Is this video coming from a real camera?

Software can pretend to be a camera and feed a call anything at all. Witness proves the camera is real, and who it belongs to, to the person on the other end.

Type the code exactly as it was given. Dashes and case do not matter.

A video call seen over the caller's shoulder

WITNESS

Yes, checked seconds ago

The frames were checked against the camera this person registered, moments ago.

Verified

Nobody hacked anything.
They just joined the call.

$25m
paid out by one employee at the engineering firm Arup in 2024, after a video call where every colleague on screen was a deepfake.
↗ The Guardian
62%

of organisations were hit by a deepfake attack in the past year; 37% met one on a video call. ↗ Gartner, 2025

70%

of people shown a deepfake video next to a real one judged the fake to be genuine. ↗ Veriff & Kantar, 2026

$40bn

in US fraud losses that generative AI could enable by 2027, up from $12.3bn in 2023. ↗ Deloitte

How the fraud actually works

A face generator synthesises the target, frame by frame, in real time

A virtual camera presents the synthetic feed to the system as a webcam

Your meeting app accepts it, exactly as designed, and shows it to you

No breach, no malware on your side. The most common form of the attack by a wide margin, because it needs so little sophistication.

You cannot out-guess a generator.
You can out-prove it.

The industry's first answer was AI that inspects the video for artefacts of generation. It is a guessing game against the thing that makes the fakes, and every improvement in generation erodes it: when state-of-the-art detectors were tested against deepfakes actually circulating in 2024, their accuracy fell by half compared to the benchmarks they were built on. ↗ Deepfake-Eval-2024

It has other forms. They share one weakness.

Real-time face swap

A live deepfake composited over a real camera's frames, under 50 milliseconds a frame.

Driver and API hooking

Frames replaced between the camera and the app, beneath what the platform can see.

Hardware injection

A capture card presents pre-made video as a physical camera device.

Every form shows you frames that no enrolled sensor produced. Every form fails the same physical check.

Detection attestation
The question it asks Does this video look fake? Did an enrolled, physical camera produce it?
What it examines The pixels the attacker manufactured The sensor's physics and a cryptographic proof
As fakes improve Gets weaker with every generator release Unchanged. It never judges how the video looks
Its output A probability score to interpret A proof that passes or fails, checkable by anyone
Who can verify it The vendor. You take their word Your counterparty's own browser, against pinned keys

A perfect deepfake passes every detector. It still has no camera.

Watch it work.

A call, verified live.
The one-time setup.

Book a demo and we will run the injection attack against a live call while you watch.

Set up once. Proven on every call.

Witness is a small desktop app: it proves your camera's own fingerprint on every call, and the person you are talking to checks it from a link.

Set up once

Prove your passport, pair your phone, enrol your camera. About ten minutes, one time.

Take the call

Select Witness Camera in Zoom, Meet or Teams. Nothing changes about how you meet.

Share the link

Every call gets its own verification link, tied to that call alone. It dies the moment the call ends.

They see proof

Their own browser checks the evidence and shows the verdict, live, for the length of the call.

Your counterparty doesn't take our word for it.

The person on the other end opens your link, and their own browser re-runs the checks on their device. It is not a badge we display; it is evidence their machine verifies. No account, no install. The verification keys are pinned into the page itself.

The camera is real

Every frame is checked against the physical fingerprint of the camera you enrolled. A feed from any other camera fails in seconds.

The person is who they say

The camera belongs to a passport-verified person, named on the page when you choose to be.

The record cannot be rewritten

The registry vouching for you is public and tamper-evident. An entry cannot be invented for one call and deleted afterwards.

Every sensor leaves a fingerprint. Apertrue reads it.

Every camera sensor carries a physical pattern it cannot help leaving in each frame, unique to that sensor since the day it was made. Apertrue's invention reads it, and Witness checks every moment of your call against the camera you enrolled. It is physics, not a watermark, tied to the physical hardware rather than added to the picture.

How the sensor fingerprint works →

Questions people ask

When does a verification call end?

When the last app using your camera lets go of it, Witness stops showing your picture. The call is held for ten minutes, then shown as ended; your next call has a new code. An overlapping handover between apps is not a camera break. If your camera stays on, Witness pauses to ask whether you are still on the same call at least every hour. Witness cannot see who is in your meeting.

What is kept after a call?

You need an account to start a call. Call records are sealed on disk, with an expiry rounded up to the hour, and their keys are destroyed after the retention period. A server restart needs the sender's Mac to unlock them; while waiting, the page says reconnecting. A backup of the sender's Mac made while a key existed may retain that key. Receipts saved by viewers or filed for a sponsor, members' last-call times and account-level action rows stay readable. See the privacy page for the deadlines and backup limits. Rooms are off.

What does Witness actually prove?

That the video on your call is coming from a real, physical camera, and that the camera was enrolled by a specific passport-verified person. It reads the sensor's own fingerprint, not the content of the picture, and the other person's browser checks it independently.

Is this deepfake detection?

No, and that is deliberate. Detectors study the pixels and guess whether they look fake, which is a race they lose a little more with every new model. Witness never looks at the pixels. It proves where the video came from, so a perfect fake from software that is not your enrolled camera still fails.

Can't someone point the enrolled camera at a screen playing a deepfake?

They would need your specific enrolled camera in their hands. Any other camera fails the fingerprint check at once, so this stops being a remote attack and becomes physical possession of your hardware. For high-value approvals the person is re-checked with a movement challenge at setup, which a screen cannot pass.

What if the computer is compromised and malware injects video?

There is no software inlet to inject into. The camera runs inside a signed, sandboxed system extension that opens the hardware itself, with no stream any other program can feed frames into. Reaching it means a kernel-level exploit of the machine, not an app. And the badge is only ever presence on a call, never authorisation for a payment.

Can my camera's fingerprint be copied from videos of me?

We measured this. Ordinary video calls and typical uploaded video are below the threshold, because compression destroys the faint sensor noise the fingerprint lives in. What could work is dedicated high-quality footage of that exact camera, which is why setup suggests enrolling a camera you do not publish high-resolution video with. Even then, an estimated fingerprint cannot be enrolled as you without your device's secure key.

My face is forever. Is my camera fingerprint the same, a thing I can never change if it leaks?

No, and that is a deliberate design choice. What the registry holds is not the raw fingerprint but a revocable binding of it. If a binding is ever compromised it can be burned and re-enrolled as a fresh one, unlinkable to the old, so a leak is not permanent the way a leaked biometric usually is.

Does it catch an injected feed during the call itself?

Today the proof binds your enrolled camera and your verified identity. Tying it to each moment of the live stream, so a switch to an injected feed is caught automatically, is what we are building now.

Where do my biometrics go?

Nowhere. The fingerprint is read on your own device and never leaves it, and the registry holds only commitments, not the fingerprint itself. The page that verifies you never even receives your device key, so two verification links cannot be tied back to the same laptop.

What does the person checking me have to trust?

Their own browser. The check runs on their device against a public, append-only record, using keys built into the page, so it does not phone home to us for a yes or no. They are reading evidence, not taking our word.

Can Apertrue forge a verification?

The record is a public transparency log designed to be co-signed by independent witnesses, so that showing two different histories would require collusion rather than one party acting alone. In the current pilot we run that witness ourselves and the page says so plainly. Moving witnesses into partners' own infrastructure is the next step, and the standard we built to is already the public one.

What do I need?

Today, a Mac and an iPhone, and a passport with a chip. Windows support is on the way. Setup happens once and takes about a minute.

Which call apps does it work with?

Any app that lets you choose your camera, including Zoom, Microsoft Teams and Google Meet. You pick Witness Camera the way you would pick any webcam.

Does it work with an external webcam?

Not yet. It secures your Mac's built-in camera today, which is the one hardest for an attacker to reach.

What if I lose my laptop or my phone?

A lost device can be revoked, and you can approve a new one. Recovery is deliberately slow and public. It waits out a delay during which your existing device can veto an imposter, and every step is written into the transparency log. If you lose your passport and every device, it will not silently recover, by design.

What does a stale badge mean?

That there has been no fresh evidence for a moment, often just a covered camera or an app that paused. Stale is not a failed check and the badge will not accuse anyone. It simply stops saying yes until it can see again.

Real cameras. Real people. Proven.

Book a demo