newCallback verification is a control that voice cloning quietly broke.
Proveniro
ai detection · agent verification · likeness provenance

Prove who's real,in the seconds that matter.

Generative AI made voice and face cloning trivial, and AI agents now make the calls. Proveniro is the AI provenance layer for human likeness — a rights and licensing registry, autonomous scanning with automated takedown, and a real-time multimodal AI ensemble wired into the calls, onboarding flows and payment approvals where the loss actually happens.

proveniro · verify.livelive
+44 20 7946 0812
Claims to be: Group CFO
Payment authorisation · callback
ref PA-40871
capturing 3.2 s sample16 khz · 5 ai models
  • codec_fingerprint
  • prosody_continuity
  • spectral_artefacts
  • replay_liveness
  • registry_match
establishing session…

live simulation · cloned caller, genuine human, authorised ai agent

AI-cloned voice · payment callbackheld · 312 msVoiceprint match · treasuryreleased · 268 msUnlicensed AI likeness · ad networknotice filedInjection attack · KYC capturerejected · 190 msAI licence granted · 14 territoriessignedLiveness challenge passedreleased · 240 msAuthorised AI agent · in scopeallowed · 104 msVoice clone in podcast adagent takedown · 4 hC2PA manifest sealedevidence storedUnregistered agent · vendor bank changeblocked · 356 msAI-cloned voice · payment callbackheld · 312 msVoiceprint match · treasuryreleased · 268 msUnlicensed AI likeness · ad networknotice filedInjection attack · KYC capturerejected · 190 msAI licence granted · 14 territoriessignedLiveness challenge passedreleased · 240 msAuthorised AI agent · in scopeallowed · 104 msVoice clone in podcast adagent takedown · 4 hC2PA manifest sealedevidence storedUnregistered agent · vendor bank changeblocked · 356 ms
The open angle

A standard control quietly stopped working, and almost nobody updated it.

Callback verification has anchored payment security for thirty years: something looks unusual, so you ring the person back on a known number and confirm it with your ears. Every part of that control assumed a human voice was hard to fake. That assumption expired.

the control, as designed
  1. 01Unusual payment or vendor bank change
  2. 02Call back on a number from file
  3. 03Recognise the voice · confirm details
  4. 04Release the payment
the control, in 2026
  1. 01Attacker harvests 3s of public audio
  2. 02Clones the voice for free, in minutes
  3. 03Answers the callback in that voice
  4. 04Payment released, control satisfied
US$25M
transferred after a single deepfaked video call with colleagues — Hong Kong, 2024
~3 sec
of public audio is enough for a commodity generative AI voice model
$0
marginal cost of the open-weight AI models used to defeat a callback
1
phone call still standing between an attacker and the payment file

industry context · figures from widely reported public incidents and vendor documentation

The platform

Four systems, one record of who is real.

Rights and defence are the same problem seen from two ends. Proveniro runs them on one AI substrate, so a licence granted on Monday is the reason an agent-filed takedown succeeds on Friday — and a model verdict in a call centre is governance evidence in a claim six months later.

Point of risk

AI detection belongs where the decision is made.

A weekly report of deepfakes found on the internet does not stop a wire. Proveniro runs inline at the five moments where a synthetic identity — human impersonation or an unauthorised AI agent — converts into money, access or reputational damage.

The callback that authorises the wire

Dual authorisation collapses to a single phone call. If the voice on that call can be cloned by a generative AI model in ninety seconds from a conference keynote, the control is theatre. Proveniro verifies the speaker before the payment file is released — not after the reconciliation.

ai verdict latency
< 400 ms
integration
SIP / WebRTC / REST
control flow
  1. trigger
    Payment > threshold triggers callback
  2. signal
    Live voice scored against clone ensemble + enrolled print
  3. outcome
    Release, hold, or escalate — written to an evidence ledger
Agentic AI

Your contact centre now has AI on both sides of the call.

Enterprises are deploying voice agents to chase invoices, onboard suppliers and verify customers. Attackers are deploying the same technology to impersonate them. A control that only asks ‘is this a human’ will start blocking your own automation — and a control that waves through anything synthetic is not a control at all.

Authorised agents

Enrol your own AI agents in the registry with a signed credential and an explicit scope. Proveniro tells the receiving system this is a declared agent acting inside its mandate, not an impersonation.

declared & scoped

Impersonated agents

An attacker’s agent holds a fluent, adaptive, forty-minute conversation and never breaks character. Detection scores the synthesis and checks for a credential, so sounding like a real assistant stops being evidence of anything.

scored, not trusted

Human-only decisions

Some actions should never be completed by a non-human, however well credentialed. Scope rules let agents into enquiry and onboarding flows while payment release stays behind a verified human.

guardrail by policy
Defence

Banks, insurers and enterprise security

Repair the controls that generative AI broke, verify the agents now calling on your behalf, prove to a regulator that you did, and price AI risk with evidence instead of anecdote.

deploy
shadow mode in days
pricing
per verification
Rights

Talent, agencies, studios and platforms

Turn a likeness into an AI-licensable asset with terms you control, and let autonomous agents do the policing — continuously, across every surface, without a legal team on retainer.

enrolment
voice + face
coverage
web, video, ads, apps
Integrate

One call. One verdict. One record.

Post media or fork a live stream. Get back a decision, the reasons behind it, and a sealed record you can hand to an auditor. No GPUs, no model hosting, no ML team, no rip-and-replace of your call platform.

Shadow mode first
Score real traffic without acting on it until the thresholds are yours.
Your region, your retention
EU and UK residency, configurable retention, and zero AI training on your data.
Evidence by default
Every verdict sealed with inputs, AI model versions and thresholds.
import { Proveniro } from class="text-brand">"@proveniro/sdk";

const pv = new Proveniro({ apiKey: process.env.PROVENIRO_KEY });

class=class="text-brand">"text-ink-4">// Score a live payment-authorisation callback
const verdict = await pv.voice.verify({
  streamUrl: class="text-brand">"siprec:class="text-ink-4class="text-brand">">//pbx.internal/call/40871",
  context: {
    control: class="text-brand">"payment_authorisation",
    amount: 2400000,
    currency: class="text-brand">"GBP",
    claimedIdentity: class="text-brand">"user_88f21",
  },
});

if (verdict.decision === class="text-brand">"hold") {
  await payments.hold(verdict.evidenceId);
}
Design targets

Built for the moment, not the retrospective.

These are the operating envelopes the AI platform is engineered against. We calibrate them with you during evaluation, on your own traffic.

< 0 ms
verdict returned in-call
0 s
audio required to score
0
languages covered by the models
0.0%
API availability target
  1. 01

    Scope the exposure

    We map the controls where a synthetic voice or face converts into loss.

    week 0

  2. 02

    Run in shadow

    Score live traffic without acting on it. Tune thresholds against your own base rates.

    weeks 1–2

  3. 03

    Turn on decisions

    Hold, step up or release, wired into the tools your teams already use.

    week 3

  4. 04

    Prove it afterwards

    Export sealed evidence for audit, regulators, insurers and counsel.

    ongoing

Questions

The things security teams ask first.

If yours is not here, put it in the access request and a human will answer it.

Voice biometrics answers ‘does this sound like the enrolled speaker’. A good clone passes that test, because it was trained to. Proveniro asks a different question: was this audio produced by a human vocal tract in a live acoustic environment, or by a model? The registry match is one signal among five, not the whole control.

Get started

AI verification is a control, not a vibe.

Proveniro is onboarding design partners across banking, insurance and talent representation. Tell us where your exposure sits and we will show you the model verdicts on your own traffic.

soc 2 type ii in progress · eu & uk data residency · no ai training on your data