When does a verification call end?
When the last app using your camera lets go of it, Witness stops showing your picture. The call is held for ten minutes, then shown as ended; your next call has a new code. An overlapping handover between apps is not a camera break. If your camera stays on, Witness pauses to ask whether you are still on the same call at least every hour. Witness cannot see who is in your meeting.
What is kept after a call?
You need an account to start a call. Call records are sealed on disk, with an expiry rounded up to the hour, and their keys are destroyed after the retention period. A server restart needs the sender's Mac to unlock them; while waiting, the page says reconnecting. A backup of the sender's Mac made while a key existed may retain that key. Receipts saved by viewers or filed for a sponsor, members' last-call times and account-level action rows stay readable. See the privacy page for the deadlines and backup limits. Rooms are off.
What does Witness actually prove?
That the video on your call is coming from a real, physical camera, and that the camera was enrolled by a specific passport-verified person. It reads the sensor's own fingerprint, not the content of the picture, and the other person's browser checks it independently.
Is this deepfake detection?
No, and that is deliberate. Detectors study the pixels and guess whether they look fake, which is a race they lose a little more with every new model. Witness never looks at the pixels. It proves where the video came from, so a perfect fake from software that is not your enrolled camera still fails.
Can't someone point the enrolled camera at a screen playing a deepfake?
They would need your specific enrolled camera in their hands. Any other camera fails the fingerprint check at once, so this stops being a remote attack and becomes physical possession of your hardware. For high-value approvals the person is re-checked with a movement challenge at setup, which a screen cannot pass.
What if the computer is compromised and malware injects video?
There is no software inlet to inject into. The camera runs inside a signed, sandboxed system extension that opens the hardware itself, with no stream any other program can feed frames into. Reaching it means a kernel-level exploit of the machine, not an app. And the badge is only ever presence on a call, never authorisation for a payment.
Can my camera's fingerprint be copied from videos of me?
We measured this. Ordinary video calls and typical uploaded video are below the threshold, because compression destroys the faint sensor noise the fingerprint lives in. What could work is dedicated high-quality footage of that exact camera, which is why setup suggests enrolling a camera you do not publish high-resolution video with. Even then, an estimated fingerprint cannot be enrolled as you without your device's secure key.
My face is forever. Is my camera fingerprint the same, a thing I can never change if it leaks?
No, and that is a deliberate design choice. What the registry holds is not the raw fingerprint but a revocable binding of it. If a binding is ever compromised it can be burned and re-enrolled as a fresh one, unlinkable to the old, so a leak is not permanent the way a leaked biometric usually is.
Does it catch an injected feed during the call itself?
Today the proof binds your enrolled camera and your verified identity. Tying it to each moment of the live stream, so a switch to an injected feed is caught automatically, is what we are building now.
Where do my biometrics go?
Nowhere. The fingerprint is read on your own device and never leaves it, and the registry holds only commitments, not the fingerprint itself. The page that verifies you never even receives your device key, so two verification links cannot be tied back to the same laptop.
What does the person checking me have to trust?
Their own browser. The check runs on their device against a public, append-only record, using keys built into the page, so it does not phone home to us for a yes or no. They are reading evidence, not taking our word.
Can Apertrue forge a verification?
The record is a public transparency log designed to be co-signed by independent witnesses, so that showing two different histories would require collusion rather than one party acting alone. In the current pilot we run that witness ourselves and the page says so plainly. Moving witnesses into partners' own infrastructure is the next step, and the standard we built to is already the public one.
What do I need?
Today, a Mac and an iPhone, and a passport with a chip. Windows support is on the way. Setup happens once and takes about a minute.
Which call apps does it work with?
Any app that lets you choose your camera, including Zoom, Microsoft Teams and Google Meet. You pick Witness Camera the way you would pick any webcam.
Does it work with an external webcam?
Not yet. It secures your Mac's built-in camera today, which is the one hardest for an attacker to reach.
What if I lose my laptop or my phone?
A lost device can be revoked, and you can approve a new one. Recovery is deliberately slow and public. It waits out a delay during which your existing device can veto an imposter, and every step is written into the transparency log. If you lose your passport and every device, it will not silently recover, by design.
What does a stale badge mean?
That there has been no fresh evidence for a moment, often just a covered camera or an app that paused. Stale is not a failed check and the badge will not accuse anyone. It simply stops saying yes until it can see again.