Skip to content
files.co

You sent the signed form. The person who got it can still change the numbers

A filled PDF form stays editable after you send it, and an altered copy looks exactly as legitimate as yours. Flattening turns a form with answers in it into a document.

AGAntonia González · August 9, 2026 · 5 min read

The paperwork is done. You downloaded the form, typed in the figures, dropped your signature into the box at the bottom, saved it, attached it to an email and sent it off. From your side that file is finished.

From the other side it’s a form with your answers loaded into it. The recipient opens it, clicks into the box where you wrote the amount, deletes it and writes another one. Saves. Now there’s a copy of your document in the world with a different number in it, your signature still sitting underneath, and nothing about it that looks tampered with. Same fonts, same layout, same everything.

Files.co now has Flatten PDF for the step that closes this. It presses your answers into the page so they stop being fields somebody can type over.

Why a filled form stays editable

The values you typed aren’t written into the document the way the printed labels are. They live in a separate layer of interactive fields sitting on top of the page — the same layer that made the boxes clickable when you were filling them in. Saving the file doesn’t dismantle that layer. It saves it, with your answers inside.

So the file that arrives is still, structurally, a blank form plus a set of values. Any PDF editor, and plenty of free viewers, will let the next person edit those values. They don’t need to hack anything or know anything. They click the box and type.

This is fine, and even useful, while a document is still moving between people. It stops being fine the moment the document is supposed to be a record of what was agreed.

Where it actually bites

  • Anything with an amount on it. Invoices, expense claims, quotes, purchase orders. The number is the whole document, and the number is a text field.
  • Signed paperwork. A drawn or placed signature that’s still a form field can be deleted as easily as it was added, and moved onto a different version of the page.
  • Forms you send back to an organisation. Consent forms, applications, declarations. If it matters what you declared, it matters that what you declared can’t be quietly adjusted afterwards.
  • Anything that gets forwarded. Documents rarely stop at the first recipient. Each hop is another editor with the file open.

None of this means people are out to defraud you. Most edits to a sent form are somebody being helpful — correcting what they think is a typo, updating a date. The problem is the same either way: the version on file no longer matches the version you approved, and there’s no visible difference between them.

What flattening does about it

It takes what each field currently draws on the page — the text, at its font and size and position, the checkbox tick, the signature image — and writes that drawing into the page itself. Then it removes the field.

The document looks identical afterwards. It’s the same drawing; it just lives in the page now rather than in a layer floating above it. What’s gone is the box you could click into. Open the flattened copy in any editor and there’s nothing to type in, because there’s no longer a field there to hold a value.

You get two switches, and they’re separate on purpose:

  • Form fields — everything you filled in.
  • Annotations — comments, highlights, sticky notes, stamps, drawn marks.

Plenty of documents need one and not the other. A contract that went through internal review might need the comments gone but the fields left alive for the other party to complete. A finished expense claim needs the opposite. Before it runs, the tool counts what it found in your file and tells you, so you’re not guessing.

Links are technically part of the same annotation layer, and the tool deliberately leaves every one of them alone. A link draws nothing — the blue underlined text is already page content, and the link is just a clickable rectangle over it. Flattening it would change nothing visible and break the click. Cross-references, tables of contents, the “see annex B” that jumps to annex B: all of it would keep looking right and stop working.

So links are counted and kept, and the summary tells you how many.

The honest limits

It doesn’t undo. Once your answers are part of the page, they can’t be typed over again, by the recipient or by you. Flatten at the end, not in the middle. Your original file isn’t modified — you get a flattened copy, and the version you started from stays exactly where it was.

Some fields can’t be flattened. Malformed PDFs are common, and a field whose stored appearance is missing or broken can’t have its drawing moved anywhere, because there’s no drawing to move. The tool flattens everything it can and then tells you, by name, which fields it couldn’t — so you know those specific boxes are still editable in the copy you’re about to send. The alternative, staying quiet about it, would hand you a file you’d wrongly believe was locked.

XFA forms are left alone. Those are the XML-based ones some public administrations still issue, the ones that show a “please open in Adobe Acrobat” page in every other viewer. They don’t use the standard field structure, so they aren’t touched.

Where it fits in the routine

Fill the form, check it, sign it, flatten it, send it. Flattening is the step that converts a form with answers written on it into a document, and it’s the difference between sending a record and sending an editable draft with your name at the bottom.

If you’re still at the filling-in stage, the PDF form filler handles that part, and there’s a longer explainer on how PDF form fields work and why XFA is a problem. Both run in your browser, like this one — the document never leaves your machine on its way to becoming final.

Explore by category