/FAQ
Deepfake detection, answered.
What fraud, risk, and trust & safety teams ask most when they evaluate ScamAI.
Q.What can ScamAI actually detect?
ScamAI detects deepfaked faces, face swaps, and fully AI-generated images and video. It also catches forged and tampered identity documents — including template-generated and synthetic IDs — manual edits and splices, and device-level attacks like virtual cameras and injection attacks that defeat naive selfie checks. One engine, the Eva V1.6 Detection Model, covers onboarding selfies, identity documents, claims media, live video meetings, and user-generated content.
Q.How accurate is it, and what about false positives?
Detection is probabilistic, not a yes/no: the Eva V1.6 Detection Model returns a tiered likelihood result and the signals that fired, so every result is explainable. You set the thresholds — auto-decline, step-up, or human review — and tune them per flow: stricter for high-value wires, looser for routine account changes. You control the false-positive/false-negative trade-off, not a vendor's fixed cutoff. Eva V1.6 is retrained as new generators appear, so accuracy tracks the current attack landscape, not a frozen benchmark.
Q.Can it work in real time, including live calls?
Real-time detection is what Halo, ScamAI's meeting product, is built for. Halo runs deepfake detection on-device during live video meetings and flags a deepfaked face or manipulated feed while the call is happening, and because analysis stays on your machine, meeting video never leaves it. For application flows, the REST API offers real-time latency for live onboarding and step-up checks, plus batch endpoints for media libraries and claims backlogs. A face-swapped selfie gets declined before the account exists.
Q.Do you store or train on our media?
Media submitted to ScamAI is analyzed to produce a result, then discarded; what's retained is the result — score, signals, request metadata — not your content, unless you configure retention for your own audits. Customer media is not used to train models without agreement. Halo analyzes meeting video on-device, so that media never leaves your endpoint at all. And for data-residency or no-egress requirements, on-prem and private-cloud deployment keep media, results, and logs entirely inside your own perimeter.
Q.How do you keep up with new deepfake generators?
New face-swap and diffusion tools appear constantly, so Eva V1.6 trains on real attack media — actual fraud attempts, not academic datasets — and retrains as new generators show up in the wild. The team publishes original research — papers and open datasets on deepfake detection, document forgery, and adversarial attacks on age-estimation systems, with named authors on arXiv — and studied techniques become detection signals. Ask any vendor when its model was last updated, and against what.
Q.How does it integrate with our stack?
Integration is one REST API: send video, images, or documents; get back a scored result with evidence attached. Drop it into your existing decision point — onboarding/KYC, claims intake, the support or moderation queue — and route on the score: approve, step-up, or review. There is no model to train, so a first integration typically takes a day, not a quarter. SDKs are coming; Halo, a lightweight desktop app, needs none; regulated environments can deploy on-prem or private-cloud.
Q.Are you compliant — SOC 2, GDPR, data residency?
ScamAI is SOC 2 Type II audited and GDPR compliant, with a Data Processing Agreement available. The legal stack — privacy policy, terms, DPA, MSA, subprocessor list, and the Halo EULA — is published openly on the site. Banks and public-sector agencies with data-residency or no-egress requirements can deploy on-prem or private-cloud: the same models run inside your perimeter, so nothing crosses a boundary you don't control. Halo analyzes meeting video on-device, so meeting content never reaches ScamAI's infrastructure.
Q.What evidence do we get for a result?
Every result ships with the signals that fired — concrete reasons like face-region inconsistencies, document-template anomalies, or device-level capture red flags. Analysts get something to review instead of a bare number, auditors and regulators get an explainable record of why an application was declined or escalated, and disputed decisions can be defended with specifics rather than a black-box score. Regulated fraud teams can't act on an opaque score alone, so explainability is part of the product, not an afterthought.
Q.How is this different from a single-point detector?
Single-point detectors answer one question — "does this media look AI-generated?" — and stop. ScamAI layers multimodal detection on top of your existing KYC/IDV vendor, strengthening it, not replacing it, and adds document-forgery detection, device signals, and on-device meeting protection in one combined result. A flagged selfie is only useful tied to the identity being onboarded and an approve/decline/review decision; a point detector leaves that connective work to your engineers. With a platform, flag, identity, and decision arrive together.
Q.What does it cost?
Pricing scales with check volume and the surfaces you protect — selfie and video at onboarding, document verification, device signals, meeting protection with Halo, or a combination. There is no published one-size-fits-all price; a dating app screening profile photos and a bank running full KYC with document forensics have different footprints. Bring your use case and monthly volumes to a 15-minute demo and leave with detection running on your own media and a price mapped to your actual flow.
Still have a question?
Bring your use case — you'll leave with detection running on your own media.
Prefer to browse? Read the docs, the DPA and subprocessor list, or the research.