Old implementation used Encoding.ASCII.GetString() which:
- Corrupts binary PDF bytes 0x80-0xFF -> '?' (false negatives)
- Matches '/Encrypt' anywhere in document content (false positives)
- Matches '/Encrypted', '/EncryptionKey' etc. (token boundary not checked)
New implementation uses ReadOnlySpan<byte> with three strategies:
1. Search last 2KB (trailer region) - fast path, covers standard PDFs
2. Search first 2KB (linearized PDFs have duplicate trailer at start)
3. Full-file fallback for PDF 1.5+ compressed xref streams, with token
boundary check (next byte must be space/newline/tab/'<'/'/'/'[')
to avoid matching '/Encrypted' or '/EncryptionKey'
Also: DevExpressPdfProcessor.ValidateAsync now returns PdfValidationResult
directly (no more PdfMetadata wrapper), includes IsEncrypted field.