KYC and onboarding

Prove the capture came from a real camera, not a real-looking file

Deepfake selfies and injected camera feeds defeat liveness checks that only look at pixels. The defence is not a better classifier. It is knowing that the frame arrived from a physical sensor at all.

The problem

Liveness checks the pixels, not the pipeline

ATTACK

Virtual cameras are a download

Software that presents a video file to any app as though it were the camera is free and takes minutes to install. A liveness check downstream of it is examining the attacker's chosen frames.

ATTACK

Screen replay is simpler still

Holding a phone up to a monitor defeats a surprising number of systems, and requires no technical skill at all.

COST

False rejects are expensive

Every honest applicant a liveness check turns away is a customer lost at the most expensive point in the funnel.

How CapSeal applies

Move the trust decision to the moment of capture

PIPELINE

Where the frame came from

CapSeal checks the frame carries the metadata the operating system attaches to buffers that genuinely came off the sensor - camera intrinsics, sensor timestamps - which an injected surface has to fabricate consistently and usually does not.

SCENE

Whether a real scene was there

Multi-frame parallax cross-checked against the device's own motion sensors. A screen and a printout are flat, and a flat subject cannot produce scene-consistent parallax.

DEVICE

Whether the device is genuine

Play Integrity and App Attest, bound into the manifest. That judgement comes from Google and Apple, not from us, and you can check it yourself.

What this does not do

Where the evidence stops

CapSeal establishes that a selfie or document capture came from a physical camera pointed at a physical scene, on a device the platform vouches for.

  • It does not perform face matching or identity resolution. It establishes that a capture is real, not whose face is in it.
  • It does not detect a deepfake presented to a genuine camera from a high-quality display in ideal conditions with certainty - it raises the cost substantially and records what it measured.
  • Rooted and jailbroken devices are reported, not blocked. Plenty of honest people run them.

The full position is in the Product Disclosure. We would rather you knew the boundary before you bought than after.

Integration

Three things to wire up

  1. Capture Drop the iOS or Android SDK into the flow your users already complete. Our capture-integrity engine measures the scene on the device and seals the result before it leaves the handset.
  2. Verify One authenticated call at intake returns a verdict, a basis and a proof object. See the SDK.
  3. Route Automate on proven and declared. Send everything else to a human with the report attached.

Try the verification half right now, with no signup, at capseal.ai/check.

Block synthetic onboarding without punishing real customers.

Drop the capture SDK into your existing flow and keep your current liveness vendor.

Book a pilot Check a file first