# ScamAI — full site content for LLMs and AI agents > ScamAI (Reality Inc.) is a deepfake detection and scam-prevention platform: multimodal detection (video, images, audio, documents) via the unified Eva V1.6 Detection Model API, on-device real-time meeting protection with Halo (beta), KYC/IDV and document-forgery detection, one REST API. Dashboard: https://app.scam.ai. Compact map: https://scam.ai/llms.txt Marketing and docs content follows in full. App surfaces are served on app.scam.ai and are private. # Platform ## Verifit | Remote inspections. Confident decisions. URL: https://scam.ai/platform/verifit Cut inspection costs and keep decisions moving. Verify property and assets remotely, with fewer site visits and less back-and-forth. ### Less waiting between request and decision Give customers an easy way to complete inspections and your team a faster way to review them. ### FAQ Q: How does Verifit help reduce inspection costs? A: Collect verified photos remotely to reduce travel, scheduling, and manual follow-ups. Your team gets what it needs to review suitable cases without an on-site visit. Q: Does Verifit replace every inspection? A: Use Verifit to handle suitable inspections remotely and reserve site visits for complex cases. Your team decides when more information or an in-person inspection is needed. Q: How does my team get started? A: Book a demo focused on your workflow. We will explore where Verifit can reduce delays, save your team time, and make inspections easier for your customers. ## Eva V1.6 Detection Model — our detection engine URL: https://scam.ai/platform/eva The unified API behind every ScamAI result: video, images, and documents, scored together in real time. ### Trained on real attacks Eva V1.6 learns from the largest library of real attack media in the industry — not synthetic benchmarks. When a new generation technique appears, the model retrains against it, so detection evolves at the speed of the threat. ### One API, every channel Attacks rarely fake just one channel. A single Eva V1.6 call routes face, document, and behavioral signals to their specialist detectors and scores them together, catching inconsistencies a single-channel check would miss. ### Explainable results Every score ships with the signals that fired. No black-box risk numbers — evidence your analysts and auditors can read and act on. ### Deployed where the risk is The same engine runs two ways: as the unified API for batch and real-time flows, and on-device inside Halo for live meetings. One API, one set of results, wherever an attack can land. ### Inside a result: how Eva V1.6 scores media When media arrives — a selfie, a document photo, a video clip — Eva V1.6 breaks it into the surfaces where manipulation leaves traces: generation artifacts, blending boundaries where a swapped face meets the original frame, frame-to-frame inconsistencies no real camera produces, edited regions and reused templates on documents. Each detector feeds one probabilistic confidence score, and the response lists the signals that fired — an argument, not an assertion. The exchange is simple: submit the file through the unified REST API and receive a JSON result with the score, the signal evidence, and per-frame detail for video. The same engine runs three ways — real-time, batch, and on-device inside Halo — so one API produces consistent results wherever an attack lands. ### Evaluating a detection model before you buy Vendor demos are the worst place to judge a detection model — every vendor demos the fakes they already catch. Test Eva V1.6 the way you would test any risk model: assemble known-genuine media from real customers plus whatever confirmed fraud you have retained, and score it blind. Then look past the headline result. Does every result carry evidence your analysts can read? Can you move the threshold yourself? Is retraining continuous as new face-swap and diffusion tools ship? Teams that buy well run shadow mode first, then step-up routing, then automated decisions as the score earns trust. ### FAQ Q: What is the Eva V1.6 Detection Model? A: The Eva V1.6 Detection Model is the detection engine behind every ScamAI result. Through one API it analyzes faces, images, video, and documents for signs of manipulation — face swaps, fully AI-generated media, and edited or forged documents — routing each to a specialist detector and returning a probabilistic confidence score with the specific signals that fired. The model is retrained as new generation tools appear, and the same engine runs behind the cloud API, in on-prem deployments, and on-device inside Halo for live meetings. Q: How does the Eva V1.6 Detection Model detect deepfakes? A: The Eva V1.6 Detection Model looks for the traces synthetic media cannot help leaving: statistical artifacts from generation models, blending boundaries where a swapped face meets the original frame, temporal inconsistencies across video frames, and capture characteristics that do not match a physical camera. No single signal decides the result — the model weighs them together into one confidence score and reports which ones fired. Because detection is probabilistic, you choose the threshold that fits your risk tolerance rather than accepting a fixed yes/no answer. Q: Does the Eva V1.6 Detection Model give a yes/no answer or a confidence score? A: A confidence score, with evidence. Every result includes a probabilistic score plus the list of signals that fired, so you can see why media was flagged, not just that it was. Your team sets thresholds on that score — auto-decline above one line, route to human review above another, pass below both — which keeps the false-positive and false-negative trade-off in your hands. For audit and compliance teams, the attached signal evidence makes each decision defensible after the fact. ## Check if AI — spot AI-generated media in seconds URL: https://scam.ai/platform/check-if-ai Upload an image and get an instant read on whether it's AI-generated. ### What does Check if AI do? A fast, self-serve check for synthetic images: upload a JPEG, PNG, or WebP and Eva V1.6 returns a manipulation score with the signals behind it — no integration required. Video and document checks run through the same unified API, not this page. ### Who is Check if AI for? A first-line gut check for trust & safety teams, journalists, and anyone who needs to know whether what they're looking at is real before they act on it. ### What happens when you hit upload Behind the upload button is the same Eva V1.6 unified API that powers ScamAI's production integrations. Your image is read for the traces synthetic media leaves behind — generation artifacts, blending boundaries around swapped faces, and the edit signatures manual retouching leaves in pixel statistics. Seconds later you get a manipulation score with the signals that fired: the same result structure an enterprise integration receives. This page takes images only, so anyone can test the engine without an integration; video and documents go through the same API. Your upload is saved to your account with the result, so you can open it again later. ### Reading a manipulation score like an analyst A detection score is a probability, so think in likelihoods. A high score with multiple fired signals is strong evidence of manipulation; a low score with none is strong evidence of authenticity; a middling score is an honest uncertain — often what compressed, re-encoded, or low-resolution media produces, since each re-share strips the forensic detail detectors read. The practical habits: check the signals, not just the number. Prefer the earliest, highest-quality copy of a file over a screenshot of a screenshot. Weigh the score alongside provenance — where the file came from and who benefits if it is believed. When the question becomes every upload, every day, move to the API. ### FAQ Q: How can I check if an image is AI-generated? A: Upload it to Check if AI. The file is analyzed by Eva V1.6, ScamAI's detection engine, which reads it for generation artifacts, blending boundaries, and manipulation signatures, and returns a manipulation score in seconds along with the specific signals that fired. No integration or setup is required. For the most reliable read, submit the earliest and highest-quality copy of the image you can find — screenshots and heavily re-shared copies lose the forensic detail that detection relies on. Q: How reliable are AI-image detectors? A: Honest ones report probability, not certainty. Detection reads statistical traces that generation and editing leave behind, and their strength varies with the file: an original-quality image gives the model much more to work with than a compressed, re-encoded copy. That is why Check if AI returns a confidence score with named signals — a high score with several fired signals is strong evidence, a middling score is genuine uncertainty, and either should be weighed against where the file came from. ## Deepfake Playground URL: https://scam.ai/platform/deepfake-playground Deepfake yourself in 30 seconds. Point your camera at your own face, pick someone to become, and watch the swap happen live — the same thing an attacker can do with consumer tools. ### How easy it's become A convincing face swap takes minutes — with free, consumer-grade tools. The playground lets you see that firsthand, so the threat stops being abstract. ### It's your own face, in real time This isn't a canned clip. Your camera streams to a GPU running the swap frame by frame, and the result comes back live — you can move, talk, and change identity mid-session. That immediacy is the point: a threat you have personally produced stops being theoretical. ### FAQ Q: How easy is it to make a deepfake? A: Alarmingly easy — a convincing face swap takes seconds with consumer-grade tools and no technical skill. That accessibility is what changed the fraud landscape: deepfakes stopped being a specialist capability and became something any motivated attacker can produce at scale. The Deepfake Playground lets you experience it firsthand rather than take our word for it — you point a webcam at your own face and watch yourself become someone else in real time. Q: Does the playground store my face or record the session? A: No. Your camera streams to the swap engine for the length of the session so it can render each frame, and nothing is written down — no recording, no uploaded photo, no stored face. If you capture a shareable card, it is composed in your own browser from a frame already on your screen and never leaves your device unless you choose to share it. Q: Can I test deepfake detection before buying? A: Yes, in stages. The playground shows you the attack; Check if AI shows you the defence, letting you upload media for a scored read from the Eva V1.6 Detection Model — the same engine behind the production API. For a serious evaluation, run a proof of concept through the API with media from your own traffic, both known-genuine submissions and confirmed fraud, because your real distribution is what production performance depends on. Q: Can the playground be used for security awareness training? A: Yes, and it is one of its most common uses. Employees who have personally watched a convincing fake of themselves appear develop sharper instincts than any slide deck produces — especially finance, support, and executive-facing teams that fraudsters target with impersonation. Teams leave with one durable takeaway: seeing a familiar face on a call is no longer evidence that the person is who they appear to be. ## On-prem deepfake detection URL: https://scam.ai/platform/on-prem-deployment Run ScamAI detection inside your own environment — VPC, private cloud, or fully on-premises — so regulated data never leaves your perimeter. ### Detection where your data lives For banks, government, and other regulated teams, media can't leave the building. On-prem deployment runs the same Eva V1.6 detection engine and API inside your environment, so results happen next to your data with no egress. ### Built for compliance Meet data-residency, sovereignty, and procurement requirements with a self-hosted install: your keys, your network, your audit trail. Halo already runs on-device; on-prem extends that privacy posture to the full platform. ### Same platform, your perimeter You get the same models, results, and integration surface as the cloud API, deployed to your infrastructure, updated on your schedule, and supported by our team. ### What a self-hosted install actually looks like On-prem is the same Eva V1.6 engine and REST API as the cloud, packaged as containers that run in your VPC or air-gapped network, so media never leaves your perimeter and a cloud integration ports with no code changes. The one difference is model updates, which you apply on your own schedule. ### Due diligence for self-hosted detection Judge self-hosted detection on how it handles isolation versus freshness: ask how often model updates ship, how they reach your environment, and what each upgrade asks of your team. Confirm the on-prem API is identical to the cloud one, and map the offering to your compliance requirements in writing. ### FAQ Q: Can deepfake detection run fully on-premises? A: Yes. ScamAI packages the same Eva V1.6 detection engine and REST API that power the cloud service for deployment inside your own environment — a VPC, a private cloud, or a fully air-gapped network. Your applications call a local endpoint with the same request and response shapes as the cloud API, and submitted media is scored entirely within your perimeter, with no egress. Results, evidence signals, and audit logs stay in infrastructure you operate, which satisfies data-residency and no-third-party-sharing requirements. Q: How do detection model updates work in air-gapped environments? A: Through packaged releases delivered over your approved transfer channels, applied on your schedule under your change-management process. This matters more for detection than for ordinary software: coverage depends on retraining against new deepfake and forgery generators, so a model frozen at install time gradually loses ground. When evaluating any self-hosted detection product, ask about release cadence, delivery mechanics for isolated networks, and how much work each upgrade demands from your operations team. Q: When should we choose on-prem instead of the cloud API? A: When data cannot leave your perimeter — data-residency laws, sovereignty mandates, sector regulation, or internal no-egress policy for sensitive media. If none of those apply, the cloud API is faster to adopt and carries no operational burden. A common middle path is hybrid: prove detection value with a cloud pilot on non-restricted traffic, then move regulated workloads on-prem once procurement and security review complete. Because the API surface is identical, migration does not require rebuilding the integration. ## PII Zero: Claims Media De-identification URL: https://scam.ai/platform/pii-zero Offline redaction of policyholder identity in claim documents, loss photos and video: names, addresses, account and policy numbers, faces and plates. ### Detect, track, redact, verify OCR reads every page or frame in three orientations; NER, checksum recognisers and a vision layer flag names, IDs, faces, plates and codes. Regions are tracked across frames and blurred beyond recovery. The output is re-scanned with the same detectors and any surviving hit blocks the release. ### Measured on real footage The product page shows actual output on synthetic claim documents and stock footage, with the number of tracked regions, frames covered and residual PII found by the second pass. ### Your perimeter, your audit log Ships as containers for a VPC, private cloud or air-gapped network. Originals are read-only; the audit log records entity types, coordinates and a masked hint, never the full value. An optional encrypted vault keeps originals for a review window you set. ### FAQ Q: Is the blur reversible? A: No. Each region is downsampled to a few pixels before it is blurred, so the shapes are discarded rather than smeared, and the output is re-read by the same detectors to prove it. Opaque fill is available by policy. Q: Does any data leave our environment? A: No. OCR, NER, face and plate detection run as local models with no API calls. Nothing is retained after the run except the audit log you configure. ## Risk Signals URL: https://scam.ai/platform/risk-signals Turn detection results into a view of your threat surface — patterns rather than single incidents. Available on request. ### See where attacks concentrate Aggregated across your checks, the same evidence shows which channels, teams, and workflows attract the most synthetic-media activity — so you can put defenses where attackers actually go. Set up with our team rather than self-serve. ### Trends, not noise Attack techniques change weekly. The same result stream can be tracked over time to show how the threat mix shifts — new generation tools, new targets, new hours of attack. ### Close the loop Signals are worth more fed back than filed. Use them to tune your own thresholds and route the riskiest sessions to review, so what you learn on Monday hardens your defenses by Tuesday. ### FAQ Q: What are risk signals in fraud detection? A: Risk signals are the structured evidence a detection system produces alongside each result — which manipulation indicators fired, on which channel, in which workflow, and when. Individually they explain one decision; aggregated, they describe your threat surface. ScamAI can roll your result telemetry up into heatmaps and trends — where synthetic-media activity concentrates, how the attack mix shifts week over week, and where the same forged template keeps reappearing. It is arranged with our team rather than switched on in the dashboard, which reports one verdict per check. Q: How do teams monitor deepfake attack trends? A: The raw material is result telemetry: every detection check records what fired, where, and when. Trend monitoring aggregates that stream by channel, team, and workflow, so shifts become visible — a new generation tool in onboarding, injection attempts concentrating on one product, attack volume moving to off-hours. Effective teams review trends on a fixed cadence with a named owner, then respond through policy: tightening thresholds on workflows under pressure or routing the riskiest sessions to human review. Q: Can detection thresholds be tuned based on analytics? A: Yes — that feedback loop is the point of trend data. ScamAI results are probabilistic confidence scores rather than fixed yes/no answers, so thresholds are yours to set, and trends tell you when to move them. If trend data shows a campaign concentrating on one workflow, lower that workflow's auto-decline threshold or widen its human-review band — a policy change, not a redeploy. Best practice: decide in advance which patterns trigger which changes, so tuning is documented policy. ## Deepfake Detection URL: https://scam.ai/platform/deepfake-detection Purpose-built deepfake signals — face swaps, full generations, and replays — scored across images, video, and live calls. Key stat: 1 / 5 min — a deepfake fraud attempt occurred every five minutes in 2024 (source: Entrust Identity Fraud Report) ### What it does Eva V1.6 scores every selfie and video frame for synthetic-media signals, with coverage that tracks the latest diffusion and face-swap generators as they appear. ### Where it fits IDV and onboarding stacks: score the selfie step before an account exists. The same signals run on claims footage, moderation queues, and live meetings through Halo. ### What you get back A per-frame manipulation score with the signals that fired: face-swap, full generation, or replay. Your flow can auto-decline, step up, or route to a reviewer with the reason attached. ### What is deepfake detection? Deepfake detection decides whether a face in an image, video, or live stream was synthetically generated or manipulated: a swapped face, an AI-generated person, or a replay passed off as live. ScamAI checks everywhere a face appears and returns a probabilistic score with the signals behind it. ### Choosing a detector: coverage, evidence, and rollout A detector worth buying covers still images, recorded video, and live calls, not just the easy selfie, and names the signals behind each score so a decline is defensible. On rollout, score live traffic in shadow mode first and save automated declines for high-confidence results. ### FAQ Q: Can deepfakes actually be detected? A: Yes — with the honest caveat that detection is probabilistic, not absolute. Generation tools leave traces: statistical artifacts, blending boundaries, temporal inconsistencies in video, and capture characteristics no physical camera produces. A detector weighs those signals into a tiered likelihood result rather than a guaranteed one, and stays effective only if it retrains as new generators appear. ScamAI returns scores with evidence and lets you set thresholds — decline high-confidence fakes automatically, route ambiguous cases to human review. Q: How does deepfake detection work on live video calls? A: Recorded media can be scored after the fact; a live call has to be scored while it happens. Halo runs ScamAI's detection on-device during meetings, continuously checking participant faces and feeds for face swaps and manipulated video, and raising a risk signal the moment something synthetic appears — mid-call, while you can still act. Because analysis happens locally, the meeting never leaves the device to be checked, keeping sensitive calls private while they are protected. Q: What kinds of deepfakes does detection need to cover? A: Three broad families. Face swaps graft a target's face onto another person's body — the classic impersonation tool. Full generations create an entirely synthetic person, common in fake profiles and synthetic identities. Replays and injections present pre-recorded or synthetic footage as a live capture, often through virtual-camera software. Each leaves different evidence, so ScamAI scores them with distinct signals across images, recorded video, and live calls — catching the synthetic media itself, however it is delivered. ## ID Document Forgery Detection URL: https://scam.ai/platform/id-document-forgery Tampering and forgery signals for identity documents — passports, national IDs, driver's licenses, residence permits. Key stat: 57% — of document fraud is now digital forgery rather than physical counterfeits (source: Entrust) ### What it does Detects edits, template reuse, and full AI generation on government identity documents, returning scored signals with the evidence that fired. ### Evidence you can defend Each flag returns the tampered region and the signal behind it, so a rejected document comes with a reason your compliance and audit teams can stand behind. ### The signals a forged ID leaves behind A forged ID gives itself away in layers: a digital edit mismatches compression and lighting at its boundaries, a template forgery reuses the same artwork across IDs, and an AI-generated document carries model fingerprints. One API call reads all three and localizes the tampering, so a reviewer sees the evidence on the document itself. ### What to ask a document-forgery vendor Document fraud has moved from physical counterfeits to digital edits and reused templates, so evaluate with your own corpus of real documents plus confirmed forgeries, in the types and countries you serve. Then check that a flag points at the tampered region, covers your document mix, and maps onto your approve, step-up, and decline logic. ### FAQ Q: How does AI detect a fake ID? A: By reading structure instead of content. An edited ID carries regions whose compression history, noise pattern, and lighting do not match the rest of the document. A template forgery reuses identical artwork across supposedly different IDs. A fully AI-generated document carries the statistical fingerprints of the model that produced it. ScamAI scores these signals together, returns a probabilistic confidence score, and localizes the suspicious region — so a reviewer sees exactly which part of the document triggered the flag. Q: Can AI-generated passports and driver's licenses be detected? A: Yes. Fully generated documents look plausible at a glance but are structured like no issuing authority's real output — generation models leave statistical fingerprints, and synthetic documents often betray template inconsistencies a genuine document would never contain. Because new generation tools appear constantly, coverage depends on retraining: ScamAI's detection engine is updated as new document-generation techniques emerge. Results come back as confidence scores with evidence rather than a blind pass/fail, so your team controls how aggressively to act. Q: What should happen when a document is flagged in KYC? A: Route by confidence, not by binary. High-confidence forgery results can auto-decline or trigger a hard stop; mid-band flags route to human review, where the localized evidence — the tampered region highlighted on the document — lets an analyst confirm or clear the flag in seconds. Every result and its signals should land in your audit trail, so a rejected applicant, a regulator, or an internal QA review can see the concrete reason behind the decision. ## Loan & Insurance Document Forgery URL: https://scam.ai/platform/loan-insurance-forgery Forgery signals for due-diligence documents — bank statements, pay stubs, proof of income and address, invoices, policy documents. Key stat: $3.1B — U.S. lender exposure to synthetic-identity fraud in a single year (source: TransUnion) ### What it does Scores the paperwork behind lending and claims decisions for tampering and AI generation, so doctored statements don't sail through underwriting. ### Where it fits Loan origination, credit review, and insurance claims pipelines. ### Catch the pattern, not just the page Because documents are scored across applications, ScamAI surfaces the same doctored template or synthetic income proof repeating across your book, exposing the organized fraud behind a single file. ### How a model reads a doctored bank statement People check financial documents by whether the numbers look plausible, but the forgery lives in the structure: fonts and spacing that drift from the template, an edited figure whose noise doesn't match the page. Detection scores those structural signals with localized evidence, and across many files it surfaces the same template reused under different names. ### FAQ Q: How can lenders detect forged bank statements? A: Automated forgery detection reads the structure a human reviewer cannot see: fonts and alignment that drift from the bank's real template, edited regions whose noise and compression history differ from the rest of the page, and the statistical fingerprints of AI-generated documents. ScamAI scores each statement and returns a confidence score with localized evidence — inside the origination flow via the REST API or in batch across a portfolio. Cross-application scoring exposes the same doctored template under different applicant names. Q: Can AI detect fake pay stubs and proof-of-income documents? A: Yes. Pay stubs, employment letters, and proof-of-address documents are edited or generated with the same tools as any other document, and they leave the same structural evidence: template inconsistencies, mismatched edit regions, and generation artifacts. Detection returns a probabilistic score with the signals that fired, localized to the suspicious area, so an underwriter reviews the flagged field rather than the whole file. Because results are threshold-based, you decide which scores auto-route to review and which pass without friction. Q: How does document fraud detection fit into insurance claims processing? A: At claims intake, every supporting document — invoices, repair estimates, policy paperwork, proof of loss — can be scored before adjudication begins. Genuine claims pass through without added friction; suspicious documents surface with a confidence score and localized evidence attached, so adjusters spend their time on the files that need judgment. Batch endpoints also let teams re-screen historical claims, and cross-claim analysis flags documents and templates reused across supposedly unrelated claims — a common pattern in organized claims fraud. ## Age Estimation URL: https://scam.ai/platform/age-estimation Age checks from a live selfie — an estimated age and the probability the person is over your threshold, no ID collected. ### What it does Estimates age from a live selfie with liveness checks, returning an estimated age and the probability the person is over your threshold, with no identity established and nothing stored. ### Where it fits Age-gated signups, checkouts, and content access, verifying age without collecting an ID. ### Privacy by default No document, no stored image, no identity established, just a live-selfie age estimate and an over-threshold probability you can gate on. Compliance stays light and data collection stays minimal. ### Estimating age from a face, not a database Age estimation reads the facial features that change with age and maps them to an estimated age, plus the probability that the person clears your threshold, so it's estimation, not recognition: no database match, no identity, no biometric record. It runs on a live selfie in one API call, and the image is analyzed and discarded. ### FAQ Q: How does AI age estimation work without documents? A: The model reads visual features of a live selfie that correlate with age — skin texture, facial structure — and returns an estimated age together with the probability that the person is over your age threshold. No document is collected and no identity established: the system answers how old this person roughly is, not who they are. ScamAI pairs the estimate with liveness and capture checks so a photo, replay, or injected feed cannot substitute for a real face, and the selfie is analyzed and then discarded. Q: Is facial age estimation the same as facial recognition? A: No, and the difference matters for privacy and compliance. Facial recognition matches a face against a database to identify or verify a specific person, which creates and depends on biometric records. Age estimation infers one attribute — an approximate age — from the image in front of it, matches nothing, identifies no one, and stores no template. That is why estimation-based age gates are lighter for privacy teams to approve: a compliance signal without an identity system built around it. Q: What happens when a user is close to the age threshold? A: Estimation is probabilistic, so well-designed gates act on the over-threshold probability rather than a single cutoff on the estimated age. Users whose probability of clearing the required age is high pass automatically; when it is low, the gate holds. The uncertain middle routes to a stronger check — typically document verification — so the heavier, higher-friction step is reserved for cases that genuinely need it. In practice, most users clear the gate instantly from a selfie, and the ID upload becomes the exception path. ## Device Signals — liveness & presentation attacks URL: https://scam.ai/platform/capture-signals Detection for spoofed presentations — printed photos, screen replays, and masks — plus liveness failures, caught at the point of capture. ### What it does Confirms the face at capture is a live, present person, not a printed photo, a screen replay, or a mask held to the lens. Spoofed presentations are flagged as the media is captured, before the frame enters your pipeline. ### Where it fits The capture step of IDV: signup selfies, document photos, and liveness video, checked as the media is captured. ### The earliest line of defense Running at capture means a spoofed or replayed presentation is caught before any downstream check even sees the frame, stopping the attack earlier, and cheaper, than catching it later. ### Layering liveness into an IDV stack Liveness is one layer, not the whole defense, so pair it with deepfake and document detection: an attack that beats one check still has to beat the others. A failed check can trigger a retake or step-up instantly, because it's a fact about the capture, not a judgment about the person. ### FAQ Q: What is a presentation attack? A: A presentation attack presents a fake face to a real camera to pass as a live person: a printed photo, a video replayed on a screen, or a mask worn or held to the lens. It is the classic way naive selfie and liveness checks are defeated — the camera is real, but the thing in front of it is not a live subject. Liveness detection targets exactly this, reading the captured image for the signals a screen, print, or mask leaves behind. Q: How does liveness detection work? A: By examining the captured face rather than trusting the session. Detection reads the signals a spoof leaves — screen glare and moiré, print texture and edges, and the depth and micro-motion a living face shows that a photo or mask does not — and returns a scored signal alongside the media. Your flow can reject or step up a session that cannot demonstrate a live, present subject before the frames reach downstream analysis. Q: How does this work with deepfake detection? A: They are complementary layers. Liveness confirms a real, present human is in front of the camera; deepfake detection judges whether the face itself has been synthetically generated or swapped. Run together, an attack has to defeat both — a mask that survives a quick look still fails liveness, and a swapped face that looks live still fails deepfake detection. ScamAI returns each as its own scored signal with the result, so the decision comes with its reasons attached. ## Manual-Edit Forensics — image forgery detection URL: https://scam.ai/platform/manual-edit-forensics Pixel-level forensics for manually edited selfies and documents — splices, clones, and retouching. ### What it does Not all forgery is AI: pixel-level analysis catches Photoshop-style edits like spliced regions, cloned patches, and retouching on selfies and documents. ### Where it fits Alongside gen-AI detection, so hand-crafted fakes don't slip past a model looking only for synthetic artifacts. ### No gap to slip through One pass covers both machine-made and hand-made forgery: Eva V1.6 scores synthetic generation while forensics catches manual edits, closing the seam attackers exploit between them. ### Splices, clones, and the physics of an edited image Every manual edit disturbs an image's internal consistency: a splice imports noise and lighting that don't match, a clone leaves improbable repetition, and retouching breaks a camera's uniform sensor noise. Forensic analysis reads those pixel statistics to prove an edit happened and localize where, running in the same pass as Eva V1.6's AI detection. ### FAQ Q: Can AI detect Photoshop edits? A: Yes — through forensic signals rather than generative-AI fingerprints. Manual edits disturb an image's internal statistics: spliced content imports mismatched noise and compression history, cloned patches repeat pixels improbably, and retouching breaks the uniform sensor noise a real camera produces. ScamAI's forensics reads these traces on selfies and documents, returns a confidence score with the signals that fired, and localizes the edited region — the flag points at the altered field, not vaguely at the whole image. Q: What is image forgery localization? A: Localization means identifying where in an image or document the manipulation occurred, not merely that it occurred somewhere. Instead of a file-level fake/real label, the result highlights the specific region whose forensic statistics are inconsistent — a pasted date field, a cloned background patch, a retouched face area. That precision changes operations: reviewers confirm or clear a flag in seconds, disputes can be answered with concrete evidence, and audit trails record exactly what was found rather than an opaque score. Q: Why do I need edit forensics if I already detect deepfakes? A: Because they catch different artifact classes. Deepfake detectors hunt the statistical fingerprints of generative models — and a hand-made edit contains none of them. A document field altered in an image editor can sail past a purely generative detector while remaining fully fraudulent. Attackers use whichever tool is cheapest for the job, so coverage needs both: ScamAI runs generative detection and manual-edit forensics in the same pass, giving a hand-made fake the same scrutiny as a synthetic one. ## MCP for LLMs URL: https://scam.ai/platform/mcp Bring ScamAI detection to AI agents. An MCP server that lets an LLM check whether an image, a video or an audio recording is real, mid-task. ### What it does An MCP (Model Context Protocol) server that exposes ScamAI detection as a tool any compatible LLM or agent can call. Install it with npx to run on your own machine, or point your client at our hosted endpoint and add your API key. Same server either way. ### Detection your agents can trust Agents get the same scored results and evidence as the API — so an automated decision is backed by the exact signals a human reviewer would see, not a guess from the model. ### Tool Calls: how the MCP works ScamAI's MCP server exposes detection as typed tools any compatible agent can call mid-task: check a selfie, verify a video, score a voice recording. Backed by the same Eva V1.6 engine as the REST API, and billed the same way. ### Putting verification inside agent workflows Give your agents a verification step so they check media before acting on it, and escalate anything risky to a human. ### FAQ Q: What is an MCP server for deepfake detection? A: MCP — the Model Context Protocol — is an open standard that lets LLMs and agents call real tools instead of guessing. ScamAI's MCP server exposes detection as tools: an agent submits a selfie, document, image, or video mid-task and receives a probabilistic confidence score plus the evidence signals that fired, back in its context. The tools are backed by the same Eva V1.6 engine as the REST API, so agent-initiated checks carry the same weight as any other result. Q: How can AI agents verify images and documents? A: Through tool calls mid-task. An agent reviewing a loan application calls a verification tool for each attached document; the media is scored by the detection backend and the result — score plus named signals — returns into the agent's context, where it can branch: proceed, request better documentation, or escalate to a human queue. Encode escalation rules in the skill rather than the prompt, so high-risk results always trigger a handoff no matter how the conversation has drifted. Q: Which LLMs and agent frameworks work with ScamAI's MCP server? A: Any runtime that speaks the Model Context Protocol. MCP is an open standard with broad adoption across major assistants and agent frameworks, so integration is configuration rather than custom development: point your agent runtime at the ScamAI server and the detection tools become available to the model. For teams building on frameworks with their own tool conventions, ScamAI also packages skills that wrap complete verification workflows, and the underlying REST API remains available for anything the protocol does not cover. ## Detection API URL: https://scam.ai/platform/api One API for the places fraud happens: send video, images, or documents and get a scored result back. Native SDKs are on the way. ### Simple to integrate Submit media, receive a manipulation result with a confidence score and the signals that fired. Wire it into onboarding flows, support channels, claims pipelines, and content moderation. ### Built for production Real-time latency for live flows, batch endpoints for pipelines, and results that include evidence — ready for your risk team and your auditors. ### SDKs coming soon Today, the REST API covers every language. Native SDKs for JavaScript/TypeScript, Python, and mobile are in development. ### Running a proof of concept Test on your own traffic — real genuine media plus known fraud — and score it blind. Then set the thresholds that decide what's auto-declined, reviewed, or approved. ### FAQ Q: How do I integrate a deepfake detection API? A: Send media over HTTPS and act on the JSON. Your backend submits an image, video, or document to the REST API with an API key and receives a probabilistic confidence score plus the evidence signals that fired. Your code compares the score to thresholds you set and branches — approve, step up, or route to review. There is no model to host; any language that can make an HTTP request can integrate today, with native SDKs coming. Q: What does a deepfake detection API return? A: A scored, explainable result rather than a bare label. The JSON response carries a probabilistic confidence score for manipulation, the specific signals that fired — the evidence behind the score — and per-frame detail for video so you can locate where in a clip manipulation appears. That structure serves machines and humans alike: your code thresholds on the score for automated decisions, while analysts and auditors read the signals to defend each outcome after the fact. Q: Does a deepfake detection API work in real time? A: It should offer both speeds, because fraud workflows need both. ScamAI's synchronous endpoints return results at real-time latency for inline flows — an onboarding selfie check or a document step where a user is actively waiting. Batch endpoints handle volume work: re-screening a loan book, scoring a claims backlog, or moderating an upload queue where throughput matters more than a single request's speed. Both patterns return the same result structure, so one integration serves live decisions and pipeline jobs alike. # Solutions ## KYC / IDV fraud detection URL: https://scam.ai/solutions/kyc-idv Make sure the person enrolling is live, present, and real — not a replay, a render, or a synthetic identity. ScamAI works with your KYC vendor to strengthen it, not replace it. Key stat: $23B — projected annual U.S. losses to synthetic-identity fraud by 2030 (source: Deloitte Center for Financial Services) ### The threat Face-swap kits and virtual cameras defeat naive selfie checks. Synthetic identities blend real and fabricated attributes to pass onboarding and mature into major fraud losses. ### Where detection sits in your onboarding flow ScamAI plugs into the two moments identity fraud enters, the selfie capture and the document upload, calling the REST API with media you already collect and returning a scored result in real time. Clean scores flow through, borderline cases step up, and clear manipulation declines with evidence attached, so genuine applicants never see a new step. ### Breaking the synthetic identity lifecycle at day zero A synthetic identity is grown, not stolen: fraudsters pair a real identifier with a fabricated face, behave normally for months, then bust out like a loyal customer defaulting. Enrollment is the only cheap place to stop it, because the fake face and doctored document must appear at day zero where each is detectable (Deloitte projects $23B in annual U.S. losses by 2030). ### FAQ Q: How do fraudsters bypass selfie and liveness checks? A: Attackers use virtual camera software to inject pre-recorded or AI-generated video into the verification session, bypassing the physical camera. Others use real-time face swaps that respond to liveness prompts, blinking and turning on cue, because a live person drives the fake face. Naive liveness checks confirm motion, not authenticity. Defeating these attacks means scoring the media itself — whether the face is synthetic and whether the presentation shows print, replay, or mask spoofing — so an injected or replayed fake is caught on its content. That deepfake and presentation-attack scoring is what ScamAI adds on top of standard liveness. Q: What is synthetic identity fraud in KYC onboarding? A: Synthetic identity fraud combines real identifiers, such as a government ID number, with fabricated names, faces, and documents to create a person who does not exist. Because part of the identity is real, database checks often pass, and the fraudster ages the account with normal activity before cashing out. Deloitte projects U.S. losses of $23B annually by 2030. At onboarding it depends on fake media — an AI-generated or swapped face and edited documents — the weak point ScamAI targets. Q: Can a deepfake pass identity verification? A: Consumer-grade face-swap tools defeat basic selfie comparison, and virtual cameras feed rendered video into verification flows that only check for a moving face. Deepfakes pass when the system trusts the video instead of inspecting it. They fail when verification scores the face for generation artifacts, checks the presentation for print, replay, or mask spoofing, and confirms consistency between selfie and document. ScamAI runs those checks at enrollment via the REST API, returning a scored result and its signals, so your team can decline or step up before the account exists. ## Loan & credit fraud detection URL: https://scam.ai/solutions/loan-credit Stop synthetic applicants and doctored income documents at origination, before the money moves. Key stat: $3.1B — U.S. lender exposure to synthetic-identity fraud in a single year (source: TransUnion) ### The threat Synthetic identities backed by forged pay stubs and doctored statements sail through underwriting. By the time repayment fails, the 'borrower' never existed. ### Plugged into origination, not bolted on after ScamAI sits inside origination, before funds move: each pay stub, statement, or selfie is scored by the REST API with the signals behind it. Auto-decline clear forgeries, route borderline files to review, and pass clean applications untouched. ### Income documents are where the fraud lives Most loan fraud needs fake income, not a fake person: a doctored payslip or inflated balance clears every identity check. Eva V1.6 reads each file for editing and AI-generation artifacts and flags one template reused across applications (TransUnion puts lender exposure at $3.1B a year). ### FAQ Q: How do lenders detect fake pay stubs and bank statements? A: Fake income documents are detected through forensic analysis rather than visual review: examining files for editing artifacts, font and layout inconsistencies, and signs of AI generation that persist even in convincing forgeries. Detection also compares documents across applications, since fraud rings reuse templates with only the numbers changed. ScamAI runs these checks through a REST API inside the origination flow, returning a per-document tamper result with evidence, so underwriters see which files need scrutiny instead of manually inspecting every PDF. Q: What is synthetic identity fraud in lending? A: In lending, synthetic identity fraud means a borrower who never existed: a blend of real and fabricated attributes, supported by forged pay stubs and statements, that passes underwriting, then defaults with no one to collect from. TransUnion measured U.S. lender exposure at $3.1B in a single year. Because the applicant cannot appear in person, the fraud depends entirely on media — a rendered face at verification and doctored documents — and both are detectable at origination, before the loan funds. Q: Can loan application fraud be detected before funding? A: Application fraud is most detectable at origination, because that is when the fabricated material is submitted at once: the selfie, the ID, and the income documents. Screening each for manipulation at upload catches the fraud while the decision can still change cheaply — a decline or a step-up rather than a charge-off. ScamAI returns results in real time inside the approval flow, and batch endpoints let lenders rescan existing books for synthetic applicants approved before detection was in place. ## Insurance claims fraud detection URL: https://scam.ai/solutions/insurance-claims Verify claim photos, videos, and documents are genuine — not staged, edited, or AI-fabricated. Key stat: $308B — the annual cost of insurance fraud in the U.S. (source: Coalition Against Insurance Fraud) ### The threat Claimants generate damage photos that never happened, edit real images to exaggerate a loss, and fabricate supporting paperwork with consumer AI tools. ### From FNOL to result without slowing the claim Detection runs at first notice of loss: each uploaded photo, video, or document is scored by the REST API with evidence attached. Clean media stays straight-through, and flagged media routes to an adjuster or SIU without changing the claimant experience. ### The new fraud is editing reality, not inventing it The hard problem is exaggeration, not fabrication: AI-extended damage or one changed digit passes every metadata check, because only the pixels lie. Eva V1.6 detects localized manipulation inside otherwise genuine images and localizes the edited region (insurance fraud already costs the U.S. $308B a year). ### FAQ Q: How do insurers detect AI-generated or edited claim photos? A: AI-generated and edited claim photos are caught by forensic analysis of the image itself: generation artifacts, inconsistencies in lighting and texture, signs of localized editing, and traces left by manipulation tools. ScamAI applies these checks to every photo, video, and document at upload through the REST API, returning a scored result with evidence attached, so adjusters know which files to trust before adjudication begins. Q: What is a shallowfake in insurance fraud? A: A shallowfake is a genuine photo or document altered with basic editing tools rather than generated from scratch — real damage extended, a date changed, an amount inflated. Shallowfakes are harder to catch with context checks because the underlying media is authentic; the manipulation is localized. Detecting them requires pixel-level forensics that identify edited regions inside otherwise real images. ScamAI flags both shallowfakes and fully AI-generated media, and tells the adjuster which kind it found. Q: Does fraud detection slow down legitimate claims? A: Media screening runs automatically between upload and adjudication, so genuine claims are not delayed — a clean result keeps the claim on the straight-through path with no extra step for the claimant. The effect is usually the opposite of friction: because fabricated and manipulated media is filtered out with evidence attached, adjusters spend less time on manual suspicion and more legitimate claims qualify for fast-track handling. Fraud detection at intake is what makes higher automation rates safe. ## Meeting deepfake protection URL: https://scam.ai/solutions/meeting-security Continuous verification of who is really on the call — powered by Halo. Key stat: $25M — stolen in a single deepfaked video call — every 'participant' but the victim was synthetic (source: Arup case, 2024) ### The threat One synthetic participant on one video call can move millions. Deepfaked vendors, cloned colleagues, and replayed backgrounds are already inside enterprise meetings. ### What Halo does during the call The check runs the whole way through the meeting, on the participant's device, not just at the door. ### Verified at join is not verified at minute forty A call is live: a participant can hand off, an account can be compromised, or a synthetic face can switch on right when the meeting turns to money. Halo holds the result for the whole call, not just the join. ### FAQ Q: How can you tell if someone on a video call is a deepfake? A: Human tells — odd blinking, blurring at the edge of the face, lag between expression and movement — are increasingly unreliable, because modern face swaps have eliminated most visible glitches. Reliable identification requires algorithmic analysis of the video itself: generation artifacts, face-boundary inconsistencies, and signals invisible to a participant watching a compressed stream mid-conversation. Halo runs that analysis continuously on-device during the call and surfaces a risk signal when a face is synthetic, taking the judgment off the busy participant. Q: What is on-device deepfake detection and why does it matter for meetings? A: On-device detection means the analysis runs locally on the participant's machine instead of sending call video to the cloud. For meetings this matters twice: sensitive discussions — deals, legal matters, board business — never leave the device to get a result, and detection works in real time without a network round trip. Halo runs Eva V1.6 locally, verifying faces and backgrounds continuously. ScamAI is SOC 2 Type II audited and GDPR compliant; with Halo, the meeting content is never shipped anywhere. Q: What was the $25M deepfake video call incident? A: In the 2024 Arup case, a finance employee joined a video call to discuss a confidential transaction. Every other participant — including the CFO who authorized the payment — was a deepfake. Initially suspicious of an email request, the employee was reassured by familiar faces on video and transferred roughly $25M across multiple payments. It is the canonical example of why video now needs verification: being on the call is no longer proof of who is on the call. ## Pig butchering scams URL: https://scam.ai/solutions/pig-butchering Detect the fake faces and forged proof behind long-con romance and investment scams — before your users are drained. Key stat: $5.8B — reported U.S. losses to crypto-investment ('pig butchering') scams in 2024 (source: FBI IC3) ### The threat Scammers spend weeks building trust with a fabricated persona, using AI-generated profile photos and deepfake video calls, then steer the victim into a fake investment platform. By the time the money moves, the 'person' never existed. ### Detection at every stage of the con Pig butchering touches several products before money moves, and ScamAI scores the media at each one through the REST API: profile photos at signup, video-call frames for face swaps, and the fake dashboards, statements, and payment proofs shown to victims. Each result is a separate chance to break the con before the savings leave. ### Weeks of runway means weeks of chances to intervene Pig butchering is slow by design, and that patience is its weakness: every stage leaves synthetic media behind, from the generated profile photo to the deepfaked call to the fake trading dashboard and the forged withdrawal-fee invoice. Detecting any one of them interrupts the con while the victim has lost little or nothing (the FBI counted $5.8B in reported U.S. losses in 2024). ### FAQ Q: What is a pig butchering scam? A: Pig butchering is a long-con investment scam: the fraudster builds a weeks-long relationship with the victim — often romantic, started on a dating app or through a wrong-number message — then introduces a fake investment platform showing fabricated returns. The victim invests more, fattening the pig, until the scammer disappears with everything. The persona is synthetic, built on AI-generated photos and deepfaked video calls. The FBI attributed $5.8B in reported U.S. losses to these crypto-investment scams in 2024. Q: How can platforms detect romance scammers using AI-generated photos? A: AI-generated profile photos carry statistical artifacts that detection models identify even in flawless-looking images — inconsistencies in how generators render texture, lighting, and facial detail. Screening at signup catches synthetic personas before they contact anyone, and rescreening when an account shows scam-pattern behavior catches personas that changed photos later. ScamAI's REST API returns a scored result per image, so trust and safety teams can gate, review, or ban on thresholds they control instead of waiting for user reports. Q: How can banks stop pig butchering before the money is gone? A: Banks usually meet pig butchering at the transfer, when a customer moves unusual sums to crypto exchanges or unfamiliar accounts. The intervention problem is that victims defend the scam — they believe the investment is real. Forensic evidence changes those conversations: screening the proof the victim was shown — platform screenshots, account statements, payment confirmations — produces a manipulation result a banker can show the customer. Proving the document is forged is more persuasive than saying the relationship is fake. ## Deepfake social engineering attacks URL: https://scam.ai/solutions/social-engineering Catch the deepfaked faces attackers use to manipulate employees into transfers, access, and approvals. Key stat: 3,000% — growth in deepfake-based fraud attempts in a single year (source: Onfido Identity Fraud Report) ### The threat Modern social engineering wears a real face: a deepfaked executive on a video call, or an urgent message that looks like it came from someone you trust, pressuring an employee to move money or hand over access. In the 2024 Arup case, one such call moved $25M. ### A verification layer across your riskiest requests Social engineering converges on a few moments like a payment approval, a credential reset, or an access grant, so ScamAI deploys there: employees who handle them run Halo to verify faces in every meeting on-device. Any media used to build trust is scored through the REST API, and a flagged face or forged document pauses the request for verification through a known channel. ### Awareness training assumed the fake would look fake A decade of training taught employees to hunt for tells like bad grammar and video that looks off, but generative AI retired those tells (Onfido measured 3,000% single-year growth in deepfake fraud attempts). Training still matters for the instinct to slow down and verify, but the human eye can no longer be the detection layer: people own pausing and verifying out-of-band, software owns judging whether the face is real. ### FAQ Q: What is deepfake social engineering? A: Deepfake social engineering is manipulation that borrows a trusted face: an attacker appears on video as an executive, colleague, or vendor and uses that trust to push an employee into a transfer, a credential reset, or an access grant. It extends classic pretexting with synthetic media convincing enough to defeat visual judgment, stacking urgency and confidentiality to keep the target from verifying. Defenses combine process — out-of-band verification for sensitive requests — with in-meeting detection that flags the fake directly. Q: Can employees be trained to spot deepfakes? A: Training helps with process but not with perception. Employees can reliably learn to pause on urgent requests, verify through separate channels, and escalate anomalies — behaviors that stop many attacks however good the fake. What they cannot learn is to see deepfakes: modern face swaps eliminate the glitches older awareness material taught people to find. Effective programs pair the trained behaviors with algorithmic detection, such as Halo running during meetings, so identifying the synthetic face is not a human responsibility. Q: How should a company verify an urgent request made over video? A: Urgent video requests should be verified through a channel the requester did not control: a phone number from the directory, a message in the corporate chat thread, or an in-person check — never contact details provided during the call. The policy works best unconditional, applied to every payment or access request above a threshold, because attackers engineer exceptions to feel justified. In-meeting detection strengthens the policy by flagging synthetic faces during the call, giving employees grounds to invoke it. ## HR / Hiring URL: https://scam.ai/solutions/hiring-fraud Protect hiring end to end — make sure the person you interview is the person you hire, not a deepfake stand-in or a proxy. Key stat: 1 in 4 — candidate profiles worldwide projected to be fake by 2028 (source: Gartner) ### The threat Remote hiring has a new fraud: a real interviewee replaced by a deepfake, or a proxy standing in for the candidate who was screened. It is a growing vector for insider risk and sanctioned-actor infiltration. ### From first interview to first day Detection covers the two points where identity can be swapped: Halo flags a swapped or lip-synced face live in the interview, and the REST API confirms at onboarding that the hire matches who interviewed. Flagged interviews follow a set path of re-interview, escalation, or withdrawal, while genuine candidates notice nothing. ### How the fake candidate actually gets through The usual pattern is a real person interviewing behind a real-time face swap, or a proxy answering off-screen while someone else shows up to work. The stakes reach sanctioned-actor infiltration with code and payroll access, and the interview is the last moment the fraud must perform live (Gartner projects one in four candidates will be fake by 2028). ### FAQ Q: How do fake candidates use deepfakes in remote job interviews? A: Fake candidates run real-time face-swap software fed into the call through a virtual camera, so the interviewer sees a fabricated face that moves naturally — driven by a real person who is not who they claim to be. Variants include lip-sync overlays and proxy setups where an off-screen expert supplies answers. The goal is to pass assessment as one identity and place a different person, or a sanctioned actor, into the role. Detection during the interview flags the swap mid-conversation. Q: How can recruiters verify a remote candidate is real? A: Recruiter-level checks — asking the candidate to turn their head, wave a hand across their face, or adjust the lighting — can disrupt some older face swaps, but current tools handle these prompts well, and the checks make interviews adversarial for genuine candidates. Reliable verification pairs the interview with on-device detection: Halo analyzes the candidate's video continuously and flags swapped or rendered faces without the choreography. Identity verification at onboarding then confirms the new hire matches the person who interviewed. Q: Why is hiring fraud a security problem and not just an HR problem? A: A fraudulent hire is an insider threat with a badge: day one brings credentials, source code access, customer data, and a paycheck that can flow to a sanctioned entity. Documented cases include remote IT workers placed by hostile states inside Western companies this way. So the response spans recruiting and security together — screening interviews for deepfakes, verifying identity at onboarding, and treating a flagged candidate as a security event with an escalation path, not merely a rejected application. ## Content moderation URL: https://scam.ai/solutions/content-moderation Score uploads for AI generation and manipulation before synthetic content spreads. Key stat: 8M — deepfakes projected to be shared online in 2025 — up from 500k in 2023 (source: World Economic Forum) ### The threat Synthetic media arrives faster than human moderation can review it: deepfaked public figures, AI-generated abuse material, and coordinated fake content at platform scale. ### One API call between upload and publish Detection slots into the ingest pipeline you already run: each uploaded image or video is scored by the REST API before it goes live, with the evidence behind it. Auto-action at high confidence and queue humans at medium, on thresholds your policy team tunes per surface. ### Detection powers labeling, not just takedowns Policy is no longer allow-or-remove, since much AI content is legitimate and the real duty is disclosure. A scored result lets platforms label routine synthetic content, restrict synthetic media of real people, and remove deceptive deepfakes (the World Economic Forum projected 8M deepfakes shared online in 2025). ### FAQ Q: How do platforms detect AI-generated content at scale? A: At platform scale, detection runs as an automated scoring step in the upload pipeline: every image and video is analyzed for generation artifacts, face swaps, and manipulation before publication, and the score feeds moderation rules as spam and abuse signals already do. Human review is reserved for the contested middle. ScamAI's REST API is built for this pattern, with real-time results at upload, batch endpoints for library rescans, and evidence attached to each result for moderator review and transparency reporting. Q: Can deepfake detection keep up with upload volume in real time? A: Real-time detection at upload volume is an architecture question: the check must return a result within the latency budget of the publish flow and scale with traffic. ScamAI's API is designed for both modes — synchronous scoring for the upload path and batch processing for backfills and rescans — so platforms do not choose between coverage and speed. The practical pattern is scoring everything at ingest, auto-actioning only at high confidence, and letting the moderation queue absorb the borderline cases. Q: Should AI-generated content be removed or labeled? A: Most platforms are converging on tiered enforcement rather than blanket removal: benign synthetic content stays up with a label, synthetic depictions of real people face restrictions, and deceptive deepfakes — fabricated statements, non-consensual imagery, fraud content — are removed. Every tier depends on knowing the content is synthetic, which self-disclosure alone cannot provide. Automated detection supplies that knowledge at scale, and results with evidence let platforms defend both the label and the takedown in appeals and transparency reports. ## Misinformation detection URL: https://scam.ai/solutions/misinformation Detect the deepfakes and synthetic media behind misinformation before it spreads and erodes trust. Key stat: 90% — of online content could be AI-generated by 2026 (source: Europol Innovation Lab) ### The threat Deepfaked officials, fabricated events, and AI-generated media spread faster than they can be debunked. The 'liar's dividend' also lets bad actors dismiss real footage as fake. ### Results at the speed of the news cycle Newsrooms and fact-checkers submit suspect media to the REST API and get back a scored, evidence-backed result fast enough for the piece being written now. Because each result names the signals that fired, the output is citable. ### Verifying the real is half the job Once the public knows video can be faked, anyone caught on genuine footage can call it synthetic, so detection has to run both ways. A clean result is as valuable as a flag, letting a newsroom stand behind authentic footage (Europol projects up to 90% of online content could be AI-generated by 2026). ### FAQ Q: How do fact-checkers verify whether a video is a deepfake? A: Fact-checkers combine traditional verification — sourcing the original upload, checking location and timing, contacting the people depicted — with forensic analysis of the media, examining faces and frames for generation artifacts and manipulation traces that survive compression. The forensic layer matters most when a fake is well made and context checks are inconclusive. ScamAI provides that layer through the REST API: a scored result with the signals that fired, delivered fast enough to inform coverage before the content peaks. Q: What is the liar's dividend? A: The liar's dividend is the benefit bad actors gain from the existence of deepfakes: because the public knows video can be fabricated, genuine footage can be dismissed as fake. The term describes a second-order harm of synthetic media — beyond deceiving people with fakes, it corrodes the evidentiary value of everything real. Countering it requires the ability to affirm authenticity, not just flag manipulation — so results that clear genuine media matter as much as results that catch fakes. Q: Can detection tools confirm that footage is authentic? A: Detection models score media in both directions: a result can flag signs of AI generation or manipulation, or report none are present, with evidence behind either conclusion. A clean forensic result is not absolute proof, but combined with provenance and sourcing it gives newsrooms and platforms grounds to treat footage as genuine — and resist pressure to retract real material dismissed as fake. ScamAI attaches the fired signals to every result so the reasoning is citable, not just the score. ## Deepfake brand protection URL: https://scam.ai/solutions/brand-protection Catch the deepfakes, fake ads, and impersonations that hijack your brand and your executives' likenesses. Key stat: $2.9B — reported consumer losses to impersonation scams in 2024 (source: FTC) ### The threat Attackers clone your executives, run fake ads carrying your logo, and spin up impersonation accounts, driving fraud that looks like it came from you. ### From suspicious sighting to takedown-ready evidence Send suspect media to the REST API and get back a result on whether an executive's face is generated or an ad shows AI manipulation, with the signals behind the call. Confirmed fakes move into your takedown workflow with forensic evidence attached. ### Every fake ad spends your trust to scam your customers Brand impersonation is a double theft: your customers lose money to a fake fronted by your CEO's face, and your brand absorbs the durable damage as every victim ties the scam to your name. Speed is the defense that matters, since a fake that runs for weeks instead of hours is measured in victims, and detection with evidence compresses the time from sighting to takedown (the FTC counted $2.9B in reported impersonation losses in 2024). ### FAQ Q: How do companies detect deepfake ads using their executives? A: Deepfake ad campaigns are detected through a combination of monitoring and forensics: social listening and ad-library monitoring surface suspect creative, and detection models then confirm whether the executive's face is genuine or AI-generated. The forensic step matters because takedown requests supported by evidence move faster than bare assertions. ScamAI scores suspect media through the REST API, returning results with the signals that fired so brand and legal teams can act immediately. Q: How do you get a deepfake impersonation taken down? A: Takedowns run through the platform hosting the content — social networks, ad networks, app stores, or registrars — and speed depends on the quality of the report. A request with forensic evidence the media is AI-generated, alongside proof of the impersonated party's identity, is harder to deprioritize than a bare complaint. ScamAI results attach that evidence: the manipulation score and the signals that fired. Companies route confirmed fakes into a prepared takedown workflow so the response takes hours, not weeks. ## AI phishing & spam detection URL: https://scam.ai/solutions/phishing-spam Screen the images, documents, and media inside phishing and spam campaigns for AI generation and manipulation. ### The threat Phishing and spam increasingly carry AI-generated images, fake invoices, and synthetic identities to slip past filters and trick recipients into paying, clicking, or handing over credentials. ### A media forensics layer behind your mail filter ScamAI gives your mail gateway a signal it cannot produce: attachments and embedded media are scored by the REST API for AI generation and tampering. That score joins your filter's features, so a clean-looking message carrying a forged invoice still gets caught. ### The lure moved from text into images Filters read text but mostly skip images, so the lure moved into media: a pixel-perfect PDF invoice, a payment instruction hidden in a screenshot. Scoring the media itself catches the forged document by the forensic traces of its manufacture. ### FAQ Q: How is AI-generated phishing different from traditional phishing? A: Traditional phishing was detectable by its flaws: template reuse, crude forgeries, and language errors that filters and users learned to catch. AI-generated phishing removes the flaws and adds variation — every message and forged document can be unique, defeating signature and hash-based blocking, and lures arrive as convincing images and PDFs rather than suspicious text. Detection shifts accordingly: instead of matching known-bad patterns, filters need forensic signals on whether the media was generated or manipulated — the layer ScamAI adds. Q: Can fake invoice attachments be detected automatically? A: Forged invoices carry detectable traces even when they look perfect: editing artifacts, font and layout inconsistencies, and signs of AI generation. Automated document forensics finds these at scale — every attachment scored as it arrives, not left to an accounts-payable clerk to notice. ScamAI's REST API returns a per-document result with evidence, which mail security stacks consume as another signal: a message with a synthetic invoice gets quarantined or flagged even when its text and sender pass every other check. Q: What is image-based phishing and why do filters miss it? A: Image-based phishing puts the deception inside media instead of text: a screenshot styled as a security alert, a QR code replacing a clickable link, a payment instruction rendered as a picture. Filters tuned to message text and URLs miss it because such messages carry minimal, innocuous text — the attack lives in pixels the classifier never reads. Countering it requires analyzing the media for manipulation and synthetic origin — a media forensics signal alongside conventional filtering closes the gap. # Industries ## KYC/AML compliance URL: https://scam.ai/industries/kyc-aml-compliance Meet KYC and AML obligations against AI-era fraud — deepfake selfies, forged IDs, and synthetic identities caught at onboarding and beyond. Key stat: $4.6B — in AML and KYC enforcement actions issued globally in 2024 (source: Fenergo) ### Compliance under AI-era fraud Regulators expect you to keep synthetic identities and manipulated documents out of onboarding. ScamAI scores the selfie for deepfakes, verifies liveness, and checks every submitted document for forgery — so your KYC/AML program holds up against generative-AI attacks. ### Auditable by design Every result ships with the signals that fired, giving compliance teams and auditors defensible evidence for approve, decline, and enhanced-due-diligence decisions — not an opaque score. ### What examiners expect now that IDs can be generated KYC rules assumed the hard part was matching a person to a document; generative AI broke that assumption. FATF guidance asks whether your identity-proofing resists spoofing, the Bank Secrecy Act's Customer Identification Program rule requires a reasonable belief in each customer's true identity, and FinCEN's 2024 alert lists the generative-AI red flags institutions should detect and report. ScamAI answers all three with documented, testable detection of deepfake selfies and forged documents, with evidence trails built for examiner review. ### Where detection sits in the verification stack Eva V1.6 slots into your existing stack as a dedicated synthetic-media layer, not another all-in-one IDV tool: it scores the selfie for AI generation before the biometric match runs — a match against a fake face is still a fake — and runs forensics on every ID and supporting document. The same checks re-run at enhanced due diligence and periodic refresh, so a customer who onboarded legitimately cannot later swap in synthetic media unnoticed. With $4.6B in AML and KYC enforcement actions issued globally in 2024, an audit trail that carries reasons rather than bare scores is the point. ### FAQ Q: How are deepfakes used to bypass KYC checks? A: Fraudsters attack KYC at two points. At the selfie step, they use face swaps, AI-generated faces, or replayed synthetic video to pass liveness and biometric matching — often injecting the fake feed into the session with a virtual camera. At the document step, they submit AI-generated or template-forged IDs and proof-of-address documents. Because both artifacts agree with each other, the fake identity sails through checks that only match a face to a document; detection has to interrogate the media itself. Q: Do regulators require deepfake detection for KYC and AML programs? A: No rule names a specific technology, but the expectations point one way. The U.S. Customer Identification Program rule requires a reasonable belief in a customer's true identity, FinCEN's 2024 alert asks institutions to identify and report deepfake-related red flags, and FATF guidance tells firms to evaluate whether their identity-proofing resists spoofing. If synthetic identities are passing your onboarding, examiners will ask what controls you had — documented synthetic-media detection is the clearest way to show your program kept pace. Q: What evidence does a compliance team get with each detection result? A: Every ScamAI result includes the signals that drove it: which regions of a face or document showed manipulation, what class of generation or tampering was detected, and the confidence behind the score. An analyst reviewing a declined onboarding can see why, an MLRO can cite indicators in a suspicious activity report, and an auditor can trace any decision to evidence. Results are retained while the underlying media is discarded after scoring — a complete audit trail without a data-retention liability. ## On-device deepfake detection agent URL: https://scam.ai/industries/on-device-agent Real-time detection that runs on the device — media and identity verified locally, with nothing leaving the endpoint. Shipping today in Halo; an embeddable agent for your own apps and devices is in development. Key stat: 1 / 5 min — a deepfake fraud attempt occurred every five minutes in 2024 (source: Entrust Identity Fraud Report) ### Detection at the edge The same Eva V1.6 detection runs locally on the endpoint: deepfakes, forged documents, and manipulated media flagged in real time without a round trip to the cloud. Halo ships this today for live video meetings. Packaging the same engine as an embeddable agent your own app or device can call is in development, alongside the native SDKs on the API roadmap. ### Private and always on Because analysis happens on the endpoint, sensitive media never leaves the device — ideal for regulated environments, offline scenarios, and low-latency flows where cloud calls aren't an option. ### Data minimization as a compliance position To check media for manipulation, most architectures ship it to someone's cloud — and for regulated deployments that round trip is itself a compliance event, raising GDPR questions about data minimization, purpose limitation, and cross-border transfer. On-device detection removes the event entirely: Eva V1.6 runs locally and only the result leaves the device, so a privacy impact assessment has no new data flow to assess. ScamAI is SOC 2 Type II audited and GDPR compliant, and your users' faces never become someone else's dataset. ### Where an edge detection agent fits The embeddable agent is being built for capture-time checks inside banking and fintech apps, kiosks and retail counters that need to verify the person standing there, and field or regulated endpoints where data cannot leave the machine. Today the shipping path for on-device detection is Halo on the participant's own machine, with the REST API covering every other integration in the meantime. If one of these patterns is yours, tell us — early access shapes what we build first. ### FAQ Q: What is on-device deepfake detection? A: On-device deepfake detection runs the model on the endpoint — a phone, kiosk, laptop, or embedded device — instead of sending media to a cloud API. The device captures a face image, document photo, or video frame; the local model scores it for AI generation and manipulation; the app gets a result in real time. Because analysis happens where media is captured, nothing sensitive leaves the device: lower latency, offline operation, no new data flow for privacy review. Q: Does the on-device agent work without an internet connection? A: Yes — that is the point of running inference on the endpoint: results do not depend on connectivity. Halo already works this way, analyzing meeting video locally on the participant's machine. The same property is what makes the embeddable agent, currently in development, suited to kiosks in low-coverage locations, field workflows like claims adjusting or benefits processing in remote areas, and any environment where the network is untrusted or intermittent. Model updates arrive when the device connects, and result metadata can queue for later sync if you want centralized reporting. Q: How is an on-device agent different from calling a detection API? A: Both return the same thing: a manipulation result with signals from the Eva V1.6 model. The difference is where the media goes. With the REST API — available today, in any language — your backend sends media to ScamAI, which analyzes, scores, and discards it; right for server-side pipelines like upload moderation or claims processing. On-device, the model runs on the endpoint instead, so media never leaves it: today that ships as Halo for live meetings, and as an embeddable agent for your own apps once it is out of development. Teams choose on-device for privacy-sensitive capture, offline operation, and latency budgets. ## Deepfake detection for financial services URL: https://scam.ai/industries/financial-services Stop synthetic identities at onboarding and deepfaked executives on video calls before the wire is released. Key stat: $40B — projected U.S. fraud losses enabled by generative AI by 2027 (source: Deloitte) ### Where banks get hit KYC bypass with rendered faces, forged statements in lending, and deepfaked executives authorizing transfers. ### How ScamAI helps Eva V1.6 screens enrollment selfies and document uploads for AI generation and tampering, and Halo flags deepfaked participants in the meetings where transfers get approved — every result with evidence attached. ### One platform across the bank From retail onboarding to lending-document intake to executive wire approvals, the same detection covers every trust decision — no separate point solution to buy and wire up per channel. ### Mapping detection to FinCEN and BSA expectations FinCEN's late-2024 alert warned institutions about deepfake media used to defeat identity verification, and reminded them that suspected generative-AI use belongs in suspicious activity reporting — putting synthetic-media detection inside existing Bank Secrecy Act obligations. Eva V1.6 scores enrollment selfies and uploaded documents for AI generation and manipulation, and every result ships with the signals that fired: concrete language for SAR narratives instead of a hunch. ScamAI is SOC 2 Type II audited and GDPR compliant, so the detection layer does not create a new audit finding. ### From account opening to wire release Detection only reduces losses where money actually moves: account opening, where Eva V1.6 screens the applicant's selfie and ID before provisioning; the lending pipeline, where pay stubs and statements get forensics before underwriting sees them; and high-value approvals, where Halo flags synthetic video in the meeting authorizing the transfer. Each check is a REST API call that drops into your existing orchestration, so fraud teams keep their case-management tools and decision engines. Deloitte projects $40B in U.S. fraud losses enabled by generative AI by 2027 — the institutions instrumenting these checkpoints early set the loss curve. ### FAQ Q: How do banks detect deepfakes during digital account opening? A: Banks layer synthetic-media detection on top of standard identity verification. When an applicant submits a selfie and ID, a detection model like Eva V1.6 analyzes the face for AI generation, face swapping, and presentation attacks, while document forensics checks the ID and supporting paperwork for tampering and generated content. The result is a verdict with a confidence and evidence that feeds the bank's decision engine: genuine applicants pass in seconds, and suspicious enrollments route to manual review before an account is opened. Q: What did FinCEN say about deepfakes, and what should banks do about it? A: FinCEN's 2024 alert warned that criminals are using deepfake media, including AI-generated identity documents and altered photos, to open accounts and defeat verification. It asked institutions to watch for red flags like inconsistencies between a customer's photo and their document, and to reference generative-AI indicators in suspicious activity reports. Practically, banks should add synthetic-media scoring at onboarding and document intake, with detection tooling that produces explainable evidence for SAR narratives and examiners. Q: Can deepfake detection integrate with our existing KYC vendor? A: Yes. ScamAI sits alongside, not in place of, your identity verification stack. The REST API accepts the same selfie and document images your KYC vendor already captures and returns a manipulation result with the signals that fired. Most teams call it from their orchestration layer as an additional onboarding check, using the score to trigger step-up verification or review. No rip-and-replace: your IDV provider keeps matching identities, and ScamAI answers the separate question of whether the media itself is real. ## Deepfake detection for the public sector URL: https://scam.ai/industries/public-sector Protect officials and citizens from impersonation campaigns. Key stat: $2.9B — lost to impersonation scams — including fake government agencies — in 2024 (source: FTC) ### Where government gets hit Deepfaked officials spreading disinformation, forged documents in benefits claims, and synthetic identities defrauding public programs at scale. ### How ScamAI helps Eva V1.6 scores documents at benefits intake and verifies media for press teams; Halo protects staff meetings on-device. Every result ships with the evidence behind it. ### Trust in public communication When an official's likeness can be faked in minutes, verified media keeps citizens able to trust what their government actually said — and to spot what it didn't. ### Impersonation now has its own rulebook Impersonating a government official has always been a federal crime; generative AI made it scalable, and in 2024 the FTC's Government and Business Impersonation Rule took effect to match. NIST's digital identity guidelines (SP 800-63) contemplate exactly the presentation and injection attacks that deepfake selfies and forged documents represent. ScamAI covers both directions — media verification to protect citizens from fake versions of you, deepfake and document forensics at intake to protect programs — each producing evidence an oversight body can review. ### From benefits intake to the press office At benefits intake, Eva V1.6 runs document forensics on identity documents and income statements before eligibility decisions are made — the same checkpoint where synthetic identities drained pandemic-era programs. In the press office, media verification gives comms teams a defensible answer when a video of an official surfaces, before the clip finishes its first news cycle. For sensitive coordination, Halo runs on staff machines during video meetings without sending meeting content anywhere. ### FAQ Q: How can a government agency verify whether a video of an official is real? A: Run the clip through a detection model built for synthetic media. ScamAI's Eva V1.6 analyzes the video frame by frame for face swapping, AI generation, and manipulation, and returns a result with the signals that drove it. That gives a communications team something a press statement can stand on: not just "we believe this is fake," but documented detection evidence, available in minutes. Q: How does deepfake detection reduce benefits and public-program fraud? A: Most program fraud enters through intake: forged identity documents, AI-generated pay stubs and statements, and synthetic identities assembled to pass remote verification. Detection at intake scores every document and selfie for generation and tampering before an eligibility decision is made, routing suspicious cases to investigators with evidence attached. That shifts fraud control from pay-and-chase to prevention at the front door, and aligns with the identity-assurance expectations in NIST's digital identity guidelines that most U.S. agencies build their remote proofing around. Q: Can public-sector deployments keep media on their own infrastructure? A: Yes. For meeting protection, Halo runs entirely on the endpoint: detection happens on the staff member's machine and meeting content never leaves it. For intake and verification pipelines, the on-device agent brings the same Eva V1.6 model inside your boundary, so document and face analysis runs locally where policy prohibits external services. Where the REST API is used, media is analyzed, scored, and discarded (ScamAI retains results, not content), and the company is SOC 2 Type II audited and GDPR compliant. ## E-commerce & marketplaces URL: https://scam.ai/industries/e-commerce-marketplaces Keep fake sellers and cloned storefronts out. Key stat: $48B — global e-commerce losses to online payment fraud in 2025 (source: Juniper Research) ### Where marketplaces get hit Synthetic seller identities, AI-generated product imagery for goods that don't exist, forged business documents, and cloned storefronts harvesting buyers. ### How ScamAI helps Seller onboarding liveness, document verification on business credentials, and image forensics on listings — trust signals for every side of the marketplace. ### Trust for both sides Buyers meet real sellers and genuine listings; sellers reach a marketplace that isn't overrun by clones and fakes — protection for the whole transaction, not just one side of it. ### Seller verification is law now, not best practice In the U.S., the INFORM Consumers Act requires marketplaces to collect and verify bank, tax, and contact details from high-volume third-party sellers; in the EU, the Digital Services Act's traceability-of-traders provisions require verifying trader information before they can sell. Both regimes assume the documents sellers submit are checkable — exactly what generative AI undermines, now that a fraud ring can fabricate a matching set of registration, ID, and bank documents. Eva V1.6 runs forensics on seller credentials and deepfake screening on verification selfies, so what you are legally required to verify is tested for synthesis, not just collected. ### Detection across the marketplace lifecycle Marketplace fraud is not a single event, so detection is not a single checkpoint: deepfake and document screening at seller onboarding, image forensics on listing photos to catch goods that do not exist, and re-verification at payout redirection or credential recovery to close the account-takeover path. In disputes, media checks on buyer-submitted damage and return photos separate genuine claims from refund abuse. Each is one REST API call — and with Juniper Research putting 2025 e-commerce losses to online payment fraud at $48B, prevention compounds at these moments. ### FAQ Q: How do online marketplaces detect fake sellers? A: Layered verification at onboarding. The applicant's selfie is screened for deepfakes and AI-generated faces, their identity and business documents get forensic analysis for forgery and generation, and the results feed the marketplace's risk decision before selling privileges are granted. It matters because fraud rings submit internally consistent document sets that pass visual review. Detection models like Eva V1.6 examine the media itself (generation artifacts, tampering traces, template reuse), so a fabricated seller package gets caught even when the documents agree. Q: Can AI-generated product images be detected on listings? A: Yes. Image forensics can identify product photos AI-generated rather than captured, plus composites and manipulations. That signal matters for two abuse patterns: listings for goods that do not exist, where the storefront is synthetic and buyers pay for nothing, and counterfeit listings dressed up with generated imagery to dodge duplicate-image matching against the original store. Marketplaces score listing images through the REST API at publish time, gating high-risk listings for review before they go live, not after buyer complaints arrive. Q: What does the INFORM Consumers Act require marketplaces to verify? A: The INFORM Consumers Act requires marketplaces to collect and verify information from high-volume third-party sellers (bank account details, government-issued ID or tax documentation, and contact information) and to suspend noncompliant sellers. It also mandates disclosure of seller information to buyers past thresholds. The catch: collection is easy, and verification is where fraud lives; AI-generated IDs and fabricated business documents satisfy a checkbox process. Document forensics and deepfake screening make the verification step substantive, which is what the statute asks for. ## Dating apps URL: https://scam.ai/industries/dating-apps Keep fake profiles, AI-generated photos, and deepfaked video calls off your platform — before they turn into romance scams. Key stat: $1.1B — reported U.S. losses to romance scams in a single year (source: FTC) ### Where dating apps get hit Scammers build trust with fabricated personas — AI-generated profile pictures, deepfaked video calls — then steer matches toward money or fake investments. The whole con depends on the fake looking real. ### How ScamAI helps Screen profile photos for AI generation at signup, check verification selfies for deepfakes and presentation attacks, and surface synthetic-persona risk signals early — protecting users while the con is still warming up. ### Safety duties are shifting from optional to statutory The UK's Online Safety Act puts duties on user-to-user services to assess and mitigate illegal content, and romance fraud — a crime built on fake personas — sits squarely inside that duty, while the EU's Digital Services Act requires platforms to act on illegal content and be transparent about moderation. Every one of these regimes presumes the platform can tell fabricated personas from real ones. ScamAI supplies that: AI-generation screening on profile photos, deepfake and presentation-attack detection on verification selfies, and risk signals your trust and safety team can document. ### From signup to verified profile At signup, every profile photo is scored for AI generation — one REST API call in your upload path — catching the fabricated faces that anchor scam personas before a profile reaches the match queue. At verification, Eva V1.6 screens the badge selfie for deepfakes and presentation attacks, so the badge means what users think it means instead of laundering a fake into credibility. Real-time screening inside your own in-app video calls needs the embeddable on-device agent, still in development; today the checkpoints are photo upload and verification. ### FAQ Q: How do dating apps detect fake profiles that use AI-generated photos? A: By scoring photos at upload rather than waiting for user reports. Generated faces carry statistical artifacts that detection models identify even when the image looks flawless. ScamAI's Eva V1.6 screens every profile photo at signup and on photo changes, returning a result before the profile enters matching. Front-door screening matters because AI-generated faces defeat the older defense: reverse-image search only catches photos stolen from somewhere else. A generated face has no source to find; detection must examine the image itself. Q: Can deepfakes be detected on live video calls inside a dating app? A: Real-time in-call screening is what the loophole demands — victims are told to "insist on a video call," and scammers answer with face-swapped video that passes inspection — but embedding it inside your own video stack requires the on-device agent, which is in development. What runs today is screening at the checkpoints you already control: profile photos at upload and verification selfies, both scored through the REST API for face swaps and presentation attacks. Platforms use those signals to gate a persona for review, warn the other user, or feed the account's risk score. Q: What does the UK Online Safety Act mean for dating platforms? A: The Online Safety Act puts duties on user-to-user services, dating apps included, to assess the risk of illegal content and take proportionate measures against it, with romance fraud among the harms in scope. Larger categorized services face expectations to offer identity-verification options. Practically, a platform must demonstrate systems that find fabricated personas: photo screening for AI generation, verification selfies checked for deepfakes, and documented enforcement. Detection results with evidence support the mitigation itself and the risk-assessment paperwork the regime requires. ## Telecom fraud detection URL: https://scam.ai/industries/telecom Protect SIM changes, account access, and support channels from synthetic identities and social engineering. Key stat: $39B — estimated annual global losses to telecom fraud (source: CFCA Global Fraud Loss Survey) ### Where telecom gets hit A SIM swap starts with a story: an attacker armed with breached personal data talks a support rep or retail associate into moving a victim's number, then intercepts the one-time codes protecting their bank, email, and crypto accounts. Port-out fraud, account-recovery takeovers, and synthetic identities at activation follow the same pattern — the human check is the weakest link. ### How ScamAI helps ScamAI re-verifies the customer is live and real on high-risk changes — a face-liveness check the fraudster on the line can't pass — and surfaces device and document risk signals before a SIM or account moves. ### The FCC has rewritten the SIM-swap playbook The FCC's 2023 rules on SIM swapping and port-out fraud require wireless providers to authenticate customers securely before processing a SIM change or number port, and to notify the customer immediately — flexible on method, accountable for outcomes. They sit on top of long-standing CPNI obligations penalizing weak account-access controls, leaving one open question: what "secure authentication" means once generative AI defeats knowledge-based checks and naive photo review. ScamAI's answer interrogates the media itself — face liveness and deepfake screening on high-risk changes, document forensics on forged IDs in recovery flows. ### Where detection sits in the SIM-change flow The same entry points recur across the CFCA's estimated $39B in annual telecom fraud losses: SIM swaps, number ports, account recovery, and new-line activation. When a SIM change or port-out arrives — in-app, in store, or through support — the flow triggers a step-up face check screened by Eva V1.6 for deepfakes and presentation attacks, while identity documents in recovery flows get forensic scoring, so a forged ID fails however polished the story. The REST API drops into order-management and support flows, and the customer notification the FCC requires stays — detection makes the approval behind it trustworthy. ### FAQ Q: How can carriers prevent SIM-swap fraud? A: By making the authentication step before a SIM change resistant to the attacks in use. Knowledge-based questions fail because answers leak in breaches; SMS codes fail because the attacker captures the number. The durable control verifies the person: a face check screened for deepfakes and presentation attacks, in the carrier's app or on a retail tablet, plus document forensics on IDs in recovery flows. With the customer notifications the FCC now requires, that closes the social-engineering path into someone's number. Q: What do the FCC's SIM-swap rules require of wireless providers? A: The FCC's 2023 rules require wireless carriers to use secure methods to authenticate a customer before executing a SIM change or port-out, to notify the customer immediately on any such request, and to maintain processes for failed authentication and complaints. The rules deliberately avoid prescribing one technology; carriers choose methods that resist current attacks. That flexibility is why providers add face-based verification with deepfake screening on high-risk changes: its strength does not depend on secrets the attacker already holds. Q: Can identity verification with deepfake detection run in retail stores and the carrier app? A: Yes, and covering both matters, because fraudsters route to the weakest path. In the app, the SIM-change or recovery flow triggers a face capture that Eva V1.6 screens for deepfakes and presentation attacks before the request proceeds. In stores, the same verification runs on the retail tablet, so a walk-in with a forged ID faces the same check as a remote attacker. The on-device agent runs detection locally on the tablet or phone, keeping biometric media on the endpoint. # Resources ## Education URL: https://scam.ai/resources/education Learn how AI-driven scams work — and how to defend against them. ### Coming soon Guides, explainers, and live sessions walking through new attack techniques and how detection counters them. Until they land, the blog and research pages cover current attacks, and the Check if AI playground lets you test detection on your own media. Subscribe to AI Threat Weekly to get invited. ## Trust Center URL: https://scam.ai/resources/trust-center Security, privacy, and compliance documentation. ### Private by design Media is analyzed, scored, and discarded — we keep the results, not your content. Halo goes further: detection runs on-device and nothing leaves your machine. ### Compliance ScamAI is SOC 2 Type II audited and GDPR compliant, and a member of C2PA (the Coalition for Content Provenance and Authenticity). We share audit reports and security documentation under NDA — request access through the demo form. ## Changelog URL: https://scam.ai/resources/changelog What's new in ScamAI detection — models, APIs, and product. ### Shipping continuously We log model releases, detection-coverage updates, and API changes here as they ship. Subscribe through the demo form to get release notes in your inbox. ## Affiliate program URL: https://scam.ai/resources/affiliate Earn by referring teams that need deepfake and fraud detection. ### How it works Apply, get your tracking link, and refer teams that need deepfake or fraud detection. Every referral is tracked and reported transparently, and you earn a share of the revenue each one generates. ## Partner program URL: https://scam.ai/resources/partners Resell, integrate, or build on the ScamAI detection API. ### Who we partner with Identity platforms, fraud-ops vendors, meeting software, and system integrators embedding detection into their own products and services. ### Three ways to partner Resellers bring ScamAI detection to their own customers. Integration partners embed the REST API inside their identity, fraud-ops, or meeting products, so results show up in the workflow their users already run. And builders ship new products on the detection engine itself. Tell us which model fits — we scope it on the first call. ## Deepfake detection education program URL: https://scam.ai/resources/education-program Training, certification, and curriculum for partners, students, and institutions who want to teach and deploy deepfake detection. ### Who it's for Implementation partners enabling their teams, universities and bootcamps building media-forensics curricula, and researchers who want structured, hands-on access to detection tooling. ### What's included Guided courses on deepfakes, synthetic media, and detection; certification tracks; and lab access to the ScamAI API so learners work with real results, not slides. ## Our partners URL: https://scam.ai/resources/partnerships Build with ScamAI — technology, channel, and integration partnerships that embed deepfake detection into more products, platforms, and go-to-market motions. ### Partner with us Identity platforms, fraud-ops vendors, meeting software, system integrators, and consultancies bring ScamAI detection to their own products and customers — from deep API integrations to co-selling. ### How to become a ScamAI partner Whether you want to embed detection, resell it, or co-build a solution, tell us what you're building and we'll find the right way to work together. Most partner conversations start with a 15-minute demo on your own media. # Company ## About ScamAI URL: https://scam.ai/company/about ScamAI exists because seeing is no longer believing. We build the tools that let people and organizations trust what they see. ### The company ScamAI — built by Reality Inc. — is a team of researchers and engineers focused on one problem: detecting AI-generated deception at the moment it matters. That work ships as Eva V1.6, our unified detection API; Halo, on-device detection for live video calls; and one REST surface that scores media, identity, and documents. The company is SOC 2 Type II audited and GDPR compliant. ### What we believe Everyone deserves to know what's real. Detection should come with evidence, run where the risk is — on-device when privacy demands it — and evolve as fast as the attacks do. ### Research in the open The detection work is published, not just claimed: 13 papers across five research areas — deepfake detection, document forgery, and age-estimation robustness among them — with 7 open datasets and named authors on arXiv. That research feeds directly into the Eva V1.6 Detection Model, which is retrained as new generators appear. ### How we handle your data Media sent to ScamAI is analyzed to produce a result and then discarded — we keep the results and the evidence, not your content. Compliance documentation, our DPA, and the subprocessor list are published in the trust center for security review. ## Careers URL: https://scam.ai/company/careers Don't apply if you just want a job — this isn't one. Everyone here shares the same goal and the same faith: beat the criminals using AI to deceive people. The bar is high and we are ruthlessly selective. But if this is your fight, we want to hear from you. ### This is not a regular job We're a small team with one enemy: the people using generative AI to steal, impersonate, and defraud. Everyone is here for the mission, not the title — and for the refusal to let seeing stop meaning believing. ### A very high bar We are selective on purpose. We hire people who are exceptional at what they do and who care more about the outcome than the org chart. You'll own real surface area from week one and ship work that stands directly between scammers and the people they target. ### Who we're looking for We're hiring across Business Development and GTM, Marketing and Growth, and Detection Research and Engineering. If you can reach the teams under attack — or sharpen the detection that protects them — use the contact page to tell us what you'd take on and why this is your fight. ## Team URL: https://scam.ai/company/team The researchers and engineers building ScamAI — focused on detecting AI-generated deception at the moment it matters. ### Who we are A small, senior team spanning detection research, ML engineering, and product, backed by operators and researchers from across security and AI. ### How we work Close to the adversary and close to the customer: we retrain against new attack techniques as they appear and ship detection people can act on the same week. ## ScamAI vs Reality Defender URL: https://scam.ai/company/vs-reality-defender Reality Defender is a strong, well-funded media-authenticity layer — it flags AI-generated audio, video, image, and text, and now watches live calls. But it stops at detection: no document-forgery or liveness for identity flows, and every check runs server-side. ScamAI adds the identity and document layer, and runs detection on the endpoint itself with Halo. ### Reality Defender at a glance Reality Defender is a well-funded enterprise "authenticity layer": an ensemble flagging AI-generated audio, video, image, and text across its Real Suite — RealScan, RealCall, and RealMeeting — deployable cloud, private-cloud, or air-gapped. Gartner named it a "Market Shaper" in its 2026 Emerging Market Quadrant for deepfake detection, and "the company to beat" in a research note. ### Detection is only half the fight Reality Defender scores whether media is authentic, but runs no document-forgery or liveness for identity flows and makes no identity decision. ScamAI adds exactly that layer — face, document, and liveness signals in one result your KYC flow can act on — so a flagged deepfake connects to an approve, step-up, or decline, instead of a detector plus a second identity vendor. ### Defense that runs where the attack happens RealCall and RealMeeting do watch calls in real time — but in the cloud; even Reality Defender's on-prem and air-gapped options are server-side. Halo runs detection as native inference on the endpoint itself, so sensitive call and selfie media never leaves the device. Already running Reality Defender? ScamAI drops in beside it as the on-device, identity, and document layer. ## ScamAI vs Sensity URL: https://scam.ai/company/vs-sensity Sensity has grown from deepfake monitoring into real-time detection — a KYC product and a Teams plugin for live calls, with strong forensic explainability. The gap now is where the detection runs: Sensity scores in the cloud, while ScamAI runs on the endpoint with Halo, so sensitive KYC media never leaves the perimeter. ### Sensity at a glance Sensity AI detects deepfakes across image, video, and audio — from an air-gapped investigator workstation for forensics to a real-time KYC SDK and a Microsoft Teams plugin for live calls. Deployable cloud, on-prem, or on that workstation, with strong explainability: pixel-level heatmaps and court-ready reports. ### Where ScamAI differs Sensity detects in the cloud — its KYC SDK and Teams plugin send media to a server to be scored. ScamAI runs the same class of detection on-device with Halo, so face and document media stays on the endpoint, and unifies document forensics, liveness, and behavior into one score wired directly into KYC and claims flows. ### Independent, and tuned to live fraud Both return evidence, not bare scores — Sensity is genuinely strong on forensic heatmaps and court-ready reports. Where ScamAI pulls ahead is keeping that analysis on-device and tuned to live fraud rather than after-the-fact investigation. Comparisons here reflect ScamAI's assessment; verify current capabilities with each vendor. ## ScamAI vs Hive URL: https://scam.ai/company/vs-hive Hive is a content-moderation platform with a serious deepfake-detection line — credible enough to win a U.S. Department of Defense contract. But its core is moderation at scale; ScamAI is fraud-first, built to protect identity and stop scams, and runs on-device where Hive is a cloud API. ### Hive at a glance Hive offers content moderation and AI-generated-content detection via API across image, video, audio, and text — widely used for platform moderation, with a dedicated deepfake model (generator attribution, per-face boxes) and an on-prem deployment credible enough to win a U.S. Department of Defense contract. ### Where ScamAI differs Hive does flag identity-document fraud and offers liveness — but as moderation features, not a fraud stack. ScamAI is built for fraud and identity: real-attack-trained detection across face and documents, document-forgery and liveness that drop into onboarding, and on-device meeting protection with Halo that a cloud API can't match. ### Purpose-built for the attack Hive even scans live calls in real time — but in the cloud, tuned to moderation. ScamAI is tuned to the specific plays scammers run — impersonation, forged documents, live deepfakes — and runs on-device. Already using Hive? ScamAI drops in beside it as the fraud and identity layer. ## ScamAI vs Resemble AI URL: https://scam.ai/company/vs-resemble-ai Resemble Detect is genuinely capable — one model across audio, video, and image, real-time on calls, with a strong explainability story. But Resemble also builds voice-cloning technology, so it sits on both sides of the problem. ScamAI is independent — detection is the whole business — and runs on-device with Halo. ### Resemble AI at a glance Resemble AI's core business is generative AI voice; its detection arm, Resemble Detect, spans audio, video, and image in a single unified model (DETECT-3B Omni), with real-time call detection and a genuinely strong explainability story — verdicts and heatmaps, not just a score. ### Independent by design Selling both cloning and detection puts one company on both sides of the problem. ScamAI has no synthetic-media product to protect — detection is the whole business, so there's no incentive conflict. ### From detection to decision Resemble Detect now reaches into KYC — evaluating documents, selfie, and voice — but not full identity verification, and it scores in the cloud or on an on-prem server. ScamAI adds document-forgery and liveness for identity flows and runs on-device with Halo at the edge, so a flagged deepfake connects to an approve, step-up, or decline without media leaving the endpoint. Comparisons here reflect ScamAI's assessment; verify current capabilities with each vendor. ## ScamAI vs Incode URL: https://scam.ai/company/vs-incode Incode is a Gartner-Leader identity-verification platform that now ships Deepsight, a dedicated deepfake engine. It's excellent at onboarding — but that's its center of gravity. ScamAI defends every call, claim, and login after onboarding, runs on-device for live meetings, and deploys on-prem/VPC. ### Incode at a glance Incode is a scaled identity-verification platform named a Leader in the 2024 and 2025 Gartner Magic Quadrant for Identity Verification: facial recognition, document verification across 4,900+ document types, passive liveness, KYC/KYB orchestration, and now Deepsight — a dedicated deepfake-detection engine. ### Deepfake-native, and vendor-neutral Incode's Deepsight is a real deepfake engine — but it's native to Incode's own platform, licensed as part of their score. ScamAI is deepfake-native too, and vendor-neutral: it drops into whatever IDV stack you already run — including Incode — as an independent, on-device risk signal, instead of asking you to move onto one platform. ### Fraud defense doesn't end at onboarding Incode's center of gravity is the verification event, and its on-device work covers liveness at capture — not live meetings. Executive impersonation and deepfaked calls happen long after onboarding; Halo defends the whole relationship on-device, and ScamAI deploys on-prem/VPC where Incode focuses on cloud and edge. ## ScamAI vs Sightengine URL: https://scam.ai/company/vs-sightengine Sightengine is a content-moderation API with deepfake detection and a passive-liveness check bolted on. ScamAI is a fraud and identity platform — document-forgery, liveness, and deepfake detection in one result, running on-device with Halo where Sightengine runs server-side. ### Sightengine at a glance Sightengine is a mature, developer-friendly content-moderation API — nudity, violence, and ~150 moderation classes across image, video, text, and audio — with deepfake detection as an add-on returning a face-swap confidence score, plus a passive-liveness (PAD) check. Cloud by default, with on-prem on the enterprise plan. ### Moderation API vs fraud platform Sightengine keeps unwanted content off your app, and its PAD liveness touches identity — but there's no document-forgery or KYC workflow behind it. ScamAI is the fraud and identity layer: document-forgery, liveness, and deepfake detection in one result with identity context, not a moderation SDK with a deepfake add-on. ### On-device vs server-side Sightengine runs in the cloud by default; on-prem is an enterprise-tier option, and even then it's server-side. ScamAI runs detection on-device with Halo — sensitive selfies and ID documents never leave the endpoint at all, decisive where shipping PII off-device is a compliance non-starter. ### FAQ Q: When is Sightengine the better fit? A: If your problem is content moderation — nudity, violence, unwanted uploads at scale — Sightengine is built for exactly that, and offers on-prem on its enterprise plan. Choose ScamAI when the problem is fraud: document-forgery, liveness, and deepfake detection that runs on-device through Halo. Q: Does Sightengine detect deepfakes? A: Yes — as an add-on to its moderation API, returning a face-swap confidence score, plus a passive-liveness (PAD) check. ScamAI treats deepfake detection as the core of a fraud platform: faces, documents, and video scored together, evidence attached to every result, deployable on-device through Halo for live meetings. ## ScamAI vs AI or Not URL: https://scam.ai/company/vs-aiornot AI or Not answers "is this AI-generated?" — a general classifier. ScamAI is a fraud and identity detection layer: document-forgery, liveness, and deepfake signals your KYC flow acts on, running on-device with Halo. ### What is AI or Not? AI or Not is a multimodal AI-detection API — image, text, video, and audio — with a strong consumer and newsroom brand and a headline 98.9% accuracy claim. It markets into fraud and KYC teams, but it's a general-purpose classifier, not an identity or fraud platform with document, liveness, and deepfake detection behind it. ### Detection signal or fraud context? AI or Not tells you an image looks AI-generated, with a confidence score and the likely generator. ScamAI adds the identity context around it: document-forgery, liveness, and deepfake signals scored together for a KYC flow to act on — not just a probability that one file is synthetic. ### On-device for the data that matters For KYC, selfies and ID documents are the most sensitive data you hold. AI or Not runs in the cloud by default (on-prem only on its enterprise tier); ScamAI's on-device Halo keeps that media on the endpoint itself — a decisive edge for data-residency-bound banks and insurers. # API documentation ## Overview URL: https://scam.ai/docs ScamAI detection API overview: one REST endpoint returns an authenticity verdict for image, video, and audio — base URL, auth, request shape, and limits. Covers: overview base url https://api.scam.ai auth header x-api-key multipart/form-data dashboard app.scam.ai one endpoint POST /v1/detections GET retrieve image video audio media inferred verdict likely_authentic suspicious likely_ai_manipulated confidence credits_used deepfake face-swap ai-generated synthetic voice ## Authentication URL: https://scam.ai/docs/authentication Authenticate ScamAI API requests with the x-api-key header, and create, rotate or revoke keys yourself from the dashboard — no sales call, no shared keys. Covers: authentication x-api-key header api key rotate keys dashboard server-side secret never client-side save flag privacy dpa retention ## Quickstart URL: https://scam.ai/docs/quickstart Run your first ScamAI detection with a single curl command against the unified endpoint, then read the verdict, confidence and credits spent in the reply. Covers: quickstart curl example first request POST /v1/detections file upload image jpg verdict likely_ai_manipulated suspicious likely_authentic confidence probability manipulated credits_used review queue ## SDKs URL: https://scam.ai/docs/sdks Install the official TypeScript or Python SDK. Each wraps the detection endpoint with multipart uploads, typed errors, safe retries and webhook verification. Covers: sdk client library typescript node javascript npm install @scam-ai/sdk python pip install scamai package official wrapper multipart retries typed errors exceptions webhook signature verification ## Create a detection URL: https://scam.ai/docs/create-detection POST /v1/detections runs a detection on one image, video or audio file — or a video link — and returns the verdict, the confidence, and the credits it spent. Covers: create detection POST /v1/detections file url save idempotency-key multipart image video audio media inferred deepfake face-swap ai-generated synthetic voice verdict likely_authentic suspicious likely_ai_manipulated confidence model frames_metered credits_used summary frames segments thumbnails ## Retrieve a detection URL: https://scam.ai/docs/retrieve-detection GET /v1/detections/{id} fetches a detection after the fact and returns exactly the body the create call returned, so a webhook or a retry needs no cache. Covers: retrieve detection GET /v1/detections/id fetch by id owner only stored response save false 404 not found history ## Errors URL: https://scam.ai/docs/errors Every error the ScamAI detection API returns — 400, 401, 402, 403, 409, 413, 415, 422, 429 and 502 — what each one means, and the action that clears it. Covers: errors 400 bad request 401 unauthorized api key 402 insufficient_credits out of credits 403 scope forbidden 409 idempotency_in_flight 413 too large 415 unsupported media 422 unprocessable reasons no face 429 rate limited 502 detector unavailable support@scam.ai ## Media types & credits URL: https://scam.ai/docs/credits What each media type costs on the ScamAI detection API: an image is one credit, video bills per sampled frame and audio per minute, all from a prepaid balance. Covers: credits pricing image 1 credit video per frame sampled one per second capped 20 credits audio per minute rounded up capped 25 credits_used prepaid ledger ## Constraints & best practices URL: https://scam.ai/docs/constraints Accepted formats, per-media size caps and threshold guidance for the ScamAI detection API — what to send, what is refused, and how to read a middling score. Covers: constraints best practices formats jpeg png webp images mp4 video mp3 wav flac m4a aac ogg audio max file size image 10 MB video 25 MB audio 25 MB thresholds per flow id tracing ## Dashboard & support URL: https://scam.ai/docs/dashboard Manage API keys, watch the credit balance and open any detection's record in the ScamAI dashboard at app.scam.ai — plus how to reach support with a run id. Covers: dashboard app.scam.ai log in usage api keys detection history support support@scam.ai on-prem vpc deployment regulated soc 2 gdpr trust center # Site-wide FAQ URL: https://scam.ai/faq Q: What can ScamAI actually detect? A: ScamAI detects deepfaked faces, face swaps, and fully AI-generated images and video. It also catches forged and tampered identity documents — including template-generated and synthetic IDs — manual edits and splices, and device-level attacks like virtual cameras and injection attacks that defeat naive selfie checks. One engine, the Eva V1.6 Detection Model, covers onboarding selfies, identity documents, claims media, live video meetings, and user-generated content. Q: How accurate is it, and what about false positives? A: Detection is probabilistic, not a yes/no: the Eva V1.6 Detection Model returns a tiered likelihood result — likely real, needs review, or likely AI-manipulated — with the confidence behind it and a plain-English summary of what it found. You set the thresholds — auto-decline, step-up, or human review — and tune them per flow: stricter for high-value wires, looser for routine account changes. You control the false-positive/false-negative trade-off, not a vendor's fixed cutoff. Eva V1.6 is retrained as new generators appear, so accuracy tracks the current attack landscape, not a frozen benchmark. Q: Can it work in real time, including live calls? A: Real-time detection is what Halo, ScamAI's meeting product, is built for. Halo runs deepfake detection on-device during live video meetings and flags a deepfaked face or manipulated feed while the call is happening, and because analysis stays on your machine, meeting video never leaves it. For application flows, the REST API offers real-time latency for live onboarding and step-up checks, plus batch endpoints for media libraries and claims backlogs. A face-swapped selfie gets declined before the account exists. Q: Can detection run without sending media to ScamAI? A: Yes. Halo analyzes meeting video on-device, so that media never leaves your endpoint at all. For data-residency or no-egress requirements, on-prem and private-cloud deployment keep media, results, and logs entirely inside your own perimeter. Q: How do you keep up with new deepfake generators? A: New face-swap and diffusion tools appear constantly, so Eva V1.6 trains on real attack media — actual fraud attempts, not academic datasets — and retrains as new generators show up in the wild. The team publishes original research — papers and open datasets on deepfake detection, document forgery, and adversarial attacks on age-estimation systems, with named authors on arXiv — and studied techniques become detection signals. Ask any vendor when its model was last updated, and against what. Q: How does it integrate with our stack? A: Integration is one REST API: send video, images, or documents; get back a verdict, the confidence behind it, and a plain-English summary of what was found. Drop it into your existing decision point — onboarding/KYC, claims intake, the support or moderation queue — and route on the score: approve, step-up, or review. There is no model to train, so a first integration typically takes a day, not a quarter. SDKs are coming; Halo, a lightweight desktop app, needs none; regulated environments can deploy on-prem or private-cloud. Q: Are you compliant — SOC 2, GDPR, data residency? A: ScamAI is SOC 2 Type II audited and GDPR compliant, with a Data Processing Agreement available. The legal stack — privacy policy, terms, DPA, MSA, subprocessor list, and the Halo EULA — is published openly on the site. Banks and public-sector agencies with data-residency or no-egress requirements can deploy on-prem or private-cloud: the same models run inside your perimeter, so nothing crosses a boundary you don't control. Halo analyzes meeting video on-device, so meeting content never reaches ScamAI's infrastructure. Q: What evidence do we get for a result? A: Every result ships with a tiered verdict — likely real, needs review, or likely AI-manipulated — the confidence behind it, and a plain-English summary of what the model found; video and audio also carry the per-frame and per-window series behind the score. Analysts get something to review instead of a bare number, and auditors can trace why an application was declined or escalated. Named per-signal breakdowns and examiner-grade forensic reports are arranged with our team — ask us on a demo call. Q: How is this different from a single-point detector? A: Single-point detectors answer one question — "does this media look AI-generated?" — and stop. ScamAI layers multimodal detection on top of your existing KYC/IDV vendor, strengthening it, not replacing it, and adds document-forgery detection, device signals, and on-device meeting protection in one combined result. A flagged selfie is only useful tied to the identity being onboarded and an approve/decline/review decision; a point detector leaves that connective work to your engineers. With a platform, flag, identity, and decision arrive together. Q: What does it cost? A: Self-serve is one flat rate: $0.02 a credit, prepaid, and credits never expire. An image check is 1 credit, video is 1 credit per sampled frame (capped at 20 a clip), audio is 1 credit per minute — the full table is on /pricing. Document detection and enterprise volume are priced on request: bring your use case and monthly volumes to a 15-minute demo and leave with a price mapped to your actual flow. # Pricing and limits URL: https://scam.ai/pricing Credit cost per run: image 1 credit per image; video up to 20 credits per clip (1 credit per sampled frame, one frame a second, capped at 20); audio 1 credit per minute, rounded up; document 2 credits per page, sold on a plan through sales rather than self-serve credits. A credit is $0.02. Upload limits enforced by the scam.ai website and dashboard: image 10 MB, video 25 MB, audio 25 MB, document 25 MB. The REST API's own per-format limits are at https://scam.ai/docs/constraints. Self-serve pricing is prepaid credits at one flat rate: buy credits first, then every run spends them. Enterprise plans (a monthly platform fee with a lower per-frame rate) and document detection are arranged through https://scam.ai/contact; details at https://scam.ai/pricing. # Site map ## Start here - [Home](https://scam.ai/): Deepfake detection and scam prevention. - [Pricing](https://scam.ai/pricing): Pay as you go at $0.02 a credit, one flat rate; enterprise plans and document detection through sales. - [Why ScamAI](https://scam.ai/why-scamai): Detection you can act on, with evidence. - [Technology](https://scam.ai/technology): The detection research behind ScamAI. - [FAQ](https://scam.ai/faq): Direct answers on what ScamAI detects, accuracy, real-time use, data handling, and compliance. - [Request a demo](https://scam.ai/contact) ## Platform - [Platform overview](https://scam.ai/platform): Detection, analytics, and the API in one place. - [Verifit | Remote inspections. Confident decisions.](https://scam.ai/platform/verifit): Cut inspection costs and keep decisions moving. Verify property and assets remotely, with fewer site visits and less back-and-forth. - [Eva V1.6 Detection Model — our detection engine](https://scam.ai/platform/eva): The unified API behind every ScamAI result: video, images, and documents, scored together in real time. - [Check if AI — spot AI-generated media in seconds](https://scam.ai/platform/check-if-ai): Upload an image and get an instant read on whether it's AI-generated. - [Deepfake Playground](https://scam.ai/platform/deepfake-playground): Deepfake yourself in 30 seconds. Point your camera at your own face, pick someone to become, and watch the swap happen live — the same thing an attacker can do with consumer tools. - [On-prem deepfake detection](https://scam.ai/platform/on-prem-deployment): Run ScamAI detection inside your own environment — VPC, private cloud, or fully on-premises — so regulated data never leaves your perimeter. - [PII Zero: Claims Media De-identification](https://scam.ai/platform/pii-zero): Offline redaction of policyholder identity in claim documents, loss photos and video: names, addresses, account and policy numbers, faces and plates. - [Risk Signals](https://scam.ai/platform/risk-signals): Turn detection results into a view of your threat surface — patterns rather than single incidents. Available on request. - [Deepfake Detection](https://scam.ai/platform/deepfake-detection): Purpose-built deepfake signals — face swaps, full generations, and replays — scored across images, video, and live calls. - [ID Document Forgery Detection](https://scam.ai/platform/id-document-forgery): Tampering and forgery signals for identity documents — passports, national IDs, driver's licenses, residence permits. - [Loan & Insurance Document Forgery](https://scam.ai/platform/loan-insurance-forgery): Forgery signals for due-diligence documents — bank statements, pay stubs, proof of income and address, invoices, policy documents. - [Age Estimation](https://scam.ai/platform/age-estimation): Age checks from a live selfie — an estimated age and the probability the person is over your threshold, no ID collected. - [Device Signals — liveness & presentation attacks](https://scam.ai/platform/capture-signals): Detection for spoofed presentations — printed photos, screen replays, and masks — plus liveness failures, caught at the point of capture. - [Manual-Edit Forensics — image forgery detection](https://scam.ai/platform/manual-edit-forensics): Pixel-level forensics for manually edited selfies and documents — splices, clones, and retouching. - [How Verifit works | Less chasing. Faster answers.](https://scam.ai/platform/verifit/how-it-works): Make inspections easier with Verifit. Send a link, collect verified photos, and give your team a faster way to review cases with fewer customer follow-ups. - [Verifit for insurance | Faster claims, fewer visits](https://scam.ai/platform/verifit/insurance): Move claims forward and reduce inspection costs with Verifit. Verify property remotely, simplify policyholder follow-ups, and flag suspicious submissions. - [Verifit for lending | Keep funding moving](https://scam.ai/platform/verifit/lending): Keep inspections from holding up funding. Verify property, progress, and equipment remotely with Verifit to reduce site visits and move decisions forward. - [See Verifit in action | Request a demo](https://scam.ai/platform/verifit/demo): See how Verifit can help reduce inspection costs and speed up decisions. Book a demo tailored to your workflow, your team, and your customer experience. - [Halo — on-device deepfake detection](https://scam.ai/halo): The world's first on-device deepfake detection for live calls. ## For developers and AI agents - [MCP for LLMs](https://scam.ai/platform/mcp): Bring ScamAI detection to AI agents. An MCP server that lets an LLM check whether an image, a video or an audio recording is real, mid-task. - [Detection API](https://scam.ai/platform/api): One API for the places fraud happens: send video, images, or documents and get a scored result back. Native SDKs are on the way. - [API documentation](https://scam.ai/docs): ScamAI detection API overview: one REST endpoint returns an authenticity verdict for image, video, and audio — base URL, auth, request shape, and limits. - [API docs: Authentication](https://scam.ai/docs/authentication): Authenticate ScamAI API requests with the x-api-key header, and create, rotate or revoke keys yourself from the dashboard — no sales call, no shared keys. - [API docs: Quickstart](https://scam.ai/docs/quickstart): Run your first ScamAI detection with a single curl command against the unified endpoint, then read the verdict, confidence and credits spent in the reply. - [API docs: SDKs](https://scam.ai/docs/sdks): Install the official TypeScript or Python SDK. Each wraps the detection endpoint with multipart uploads, typed errors, safe retries and webhook verification. - [API docs: Create a detection](https://scam.ai/docs/create-detection): POST /v1/detections runs a detection on one image, video or audio file — or a video link — and returns the verdict, the confidence, and the credits it spent. - [API docs: Retrieve a detection](https://scam.ai/docs/retrieve-detection): GET /v1/detections/{id} fetches a detection after the fact and returns exactly the body the create call returned, so a webhook or a retry needs no cache. - [API docs: Errors](https://scam.ai/docs/errors): Every error the ScamAI detection API returns — 400, 401, 402, 403, 409, 413, 415, 422, 429 and 502 — what each one means, and the action that clears it. - [API docs: Media types & credits](https://scam.ai/docs/credits): What each media type costs on the ScamAI detection API: an image is one credit, video bills per sampled frame and audio per minute, all from a prepaid balance. - [API docs: Constraints & best practices](https://scam.ai/docs/constraints): Accepted formats, per-media size caps and threshold guidance for the ScamAI detection API — what to send, what is refused, and how to read a middling score. - [API docs: Dashboard & support](https://scam.ai/docs/dashboard): Manage API keys, watch the credit balance and open any detection's record in the ScamAI dashboard at app.scam.ai — plus how to reach support with a run id. ## Research - [Research](https://scam.ai/research): Published papers on deepfake detection, document forgery, and age-estimation robustness, with open datasets and named authors on arXiv. ## Solutions - [Solutions overview](https://scam.ai/solutions) - [KYC / IDV fraud detection](https://scam.ai/solutions/kyc-idv): Make sure the person enrolling is live, present, and real — not a replay, a render, or a synthetic identity. ScamAI works with your KYC vendor to strengthen it, not replace it. - [Loan & credit fraud detection](https://scam.ai/solutions/loan-credit): Stop synthetic applicants and doctored income documents at origination, before the money moves. - [Insurance claims fraud detection](https://scam.ai/solutions/insurance-claims): Verify claim photos, videos, and documents are genuine — not staged, edited, or AI-fabricated. - [Meeting deepfake protection](https://scam.ai/solutions/meeting-security): Continuous verification of who is really on the call — powered by Halo. - [Pig butchering scams](https://scam.ai/solutions/pig-butchering): Detect the fake faces and forged proof behind long-con romance and investment scams — before your users are drained. - [Deepfake social engineering attacks](https://scam.ai/solutions/social-engineering): Catch the deepfaked faces attackers use to manipulate employees into transfers, access, and approvals. - [HR / Hiring](https://scam.ai/solutions/hiring-fraud): Protect hiring end to end — make sure the person you interview is the person you hire, not a deepfake stand-in or a proxy. - [Content moderation](https://scam.ai/solutions/content-moderation): Score uploads for AI generation and manipulation before synthetic content spreads. - [Misinformation detection](https://scam.ai/solutions/misinformation): Detect the deepfakes and synthetic media behind misinformation before it spreads and erodes trust. - [Deepfake brand protection](https://scam.ai/solutions/brand-protection): Catch the deepfakes, fake ads, and impersonations that hijack your brand and your executives' likenesses. - [AI phishing & spam detection](https://scam.ai/solutions/phishing-spam): Screen the images, documents, and media inside phishing and spam campaigns for AI generation and manipulation. ## Industries - [KYC/AML compliance](https://scam.ai/industries/kyc-aml-compliance): Meet KYC and AML obligations against AI-era fraud — deepfake selfies, forged IDs, and synthetic identities caught at onboarding and beyond. - [On-device deepfake detection agent](https://scam.ai/industries/on-device-agent): Real-time detection that runs on the device — media and identity verified locally, with nothing leaving the endpoint. Shipping today in Halo; an embeddable agent for your own apps and devices is in development. - [Deepfake detection for financial services](https://scam.ai/industries/financial-services): Stop synthetic identities at onboarding and deepfaked executives on video calls before the wire is released. - [Deepfake detection for the public sector](https://scam.ai/industries/public-sector): Protect officials and citizens from impersonation campaigns. - [E-commerce & marketplaces](https://scam.ai/industries/e-commerce-marketplaces): Keep fake sellers and cloned storefronts out. - [Dating apps](https://scam.ai/industries/dating-apps): Keep fake profiles, AI-generated photos, and deepfaked video calls off your platform — before they turn into romance scams. - [Telecom fraud detection](https://scam.ai/industries/telecom): Protect SIM changes, account access, and support channels from synthetic identities and social engineering. ## Compare - [ScamAI vs Reality Defender](https://scam.ai/company/vs-reality-defender): Reality Defender is a strong, well-funded media-authenticity layer — it flags AI-generated audio, video, image, and text, and now watches live calls. But it stops at detection: no document-forgery or liveness for identity flows, and every check runs server-side. ScamAI adds the identity and document layer, and runs detection on the endpoint itself with Halo. - [ScamAI vs Sensity](https://scam.ai/company/vs-sensity): Sensity has grown from deepfake monitoring into real-time detection — a KYC product and a Teams plugin for live calls, with strong forensic explainability. The gap now is where the detection runs: Sensity scores in the cloud, while ScamAI runs on the endpoint with Halo, so sensitive KYC media never leaves the perimeter. - [ScamAI vs Hive](https://scam.ai/company/vs-hive): Hive is a content-moderation platform with a serious deepfake-detection line — credible enough to win a U.S. Department of Defense contract. But its core is moderation at scale; ScamAI is fraud-first, built to protect identity and stop scams, and runs on-device where Hive is a cloud API. - [ScamAI vs Resemble AI](https://scam.ai/company/vs-resemble-ai): Resemble Detect is genuinely capable — one model across audio, video, and image, real-time on calls, with a strong explainability story. But Resemble also builds voice-cloning technology, so it sits on both sides of the problem. ScamAI is independent — detection is the whole business — and runs on-device with Halo. - [ScamAI vs Incode](https://scam.ai/company/vs-incode): Incode is a Gartner-Leader identity-verification platform that now ships Deepsight, a dedicated deepfake engine. It's excellent at onboarding — but that's its center of gravity. ScamAI defends every call, claim, and login after onboarding, runs on-device for live meetings, and deploys on-prem/VPC. - [ScamAI vs Sightengine](https://scam.ai/company/vs-sightengine): Sightengine is a content-moderation API with deepfake detection and a passive-liveness check bolted on. ScamAI is a fraud and identity platform — document-forgery, liveness, and deepfake detection in one result, running on-device with Halo where Sightengine runs server-side. - [ScamAI vs AI or Not](https://scam.ai/company/vs-aiornot): AI or Not answers "is this AI-generated?" — a general classifier. ScamAI is a fraud and identity detection layer: document-forgery, liveness, and deepfake signals your KYC flow acts on, running on-device with Halo. ## Resources - [Resources](https://scam.ai/resources): Research, documentation, the regulation tracker, and partner programs. - [Deepfake regulation tracker](https://scam.ai/resources/regulation): Where deepfake and AI-fraud law stands, jurisdiction by jurisdiction. - [Education](https://scam.ai/resources/education): Learn how AI-driven scams work — and how to defend against them. - [Trust Center](https://scam.ai/resources/trust-center): Security, privacy, and compliance documentation. - [Changelog](https://scam.ai/resources/changelog): What's new in ScamAI detection — models, APIs, and product. - [Affiliate program](https://scam.ai/resources/affiliate): Earn by referring teams that need deepfake and fraud detection. - [Partner program](https://scam.ai/resources/partners): Resell, integrate, or build on the ScamAI detection API. - [Deepfake detection education program](https://scam.ai/resources/education-program): Training, certification, and curriculum for partners, students, and institutions who want to teach and deploy deepfake detection. - [Our partners](https://scam.ai/resources/partnerships): Build with ScamAI — technology, channel, and integration partnerships that embed deepfake detection into more products, platforms, and go-to-market motions. ## Blog - [Blog](https://scam.ai/resources/blog): Detection research and field notes from the team. ## News - [Press](https://scam.ai/resources/press): Announcements and coverage. ## Community - [Anti-Scam Community](https://scam.ai/community): Threat sharing, researcher Q&A, and early access. ## Company - [About ScamAI](https://scam.ai/company/about): ScamAI exists because seeing is no longer believing. We build the tools that let people and organizations trust what they see. - [Careers](https://scam.ai/company/careers): Don't apply if you just want a job — this isn't one. Everyone here shares the same goal and the same faith: beat the criminals using AI to deceive people. The bar is high and we are ruthlessly selective. But if this is your fight, we want to hear from you. - [Team](https://scam.ai/company/team): The researchers and engineers building ScamAI — focused on detecting AI-generated deception at the moment it matters. - [Company](https://scam.ai/company): About, team, careers, and brand. - [Brand kit](https://scam.ai/brand) ## Legal - [Privacy Policy](https://scam.ai/legal/privacy): How Reality Inc. (DBA Scam.ai) collects, uses, discloses, and protects personal data across its sites and services, and the rights available to individuals. - [Terms of Service](https://scam.ai/legal/terms): The binding terms governing access to and use of the ScamAI website, dashboard, API, and apps, including accounts, acceptable use, termination, and liability. - [Cookie Policy](https://scam.ai/legal/cookies): How and why ScamAI uses cookies and similar technologies on its sites, what each category does, and how to control or withdraw consent in your browser or ours. - [Data Processing Addendum](https://scam.ai/legal/dpa): Processor terms for personal data ScamAI processes on behalf of customers under GDPR Article 28: instructions, security, subprocessors, transfers, audits. - [Subprocessors](https://scam.ai/legal/subprocessors): Third parties ScamAI engages to help operate the Services — hosting, database, email, analytics, and abuse prevention — and how we announce changes to the list. - [Master Services Agreement](https://scam.ai/legal/msa): The default commercial terms for paid ScamAI Services — fees, term, confidentiality, IP and data, and liability — unless a signed agreement provides otherwise. - [Halo App End User License Agreement](https://scam.ai/legal/halo-eula): The license terms for the Halo on-device deepfake-detection app: what you may install and run, what stays on your device, updates, and limits of liability.