Mighty
Why MightyCitadel
Use cases
LendingIncome files before you fundInsuranceAppraisals to claim photosClaimsPhotos and estimates at first noticeAll use cases
SecurityDocsLog in
See it on your files

Docs

Direct SaaS purchase is no longer offered

New commercial terms are enterprise or custom, scoped on a call.

See it on your files
Browse docs
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Loading docs…
Mighty

Citadel is Mighty's product. It finds generated or AI-edited fakes in customer files.

See it on your files

Platform

  • For Lending
  • For Insurance
  • For Claims
  • Product
  • Use Cases
  • Contact
  • Docs

Company

  • Why Mighty
  • Blog

Trust

  • Security
  • Status
  • Privacy
  • Terms
© 2026 Nine Suns Inc. All rights reserved.Citadel, from Mighty

Choose Scan Settings

Pick content type, phase, mode, focus, profile, and data sensitivity from real product examples.

Citadel inspects anything before your product trusts it: user input, generated output, uploads, OCR text, image evidence, PDF evidence, office documents, and agent tool output.

Start with the thing your product is about to trust. Then choose the settings that match that story.

For definitions of focus, AI edits, steganography, prompt injection, and related terms, see the glossary.

Start With The Thing You Are About To Trust

Use this table first. It shows the setting combinations that should be copied into real integrations.

ScenarioUse these settingsWhy
User prompt before AIcontent_type=text, scan_phase=input, mode=secure, focus=stegFinds text trying to override rules, steer the model, reveal secrets, or hide unsafe instructions.
OCR text before automationcontent_type=text, scan_phase=input, mode=secure, focus=steg, data_sensitivity=tolerantOCR can expose hidden or altered text. Tolerant mode avoids blocking normal names, addresses, claim IDs, and invoice details.
Public AI answercontent_type=text, scan_phase=output, mode=secure, focus=steg, profile=ai_safety, data_sensitivity=strictChecks generated output before users see leaks, unsafe text, or policy-breaking content.
Internal AI summarycontent_type=text, scan_phase=output, focus=steg, data_sensitivity=tolerantLets normal business PII exist in internal notes while still catching unsafe generated output.
Mixed file uploadcontent_type=auto, scan_phase=input, mode=secure, focus=stegSafest default before storage, OCR, indexing, or AI extraction.
Office documentcontent_type=document, focus=stegRuns parser-safe container and extracted-text safety checks. Image/PDF authenticity, edit localization, and reference comparison are not claimed for structured Office files.
Image authenticity reviewcontent_type=image, scan_phase=input, mode=secure, focus=aiUse when the main question is whether visual evidence looks AI-generated, AI-edited, reposted, or provenance-backed.
Image edit reviewcontent_type=image, scan_phase=input, mode=secure, focus=editsRuns without a reference; optionally add a same-modality reference_file=@original.jpg for pairwise corroboration.
PDF edit reviewcontent_type=pdf, scan_phase=input, mode=secure, focus=editsRuns without a reference; optionally add a same-modality reference_file=@original.pdf for pairwise corroboration.
Full image/PDF evidence reviewcontent_type=image or pdf, focus=allUse when hidden content, authenticity, and edit evidence all matter.
High-value image/PDF reviewmode=comprehensive, async=true, focus=allUse when latency is acceptable and the result affects money, safety, account trust, or legal review.

Safe Default

If you are unsure, start here:

{
  "content_type": "auto",
  "scan_phase": "input",
  "mode": "secure",
  "focus": "steg",
  "profile": "balanced",
  "data_sensitivity": "standard"
}

This says: "A user or upstream system submitted something, Citadel should inspect it with the normal production path, and normal product policy should decide what happens next."

Change the defaults only when the workflow needs it:

  • Use data_sensitivity=tolerant when the text normally contains names, addresses, claim IDs, policy numbers, invoice lines, or contact details.
  • Use profile=ai_safety and data_sensitivity=strict for public AI output.
  • Use focus=ai, focus=edits, or focus=all only for supported image/PDF evidence paths.
  • Use mode=comprehensive and async=true for high-value image/PDF review where waiting is acceptable.

Input Inspection

Input inspection means the material came from a user, customer, claimant, vendor, partner, upload, browser, or upstream system.

Examples:

What came inSettingsWhat Citadel looks for
Chat prompt or form fieldcontent_type=text, scan_phase=input, focus=stegPrompt injection, content steering, secrets, unsafe instructions, and hidden text patterns.
Uploaded PDF, image, or document before storagecontent_type=auto, scan_phase=input, focus=stegHidden content, suspicious text, visual prompt injection, unsafe file text, and parser-safe extraction risk.
Office documentcontent_type=document, scan_phase=input, focus=stegParser-safe container, active-content, hidden-text, and extracted-text safety inspection without claiming image/PDF authenticity or edit-localization support.
Damage photo or receipt photocontent_type=image, scan_phase=input, focus=allHidden content, AI authenticity evidence, and localized edit evidence together.
Known image authenticity reviewcontent_type=image, scan_phase=input, focus=aiWhether the visual evidence appears AI-generated, AI-edited, reposted, provenance-backed, or visually inconsistent.
Submitted image or PDFcontent_type=image or pdf, scan_phase=input, focus=editsStandalone localized edit review, with optional same-modality reference_file corroboration when a source is available.

For browser or API uploads, see Scan File Uploads. For visual evidence, see Damage Photo AI Fraud Review.

Output Inspection

Output inspection means your system generated the material: a model answer, OCR text, extraction result, AI summary, agent tool result, generated recommendation, or public response.

Scan output before users, models, tools, or workflow automation act on it.

{
  "content": "Generated answer shown to a user",
  "content_type": "text",
  "scan_phase": "output",
  "mode": "secure",
  "focus": "steg",
  "profile": "ai_safety",
  "data_sensitivity": "strict"
}

Use the scan_group_id from the related input scan. That keeps the prompt, upload, OCR output, model answer, and review record connected.

OutputSettingsWhy
Public assistant answerscan_phase=output, focus=steg, profile=ai_safety, data_sensitivity=strictCatches unsafe generated text, secret leakage, and policy-breaking output before users see it.
Internal claim or invoice summaryscan_phase=output, focus=steg, data_sensitivity=tolerantNormal business PII can remain in reviewer-only notes while unsafe output still gets routed.
OCR text or extracted fieldscontent_type=text, scan_phase=input, focus=steg, data_sensitivity=tolerantOCR output is derived, but it is still untrusted input to your automation.
Agent tool outputscan_phase=output, focus=steg, profile=ai_safety or code_assistantKeeps unsafe tool results, retrieved text, and browser content out of the next model step.

For generated responses, see Scan Model Output. For multi-step evidence chains, see Sessions And Scan Groups.

Focus Modes Without Jargon

focus answers: what kind of risk or evidence should Citadel prioritize?

FocusPlain meaningUse it forDo not use it for
stegHidden content, prompt injection, content steering, unsafe text, OCR/document safety.Text, OCR text, model output, mixed uploads, office documents, AI-facing uploads.AI-authenticity-only review or pairwise image/PDF comparison.
aiIs this visual evidence likely generated, AI-edited, reposted, or missing useful provenance?Damage photos, receipt photos, marketplace listing images, ID or verification images, and screenshot/PDF evidence where authenticity is the main question.Text, OCR text, model output, structured Office documents, or anything where hidden instructions could reach an AI system unless paired via focus=all on supported image/PDF evidence.
editsWhat changed, and where does the submitted image or PDF look manipulated?Standalone image/PDF edit review, with optional same-modality source corroboration for damage photos, labels, receipts, package photos, food photos, screenshots, and document images.Text/OCR/model output, structured Office documents, or general hidden-instruction safety scans.
allRun threat, authenticity, and edit evidence paths for supported image/PDF evidence. Image units bill 12 SCU for all three image paths.Image/PDF evidence where hidden content, authenticity, and edit evidence all matter.Structured Office documents; use focus=steg for their safe container/text path.

Default value: steg. One focused image path bills 4 SCU per image; selecting two evidence paths (e.g. focus=steg,ai) bills 8 SCU per image unit; focus=all (all three paths) bills 12 SCU per image unit (4 SCU × 3 paths). Deprecated aliases still exist: standard maps to steg, and both maps to all.

Use focus=steg for Office and structured documents. Other canonical focus values remain accepted for compatibility, but only supported parser-safe container and extracted-text safety checks run; document_integrity.unsupported_surfaces lists visual capabilities that did not run. These files do not gain image/PDF authenticity, localized edit masks, or reference-aware comparison support.

For the technical compatibility table, see POST /v1/scan focus compatibility.

When focus=ai Is Useful

Ask: "Is this visual evidence likely generated, AI-edited, reposted, or missing useful provenance?"

Use focus=ai when authenticity is the main question and you already know the material is image/PDF evidence.

curl -X POST https://gateway.trymighty.ai/v1/scan \
  -H "Authorization: Bearer $MIGHTY_API_KEY" \
  -F "file=@./receipt-photo.jpg" \
  -F "content_type=image" \
  -F "scan_phase=input" \
  -F "mode=secure" \
  -F "focus=ai" \
  -F "profile=strict"

This is review evidence, not proof of fraud. Use focus=all instead when the same image/PDF may also contain hidden instructions or unsafe text.

When focus=edits Is Useful

Ask: "What changed, and where does the submitted image or PDF look manipulated?"

A reference is optional corroboration and is never required. When a trusted source is available, send a same-modality image or PDF with reference_file for pairwise comparison. Without one, the standalone path still runs.

curl -X POST https://gateway.trymighty.ai/v1/scan \
  -H "Authorization: Bearer $MIGHTY_API_KEY" \
  -F "file=@./submitted-damage-photo.jpg" \
  -F "reference_file=@./original-damage-photo.jpg" \
  -F "content_type=image" \
  -F "scan_phase=input" \
  -F "mode=secure" \
  -F "focus=edits" \
  -F "profile=strict"

Without a reference, Citadel runs conservative standalone image or PDF analysis. Use focus=all when you also need hidden-content or AI-authenticity review. Structured Office documents do not support this reference-aware edit-localization path.

Mode, Profile, And Data Sensitivity

These settings are separate from focus.

SettingPlain questionDefaultChange it when
modeHow deep should Citadel look?secureUse fast for low-risk low-latency text. Use comprehensive for high-value image/PDF review and async scans.
profileHow strict is this workflow?balancedUse strict for regulated, financial, legal, insurance, healthcare, or high-value workflows. Use ai_safety for public AI output.
data_sensitivityShould normal PII be expected?standardUse tolerant for claims, invoices, healthcare, identity, or support workflows. Use strict for public output, secrets, and credentials.

Mode is not tolerance. mode changes how deep the inspection goes. profile, data_sensitivity, and your routing policy decide how strict the product is after Citadel returns a result. See Modes And Tolerance.

Content Types

content_type answers: what kind of thing is this?

ValueUse when
autoYour server does not know the type yet, or the upload route accepts mixed files.
textChat text, form fields, OCR text, extracted fields, model output, tool output, notes, or transcripts.
imageDamage photos, ID images, receipt photos, screenshots, marketplace images, or visual evidence.
pdfPDF claim packets, invoices, estimates, forms, statements, or evidence packets.
documentOffice or structured documents such as DOCX, XLSX, PPTX, CSV, Markdown, JSON, XML, HTML, RTF, and similar business files.

If a PDF contains images, still send it as pdf. If an OCR system extracted text from a PDF, scan that extracted text as content_type=text and reuse the same scan_group_id.

IDs And Review

Store these fields so your reviewers and logs can explain what happened:

FieldUse it for
request_idOne unique request. Use it for retries and logs.
scan_idThe exact Citadel result. Use it for audit and async polling.
scan_group_idConnect original input, OCR text, model output, image evidence, and review for one item.
session_idConnect the wider chat, claim, case, batch, or agent run.

Route results in product language:

ActionProduct route
ALLOWContinue. Store IDs.
WARNReview, add friction, constrain the model/tool path, or request more evidence.
BLOCKStop the workflow, or show redacted_output when Citadel returns it and your policy allows it.

Common Wrong Choices

  • Using focus=all for normal text, OCR text, or model output. Use focus=steg.
  • Using focus=ai as a fraud verdict. Citadel flags review evidence; your business process decides fraud.
  • Treating a reference as required for focus=edits. Image and PDF scans run without one; a same-modality reference_file adds optional corroboration only.
  • Treating accepted document focus values as proof that every visual surface ran. Check document_integrity.unsupported_surfaces; structured documents never fabricate non-applicable provenance or edit masks.
  • Using mode=fast because a workflow should be tolerant. Use data_sensitivity=tolerant for expected PII.
  • Scanning only OCR text when the original file is available. Scan the file first, then scan extracted text with the same scan_group_id.
Next step

Ready to scan real traffic?

Book a working session on your files. Starting October 1, 2026, new commercial terms are enterprise or custom.

See workflow recipesChoose by material
Related docs

Keep going from here

Modes And ToleranceSeparate depth from strictness.GlossaryDefine focus, steg, AI edits, and prompts.Multimodal SupportChoose by material type.Workflow PlaybooksApply settings in real flows.

On this page

Start With The Thing You Are About To TrustSafe DefaultInput InspectionOutput InspectionFocus Modes Without JargonWhen focus=ai Is UsefulWhen focus=edits Is UsefulMode, Profile, And Data SensitivityContent TypesIDs And ReviewCommon Wrong Choices