Data handling
- Every uploaded video is stored in a private, org-scoped object storage bucket. Only signed URLs are ever served.
- Row-level security scopes every database read to the requester's organization. Cross-tenant reads are impossible at the database layer.
- API keys are hashed at rest. The full key value is shown once at creation and never again.
- All privileged actions (verdict overrides, key creation, membership changes) are written to an immutable audit log.
What our detectors do well
- Catch commodity face-swap and lip-sync tools - most published deepfake generators leave detectable frame or temporal artifacts.
- Flag re-encoded or metadata-stripped video, which is a strong prior for tampering in KYC contexts.
- Verify signed content credentials (C2PA) when present.
What we can't guarantee
- A state-of-the-art bespoke generator, given enough compute and no time pressure, can defeat any single detector we run - including ours. That's why we run six.
- Very short (<3s) or very low-quality clips give any detector less signal to work with. Confidence bands reflect this.
- Live-stream detection is out of scope in v1; VerifAI targets pre-recorded video.
How to use it well
Treat VerifAI as one control in a defense-in-depth stack: pair it with liveness challenges, device signals, transaction risk scoring, and - for anything high-value - a trained human reviewer looking at the evidence page we produce.
Frameworks we're built to exceed
The certification programme runs in the open. Every framework below is tracked with evidence bindings back to real platform artefacts, and gaps are published with owner and due date on the compliance portal.
Frameworks tracked
11
Average readiness
90%
Live today
3
Tracked open gaps
14
SOC
AICPA
SOC 2 Type I
Q1 202759/64 controls
92% ready2 open gaps
SOC
AICPA
SOC 2 Type II
Q3 202747/64 controls
74% ready1 open gap
27K
ISO/IEC
ISO/IEC 27001:2022
Q2 202782/93 controls
88% ready3 open gaps
42K
ISO/IEC
ISO/IEC 42001:2023 - AI Management
Q2 202731/38 controls
81% ready2 open gaps
AI
NIST
NIST AI RMF 1.0 + CSF 2.0
Continuous69/72 controls
95% ready1 open gap
DORA
EU
DORA (Regulation 2022/2554)
Q3 202735/41 controls
86% ready2 open gaps
MRM
UK
FCA SS1/23 + PRA SS2/21 (Model Risk)
Q4 202620/22 controls
90% ready1 open gap
GDPR
EU/UK
GDPR / UK GDPR + DPA 2018
Continuous32/33 controls
96% ready1 open gap
CE+
NCSC
Cyber Essentials Plus
Q4 202624/25 controls
94% ready1 open gap
C2PA
C2PA
C2PA / CAI conformance
Continuous14/14 controls
97% readyno open gaps
PCI
PCI SSC
PCI DSS v4.0 (scoped-out)
N/A0/- controls
100% readyno open gaps
