing history rather than in the handwriting. Every page of -004 contains an Acrobat header-and-footer record for the red CONFIDENTIAL footer with a LastModified time of April 13, 2021 at 09:54:56 Eastern. Every page of -006 carries the same settings one second later, at 09:54:57. The Maxwell index says both note sets had been produced to the defense the day before. That timing does not identify the operator, but it places a common processing event exactly where a defense-production workflow would be expected to leave one.
The internal record repeats the same centered red CONFIDENTIAL settings across every page in both sets. Metadata can be edited, copied, or transplanted, so I refused to treat the timestamp as a custody certificate.
Its value comes from convergence with the page structure around it, because the setting appears inside the older source pages rather than as a feature created by the March 2026 wrapper. The one-second relationship also tracks across two separate note sets instead of appearing on a single isolated page.
When the page images are normalized to the same dimensions, -004 and -006 produce pixel-identical red CONFIDENTIAL footer masks. Earlier revisions of official -001, -003, -005, and -007 occupy the same bottom-page region with closely matching geometry, while the JPEG compression in -002 softens the edges without moving the footer out of that family. A footer is easy to imitate if somebody knows what to copy. The useful part is that this footer behaves consistently across official earlier revisions and all three circulating note populations before handwriting is considered at all.
The footer and the EFTA sequence gave the investigation two independent lanes that were asking different questions. The sequence tested where the pages belonged, while the footer and April processing record tested how the source pages had been handled. Neither could establish authenticity on its own, and agreement between them did not erase the custody gap. It did mean that a later reconstruction theory would eventually have to explain both structures at the same time.
The fifteen -002 pages were the set I trusted least at the beginning because the source PDF is still missing. A JPEG can show handwriting and visible labels while hiding the object tree, incremental revisions, and embedded metadata that make -004 and -006 so much easier to inspect. I therefore treated -002 as a separate acquisition problem instead of letting the stronger PDFs lend it credibility by association. If the fifteen images were going to join the same record family, they had to survive tests that did not depend on having their original container.
All fifteen files are 640 by 828 pixels and share the same JPEG sampling, quantization, and minimal EXIF structure. Their page geometry closely matches a 612-by-792 PDF page scaled to 640 pixels wide, which is consistent with one common rasterization or conversion batch.
That does not identify the source PDF or the person who performed the conversion. It does make fifteen unrelated screenshots or ad hoc captures a less economical explanation for the set we actually possess.
Amy Gabrielle raised a useful visual question about the #349 typography on -002, and that question deserved measurement rather than a fight over screenshots. I recovered the known overlay geometry from -004 and -006 and rendered competing fonts into the same position on all fifteen JPEGs. Helvetica-Bold produced the strongest tested fit on every page, with a mean image-similarity score around 0.916, ahead of Helvetica regular, Times Bold, and Courier Bold. The result does not prove who created the overlay, but it weakens the specific claim that -002 uses a visibly different typeface from the known wrappers.
Placement gave the typography test another constraint because the font model also had to land in the same place on every page. A recreation could copy that placement intentionally, which keeps the result from becoming an authentication shortcut.
Even so, every page's best fit required zero horizontal and zero vertical correction from the geometry recovered from -004 and -006. The apparent typography difference that looked suspicious by eye therefore did not survive a direct model of the known overlay.
The sequence test was designed so the expected answer had to compete for itself. The neighboring official records predict EFTA_00057716 through EFTA_00057730 for the first note set, so I tested that fifteen-page run against one hundred other possible starting positions from 57650 through 57750. The expected 57716 start ranked first on the aggregate image fit and beat the nearest serious competitor, 57726, on twelve of the fifteen pages. The test does not convert fit into an authenticity probability. It asks whether the visible old-EFTA remnants behave most like the sequence the official record predicted before the JPEGs were examined.
I then resampled the comparison twenty thousand times to see whether a fortunate combination of pages was manufacturing the advantage. The expected sequence stayed ahead essentially throughout the bootstrap distribution.
That stability is important because one damaged footer or one unusually clear page can otherwise dominate a small set. The result remained an image-fit finding rather than a custody finding, but it survived the attempt to make its ranking disappear.
The final -002 screen looked for an obvious local compression break around the footer, the sort of crude paste that can leave a separate residual pattern. The screen found no conspicuous localized seam, which removed one simple fabrication signal without ruling out competent editing. A polished edit can survive recompression and a genuine page can accumulate artifacts during conversion, so this test carries deliberately little weight. I kept the result because negative tests belong in the record too, especially when they fail to provide the dramatic answer a reader might expect.
Handwriting came last because a handwriting score cannot rescue a weak document chain. I used the Hamburg Handwriting Analysis Tool as a computer-assisted similarity screen after the sequence, wrapper, footer, and processing tests had already established independent points of comparison. The tool cannot name a writer, cannot identify an FBI agent, and cannot prove provenance. I wanted to know whether the dominant writing in the three note sets continued to behave like related material as I progressively removed the conditions most likely to inflate that relationship.
Pass One used the complete available records and produced the starting pattern: -004 and -006 strongly favored one another, while -002 leaned toward -006 less decisively. The result was useful mainly because it exposed its own weakness. The three records contribute very different amounts of material, so the larger sets could be winning partly because the tool had more of them to compare. A first-pass score that looks impressive before page-count imbalance is controlled is a reason to keep testing, not a reason to stop.
Pass Two equalized the comparison to four pages per set and repeated the sampling so the larger records could no longer dominate simply by contributing more material. Under that control, -004 toward -006 averaged about 74.1 percent and -006 toward -004 about 73.4 percent, while -002 sat close to a 52/48 split.
Internal -002 comparisons also showed its earlier and later pages preferring one another. The -004/-006 relationship survived the first serious challenge, while -002 remained the less decisive member of the family.
Pass Three changed the FAST keypoint and orientation settings and added a treatment designed to reduce the influence of notebook ruling and page geometry. The -004 to -006 direction remained strong across the parameter changes, and -006 continued to favor -004. Suppressing visible page structure reduced some of the strength without reversing the relationship. That was the result I wanted from a stress test: less certainty where the method had been borrowing help from the page, but no convenient reversal hidden by the original settings.
Pass Four shifted from changing settings to hiding evidence from the comparison. I withheld groups of -004 pages and asked which comparison family the unseen pages selected when they were returned to the test.
All three held-out -004 groups chose -006, at roughly 61.8, 63.5, and 64.6 percent, while eight of nine broader holdout groups selected the expected cluster. The often-quoted 88.9 percent figure describes cluster consistency across those groups, not the probability that a named person wrote the notes.
Pass Five removed more page architecture than any earlier comparison. Notebook ruling was suppressed and the material was reduced toward individual handwriting lines, using roughly eighty -002 lines, ninety-two -004 lines, and sixteen -006 lines. The margins contracted sharply: -004 toward -006 fell to roughly 55.5 to 57.4 percent, -006 toward -004 to roughly 53.1 to 55.2 percent, and -002 remained close to even. The drop changed the language of the finding because it showed how much of the earlier separation depended on full-page context. The -004/-006 direction survived after the strongest-sounding numbers had fallen away.
That fifth pass made the handwriting evidence less dramatic and therefore more useful to the final assessment. The -004/-006 relationship survived after much of the page context was stripped away, although only with modest margins, which means handwriting can support the document-family result without deciding it. The weakened scores prevent the article from borrowing certainty from the earlier, larger numbers. I kept the contraction in the body because the least flattering credible version of a result usually tells the reader more than the best percentage produced along the way.
Once several independent lanes were pointing toward the same record family, another confirming test would have been easy to add and almost useless to the reader. I built the strongest reconstruction theory I could defend instead.
A knowledgeable actor working after March 2026 could know the 15/18/4 page architecture, infer portions of the old EFTA sequence from released 302s, copy visible footer conventions, transplant editable metadata, and wrap genuine or reconstructed pages inside polished PDFs. Public reporting could also supply enough content fingerprints to make a later reconstruction easier than it would have been before the surrounding files were released.
A sophisticated reconstruction remains technically possible because metadata is editable, genuine pages can be mixed with recreated material, and a competent derivative does not have to leave an obvious paste seam. The harder question is whether one reconstruction can account for every independent structure observed at the same time without quietly borrowing authenticity from the records it is supposed to explain away. I did not need the fabrication theory to become impossible before taking it seriously. I needed to see how much work the theory had to perform compared with the simpler explanation that these pages belong to the documented note family.
A successful reconstruction would have to place all three note sets into the exact gaps left by the released neighboring records while preserving the 3501.045 note/report alternation across EFTA_00057707 through EFTA_00057771. It would also need -004 and -006 wrappers generated fourteen seconds apart, nested source pages with April 2021 CONFIDENTIAL settings one second apart, footer geometry matching earlier official revisions, and a -002 population that wins the blind 101-start challenge.
Those demands are independent enough that explaining one does not automatically explain the others. The reconstruction theory grows more elaborate as it is asked to reproduce the same convergence the document-family theory already expects.
Handwriting adds another burden without being asked to authenticate the file. A reconstruction assembled from unrelated note pages might still be engineered to pass the sequence and footer tests, yet it would also need to preserve the -004/-006 relationship through page balancing, parameter changes, blind holdouts, and the weaker line-level comparison. Any one component could be manufactured or copied on its own. The challenge is making all of them behave together across the same thirty-seven-page population without producing a simpler contradiction somewhere else in the chain.
I kept failure conditions beside the finding so the investigation could still lose. An official note set with incompatible content or page structure would overturn the correspondence claim, as would a recovered -002 source PDF exposing a later manufactured layer, a source admission, an incompatible object history, or a reproducible defect that explains the current convergence more simply.
No such contradiction appeared in the frozen evidence reviewed for this article. That does not close the record; it tells the next person exactly what kind of evidence would reopen it.
The thirty-seven circulating pages strongly correspond to the missing 3501.045 interview-note sets documented in the Maxwell index. The case is strongest for -004 and -006 because their surviving PDF binaries preserve inspectable older source pages inside later March 2026 wrappers. Those inner pages occupy the expected old-EFTA positions, carry the same footer convention, and preserve April 2021 Acrobat processing structures that agree across both sets. The later wrapper history prevents me from calling the surviving files untouched government originals, yet it also gives us more history to inspect than a flat screenshot would have preserved.
-002 remains one step farther from the source because its PDF has not been recovered. The fifteen JPEGs behave like one derivative batch, fill the exact expected interval, survive the typography challenge, win the blind sequence comparison, and align with the same footer family. Their handwriting is internally coherent while remaining less decisive against the -004/-006 pair. Taken together, those findings support correspondence to the documented first note set while leaving the route from the source PDF to the surviving JPEGs unresolved.
Several descriptions still outrun the evidence even after the tests converge. The circulating PDFs cannot be called untouched final DOJ public-release files; #349 has no identified owner in the frozen record; the April 2021 metadata names no operator; and HAT identifies no writer. File-history analysis also cannot decide whether an allegation recorded during an interview is true. Document correspondence, copy custody, authorship, and factual corroboration remain separate questions that can move in different directions inside the same record.
The central finding depends on keeping those categories apart from the beginning. A genuine government note can survive only as a later derivative whose custody is incomplete, and a genuine note can accurately record what someone told investigators without establishing that the underlying event occurred. The current evidence supports correspondence to a documented government record family more strongly than it supports the provenance of every circulating copy. It leaves the merits of the allegations with the broader evidentiary record rather than asking a PDF parser to decide them.
Judge Emmet Sullivan's June 25, 2026 order provides an official endpoint to the document dispute. He directed the Attorney General either to produce the underlying FBI interview notes that formed the basis for four identified 302s, with appropriate victim-protective redactions, or show cause why the notes should not be produced.
The order independently confirms an underlying note layer in the government record and shows that those notes were significant enough to become the subject of a disclosure fight. It does not authenticate the Scribd, Reddit, or other copies examined here, which is exactly why the government's own benchmark remains so important.
Sullivan's order keeps the internet copies in proportion because it confirms the official note-family dispute without authenticating the copies now circulating online. DOJ has or had the comparison objects capable of answering the correspondence question more directly than another week of social-media certainty can.
A properly redacted official benchmark could protect the survivor while still allowing page structure, production marks, and version history to be compared. The most important unresolved evidence therefore sits with the custodian that can resolve the dispute without asking the survivor to become its proof.
The broader 3501.045 family extends beyond these handwritten pages. The Maxwell index lists later intake reports, an FBI report, a law-enforcement report, and license records, while Serial 159 identifies enclosures that create a high-confidence administrative crosswalk into the later 1A27 inventory family. I keep that finding secondary because it maps the continuing investigation rather than curing the custody gap in the circulating notes. No recovered page physically carries every label used across those administrative systems, so the crosswalk remains an administrative relationship rather than a claim that one page literally bears both identities.
A broken release history does not remain a technical problem when the file concerns a survivor. Once readers cannot tell which version came from where, suspicion starts drifting toward the person described in the record even when the handling failure happened years later and entirely outside her control. A strange footer becomes a credibility argument; a missing source file becomes a theory about the witness; a publisher's overstatement can be mistaken for something the survivor herself claimed. Institutions and publishers created those later layers, and they should have to answer for them without turning the protected person into the explanation for every defect in the chain.
The harm can travel in opposite directions and still land on the same person. A sloppy derivative can make a genuine record look fabricated, while overconfident reporting can lend the survivor's account more authority than the document itself supplies. She can end up carrying claims made by uploaders, commentators, or journalists she may never have seen. In a record already shaped by fear of exposure and retaliation, better provenance cannot resolve the allegation, but it can stop later handling failures from being stapled onto the survivor's credibility.
A release history sturdy enough to survive copying would preserve the official redacted file, a stable public identifier, the date and route of release, prior versions that were replaced, and a record of material redaction changes without exposing the protected person. Those controls are routine enough to sound boring, which is part of their value.
They give a newsroom or court a stable object to inspect, and they give a congressional office or future reader a documented change history to follow. The authenticity argument can then begin with the file rather than with speculation about the survivor.
Forensic restraint can protect a survivor by refusing to make the document chain carry more than it can support. Restoring a page to the correct file family is useful even when the larger allegation remains unresolved, because the document question can then be separated from the merits and tested against collateral records, witness accounts, investigative follow-up, and other evidence. The survivor no longer has to carry a records-management dispute the custodian should have been able to answer. A technical investigation can make that correction without pretending to resolve the human story inside the file.
Amy Gabrielle's role in the chronology shows what useful skepticism looks like when it stays testable. She surfaced important material publicly, remained cautious about authentication, and later questioned the appearance of the #349 typography on -002. I took that concern back to the files, recovered the known overlay geometry from -004 and -006, and tested whether -002 actually behaved differently. The measurement weakened the hypothesis once the pages were modeled directly, which is a productive result because a skeptical question does not lose value when the evidence answers it in an unexpected direction.
Ellie Leonard's public sequence presents a different accountability problem because the change in description carries much larger implications than the explanation presently attached to it. Leonard had spent months covering Jane Doe Four and had publicly described verification in practical terms that included finding the file number and doing the homework. One episode description then called the new material leaked FBI handwritten notes; a later update pulled the material, restarted verification, and warned that it might be part of a disinformation campaign. Those positions can coexist if new evidence appeared between them. The public record I could freeze does not identify what that evidence was.
Pulling material while survivor privacy or provenance is being checked can be responsible editorial conduct, and a later technical defect could justify a substantial correction. The problem is that the audience can see the reversal without seeing the bridge. The update identifies no incompatible government record, source admission, altered page, failed sequence, handwriting contradiction, or other reproducible technical finding. It leaves readers with the seriousness of the phrase 'disinformation campaign' and very little information about the test that produced it.
The first verification steps were ordinary reporting work that could be done before any specialized forensic analysis began. They did not require handwriting software, a confidential source, or access to a laboratory.
A reporter could locate the Maxwell index, compare the neighboring 302s, calculate the missing intervals, open the surviving PDFs, and see whether their visible layers belonged to the same processing stage. The typography concern could also be modeled directly from -004 and -006, while the more specialized work came later to test how much confidence those basic checks deserved.
I am not assigning a motive to Leonard's reversal, and I am not treating caution as misconduct. The accountability question is narrower and more useful: what evidence changed between an assertive leaked-FBI-notes description and a warning that the same material might belong to a disinformation campaign? A technical discovery could justify the change; a precautionary privacy decision could justify temporary restraint; a source problem could justify both. Readers should be able to tell which kind of decision they were being asked to understand, especially when the new characterization can make every reporter working from the same pages appear suspect.
The anonymous -002 uploader deserves the same scrutiny from the opposite direction. The frozen public record preserves the claim that the source was 'the DOJ itself' and that authenticity had been confirmed, while the source PDF, original filename, hash, reproducible Justice.gov route, and authentication method remain absent. A confidential human source can have a legitimate reason to stay unnamed. Non-identifying technical receipts could still show what was compared and how the authentication claim was reached without exposing that source.
The standard should remain the same whether a claim points toward authenticity or suspicion. Public confidence should rise only as far as the evidence shown, and a later change should leave enough of a trail for readers to understand why it happened.
Reporters need room to correct themselves without forcing the audience to choose between personalities. Survivor-related records need that discipline even more because somebody else's certainty can become part of the survivor's public biography long after the original interview ends.
The remaining uncertainty is specific enough for congressional oversight rather than another open-ended internet argument. Properly redacted official copies of 3501.045-002, -004, and -006 could be compared page for page with the circulating material. Non-sensitive production records could show when the notes were processed, which versions were released, whether later files replaced earlier ones, and which material redactions changed. If #349 belongs to a court, vendor, litigation-support system, or agency workflow, a simple identification of that namespace could resolve one of the most persistent public questions without disclosing a single survivor detail.
Congress does not have to decide whether the allegations inside the notes are true before requesting the records needed for oversight. Official redacted note copies, release and replacement logs, version history, preserved hashes, and file-level redaction transactions would let investigators examine the release system without turning a committee into a credibility tribunal for the survivor. That distinction is important because the public interest here includes both completeness and restraint. A government can protect a victim and still preserve enough technical history to show what it changed.
The same standard would improve future survivor-related releases because privacy and auditability do not have to be enemies. A redacted page can retain stable dimensions, non-identifying production marks, a durable public identifier, and a documented relationship to earlier versions.
Those features give reporters and lawyers a way to detect change without exposing the person behind the redaction. They also let a later derivative be recognized as a derivative before the difference mutates into a theory about fabrication, concealment, or the survivor herself.
The problem extends beyond the Epstein releases because public document libraries become working evidence almost as soon as files appear. Newsrooms cite them, congressional offices inspect them, litigants compare them, researchers archive them, and social platforms copy them faster than later corrections can travel. When a releasing institution silently replaces a file or provides no durable version history, everybody downstream becomes an accidental records examiner. The public ends up reconstructing government recordkeeping from cached copies and screenshots when the government could have preserved the answer at the moment of release.
The conclusion is specific enough to have specific failure conditions. An official note set that does not correspond to the circulating pages would overturn it, as would a recovered source file showing a later manufactured internal layer the current tests cannot see. A custody record demonstrating after-the-fact assembly, a source admission, or a reproducible defect that explains the convergence more simply would also require correction. I want those conditions visible because an investigation that cannot explain how it could be wrong is asking for faith rather than scrutiny.
The original -002 PDF remains the most important missing private-side object because its filename, byte size, hash, internal structure, and non-identifying custody history could move that set closer to -004/-006 or expose a defect hidden by the JPEG derivatives. The official DOJ copies remain the stronger public benchmark, which is why -002 stays one level less certain until either the source PDF or the official comparison record can be examined.
Even if every other test becomes more persuasive, that unresolved gap cannot be edited out of the conclusion. A later recovery of the source PDF could strengthen this article or force a correction, and both outcomes belong in the design of the investigation.
The most useful outcome would make part of this investigation obsolete. DOJ could release the official redacted notes with enough version history for an independent comparison, and Congress could preserve the transaction history around later file changes. Reporters would then have an official benchmark instead of relying on an anonymous upload, a podcast description, or my reconstruction. The survivor would no longer have to absorb suspicion generated by a release system that left outsiders arguing over copies the custodian could compare directly.
Thirty-seven pages cannot answer every question people have attached to Jane Doe Four, and I cannot create a missing custody record by writing around it. What this investigation can leave behind is a verification path another person can reproduce, a set of failure conditions that make correction possible, and a concrete request for the records capable of settling the remaining dispute.
DOJ holds the benchmark that could resolve the document question without exposing the survivor, while Congress has an oversight reason to ask how these versions were handled. If those records are eventually produced, the strongest outcome will not be that this article was vindicated; it will be that the next reporter, lawyer, survivor, and reader no longer has to rebuild a government file from fragments to know what the government actually released.
Primary records used in this investigation include the Maxwell non-testifying witness-material index at EFTA00095751, Judge Sullivan's June 25, 2026 order, official 3501.045 FD-302 records including EFTA01245620 and later comparator reports, the preserved circulating -004 and -006 binaries, all fifteen -002 JPEG copies, and the Serial 159 / 1A27 crosswalk materials. The technical findings are documented in the locked Passes 103-119 forensic branch and the five-pass HAT reports, with source hashes and test outputs preserved in the publication package. Public-reporting chronology is attributed to the preserved posts, episode descriptions, and contemporaneous captures used in the reporting audit. Nothing in this source apparatus changes the central limitation: the original -002 PDF and an official redacted benchmark for the circulating notes remain unavailable in the evidence set used here.