Threat model
What is defended, what is mitigated, and what is explicitly out of reach — including a compromised operating system.
Defended, mitigated, out of scope
Defended: replaying an approval against a different action, forging the hardware anchor from the client, presenting a recorded or generated face to the active challenge, and altering a record after the fact.
Mitigated: injected video from a virtual camera. With a capture agent enrolled this becomes a server-verified control; without one it is a browser heuristic and is labelled as such.
Out of scope: a compromised operating system. A kernel-level attacker who patches the media stack can feed a genuine agent false inventory. Hardware key residency stops key theft and agent impersonation, not OS compromise.
Check it yourself
The artifacts behind this page
- Action binding, verified server-side./how-it-works/action-binding →
- Capture attestation and its ceiling./how-it-works/device-proof →
What this page does not claim
Limits
- Synthetic-voice detection is not implemented, so voice cloning is not defended against by an audio detector — only indirectly, by the visual and challenge signals.