See through the synthetic.
VERIFAi is the trust layer for the post-authentic internet. Eleven forensic signals - from cardiac liveness in the pixels to micro-expression, voice and physics forensics, cryptographic evidence and a federated threat ledger - engineered to give banks a defensible answer to AI-generated video.
Two minutes. The whole thesis.
Who we are, why we exist, and the frontier approach we've taken to deliver the most accurate synthetic-video detection available anywhere in the world.

Anyone can be anyone now.
Generative video quality doubled in eighteen months. Voice cloning of relationship managers, video impersonation of HNW clients on video-KYC, pre-recorded "proof of life" clips authorising eight-figure transfers - all bypass controls built for document forgery and card-not-present fraud.

Eleven detectors. One verdict. Every piece of evidence attached.
Single detectors are bypassable. Eleven orthogonal signals - five foundational and six frontier - weighted, calibrated with Bayesian fusion, and cryptographically bound to an audit chain, are not.
Vision models inspect sampled frames for warping, texture inconsistency and generative fingerprints.
Cross-frame motion, identity drift and unnatural stability characteristic of synthesised video.
Phoneme-viseme alignment plus prosody, spectral and codec-artifact analysis of the voice track.
Container metadata, codec fingerprint, re-encoding markers and signed content credentials.
Double-encoding, GOP tampering, bitrate anomalies and missing sensor pattern typical of synthetic renders.
Every high-risk verdict routes to an analyst with a full evidence trail and tamper-evident audit log.
First-of-kind in banking.
Not on any competitor's roadmap.
Where legacy vendors ship a single classifier and hope, VerifAI ships a stack that verifies the physics of the person on the other end of the camera - and then hands you mathematical proof of the decision.
We detect a heartbeat in the pixels themselves. Skin-chroma oscillations between 0.7 and 3 Hz - present in humans, absent in generators.
Catchlight geometry, shadow agreement, saccade micro-timing. Physical laws the best generators still get wrong.
Perceptual hashes of confirmed synthetic clips shared, anonymously, across every subscriber. One catch protects all.
Nightly, the head of your tamper-evident audit chain is anchored to OpenTimestamps. History becomes provably immutable.
Every evidence PDF is signed and offline-verifiable against a public JWK. Byte-level proof it left our system unaltered.
We publish our own red-team accuracy in-product, refreshed continuously. Our numbers are yours to audit.

Not another video checker.
Every incumbent covers a slice. VerifAI is the only stack that runs a full 17-signal ensemble, signs its own evidence, and closes the loop with analyst review, federated intel and continuous learning.
| Detection depth | Evidence and trust | Operating model | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Category | Multi-signal ensemble | Cardiac liveness (rPPG) | Physics / optics forensics | Voice + prosody forensics | Signed evidence PDFs | Tamper-evident audit chain | Publicly verifiable receipts | Analyst review workflow | Federated cross-org intel | Continuous learning |
| Liveness / anti-spoof vendors | Presentation-attack only | |||||||||
| Document-KYC platforms | Doc-level only | Case log | KYC ops | |||||||
| Point deepfake classifiers | Single model | |||||||||
| In-house analyst review | Ticket trail | Human judgement | Tribal knowledge | |||||||
| VerifAI | 17 detectors | 0.7-3 Hz chroma | Catchlight + saccade | Prosody + micro-breath | Ed25519 + JWK | SHA-256 + OTS | Offline-verifiable | Queue + override | Perceptual-hash ledger | EMA re-weighting |
A full fraud-desk loop, not a black-box API.
- Analyst dashboardQueue, review, override. Signal breakdowns, confidence, timestamps, threat-intel matches.
- Public REST APISynchronous verdicts. Per-key rate limits and monthly quotas. Signed receipts.
- Evidence PDFsAsync-rendered, watermarked, Ed25519-signed, publicly verifiable.
- Tamper-evident auditEvery upload, verdict, override and download chained by SHA-256 and anchored to OTS.


Built to survive the procurement review, not just the demo.
Our security posture, certification roadmap and the evidence artefacts your risk, audit and regulatory teams will request - all in one place.
- Encrypted at rest (AES-256) and in transit (TLS 1.3).
- Regional data residency (EU / UK / US).
- Private storage buckets; signed short-TTL download URLs only.
- Watermarked, per-recipient traced evidence PDFs.
- Per-organisation tenancy with Postgres RLS enforced on every row.
- SSO / SAML on request; MFA for analysts by default.
- Least-privilege service roles; secrets rotated on 90-day cycle.
- Every action logged to a hash-chained, tamper-evident audit log.
- Every evidence PDF Ed25519-signed and offline-verifiable.
- Daily audit-chain head anchored to OpenTimestamps.
- Public /api/public/v1/verify-pdf endpoint for third parties.
- Published, refreshed red-team benchmark.
Every framework banks ask for, tracked with evidence bindings and open gaps.
Full readiness portalHow we exceed: Every trust-service criterion is backed by a cryptographic artefact (Ed25519 signatures, hash-chained audit_log, OTS anchor), not just a policy PDF.
How we exceed: Continuous evidence: every scan, verdict override and key rotation is chain-hashed and externally anchorable, so operating effectiveness is provable per-event, not per-quarter.
How we exceed: A.8.28 secure coding, A.8.16 monitoring and A.5.28 evidence collection are met with cryptographic proof (signed artefacts + hash chain) rather than screenshot evidence.
How we exceed: Model cards, red-team results and calibration methodology are published per detector - plus we ship model-risk artefacts (SS1/23-style) most AI vendors won't touch until 2028.
How we exceed: MEASURE 2.7 (red teaming) and MANAGE 2.4 (post-deployment monitoring) both operational today: hash-chained security_events + benchmark_runs prove drift management per scan.
How we exceed: Article 9 (protection & prevention) and Article 17 (incident reporting) met via SHIELD L15 kill-switch + chain-verifiable incident ledger - regulators can independently verify our reports.
How we exceed: We ship the model-risk pack banks would normally have to build themselves: tiering, independent validation, calibration methodology and per-verdict evidence bundle.
How we exceed: Art. 32 security of processing is exceeded via cryptographic tamper-evidence; Art. 30 records of processing are auto-generated from audit_log.
How we exceed: All five control themes already met by SHIELD + MDM baseline; certification is a scheduling exercise, not a build.
How we exceed: We both verify inbound C2PA and emit our own signed provenance manifests per evidence bundle - unique among detection vendors.
How we exceed: Scope minimisation is a security posture. We publish a signed attestation that no PAN, CVV or track data ever enters our systems.
Full register (with sensitive items) available under NDA via the compliance portal.
What banks can ask us for under NDA

The full deck, whitepaper and commercial model.
Access is password protected and handed off to our team. Each document is watermarked to the recipient and cryptographically signed. Ask your VerifAI contact for the access code.
In the age of synthetic media,
trust needs infrastructure.
We built VerifAI so a bank never again has to ask, "was that really our customer on the call?" The answer, signed, timestamped and independently verifiable, arrives in seconds.


