Skip to content
Exiphore

Forensic Truthfor Every Exhibit

Digital evidence can be manipulated. Exiphore examines it across multiple forensic signals, preserves its provenance, exposes the evidence behind every finding, and makes uncertainty impossible to hide.

Deployed on your infrastructure. Evidence never leaves your estate.

Exiphore examination result showing a manipulation finding with a confidence interval, examiner confidence, quality ceiling and the number of signals used
Why now

The evidence is changing faster than the tools examining it

Investigators are being handed exhibits that no longer behave like exhibits. The material arrives re-encoded, stripped of provenance, and indistinguishable on inspection from the genuine article.

  • AI-generated video
  • Cloned voices
  • Synthetic identities
  • Manipulated documents
  • Re-encoded social evidence
  • AI-assisted forgery

Traditional detection asks

“Is this fake?”

One number, from one model, on media it may never have seen the like of. Nothing to interrogate and nothing to defend.

Exiphore asks

“What can we actually establish about this exhibit?”

Independent measurements, pooled and calibrated, each stating what it cannot show — and an examiner who signs the answer.

Worked example

A real deepfake, examined

Around the Jantar Mantar demonstrations in New Delhi, a 47-second clip circulated on messaging apps showing a serving senior officer of the Delhi Police announcing his resignation and making allegations about the conduct of an investigation. It was sealed and examined. Below is what came back — the real numbers, including the ones that are unflattering.

Exhibit · video
Duration
47.3 s
Resolution
360 × 444
Bitrate
167 kbps
Faces
1 · 95 px wide
Shown as a worked example only. The officer is not named, the nameplate is covered and the clip’s captions are cropped away, so the fabricated statement is not reproduced here.
Examination complete· 27.9 s6 / 6 families · 13 signals
  • Physiological2 signals41.3%

    Pulse recovered from four facial regions disagrees between regions

  • Frequency2 signals29.1%

    High-frequency tail departs from the natural power law

  • Temporal3 signals27.7%

    Learned lip-sync analysis inconsistent with genuine capture

  • Metadata2 signals1.9%

    Transcoded; acquisition structure destroyed. Normal for redistributed media

  • Artifact3 signals0.0%

    No compositing boundary found — which alone cannot mean the exhibit is genuine

  • Learned model1 signal0.0%

    Manipulation probability low, but constrained so it can never assert authenticity

  • Provenance1 signalexcluded

    No content credentials recoverable. Non-informative, so it carries no weight in either direction rather than counting as a point against.

Manipulation Indicated

0.74

Three independent families indicate the exhibit has been altered. Escalate to examiner review.

Interval
0.59 – 0.88
Examiner confidence
57%
Quality ceiling
57%
  • Exhibit quality caps achievable confidence at 57%: one face detected, 95 px wide. A face this small relative to the frame makes the pulse measurement unreliable.
  • No provenance layer was recoverable. Absence of provenance is normal for re-encoded media and is not itself evidence of manipulation.

An automated result is not an expert opinion. A named examiner reviews the measurements and signs before this is relied upon.

The deliverable

What you receive for every exhibit

Not a score. A record: what was measured, what it establishes, what it does not, who examined it, and the bytes it all attaches to.

An Exiphore examination result as it appears in the report: verdict, manipulation index, confidence interval, examiner confidence and quality ceiling
See a full report on your own exhibit
  1. 01

    Examination result

    Manipulated, authentic or inconclusive — with the headline stated in the language a case file uses, not a probability left for someone else to read.

  2. 02

    Evidence breakdown

    Which families of forensic evidence contributed, how much each moved the result, and which found nothing. Silence is recorded as silence.

  3. 03

    Confidence and quality ceiling

    A confidence interval rather than a point estimate, and the ceiling the exhibit's own quality places on how certain any result is allowed to be.

  4. 04

    Chain of custody

    Hashes taken at seal and re-verified before every run, custody events, and a hash-chained audit trail across every action anyone took.

  5. 05

    Examiner adjudication

    A named examiner's review, their recorded reasoning, and a signature that binds examiner, analysis and rationale together.

  6. 06

    Court-ready report

    Findings, limitations, custody history and the signed adjudication frozen into a digest-sealed PDF that travels with the exhibit.

Platform

Built to survive cross-examination

Anything can produce a score. What a case needs is a finding an examiner can defend under questioning — with its reasoning, its limits and its provenance intact.

Eight independent families of evidence

Physiological signals a generator has to fabricate. Cryptographic provenance. Spectral structure. Temporal coherence. Compression and editing traces. Each family is pooled separately, so related measurements are counted once rather than mistaken for corroboration.

Explainable, measurement by measurement

Every signal shows what it measured, how strongly it was weighted for this exhibit, and what it cannot establish. Visual exhibits are rendered for the findings that have one. Nothing is a black box, because a black box does not survive cross-examination.

Sealed chain of custody

Exhibits are hashed and sealed on intake and stored read-only. The seal is re-verified before every examination, and a mismatch refuses the run. Custody and audit records are hash-chained, so any later alteration is provable.

Calibrated confidence, not false precision

Results carry a confidence interval, and exhibit quality caps how confident any result can be. When signals disagree, the platform says so and returns inconclusive rather than inventing a verdict.

Cross-case linking

Fingerprints from every exhibit are indexed, so the registry answers the question that actually advances an investigation: have we seen this before? Matches surface across cases as investigative leads.

Reports built for court

Findings, limitations, custody history and the examiner's signed adjudication are frozen into a digest-sealed report. No result is released as an expert opinion until a named examiner has reviewed the measurements and signed.

Agent architecture

A team of specialist agents, not one model

Exiphore is built as a coordinated system of AI agents. Each owns one part of the examination, works independently, and reports to an orchestrator that has to reconcile them. Independence is the point — agents that cannot see each other's conclusions cannot talk each other into one.

SEALED EXHIBITSIGNED REPORTfinding fixed here · downstream agents are read-only01Intakeagent02Examination8 agents · no shared statePhysiologicalProvenanceFrequencyTemporalArtifactMetadataSemanticLearned model03Adjudicationagent04Narrativeagent05Action planagent06Examinerhuman
01

Intake agent

Seals and characterises

Hashes the exhibit, writes it read-only, opens the chain of custody, and assesses what evidence is recoverable at all. Its quality assessment caps how confident every downstream agent is allowed to be.

Explainability

Every measurement shows its working

Signals are grouped into families and pooled so that related measurements count once. The result shows which families drove the finding, how much each contributed, and where they disagreed.

  • Per-family influence, so you can see what actually moved the result
  • Every signal states what it cannot establish, in band
  • Visual exhibits rendered for the findings that have one
  • Raw measurements available for an opposing expert to check
Exiphore breakdown showing which families of forensic evidence drove the result, with per-family influence percentages and plain-language descriptions
Exiphore case overview showing active cases, sealed exhibits, recent findings and the distribution of verdicts across a caseload
Casework

A caseload, not a one-off tool

Exhibits belong to cases. Cases carry custody, findings, reports and adjudications. Nothing is deleted — cases close and exhibits supersede, so the question of what else was run is answerable from the record.

  • Single, batch, URL and monitored-path intake
  • Role-based access with administrator-issued accounts only
  • Hash-chained audit trail across every action taken
  • Recommended investigative steps that survive an inconclusive result
Use cases

Where it earns its place

Synthetic media is not one offence. It is a method that shows up across fraud, harassment, disinformation and forgery — each with its own evidential problem.

How it works

Seal, examine, adjudicate, sign

The order matters. Nothing is analysed before it is sealed, and nothing is released before a person has signed it.

  1. 01Seal

    Hashed, written read-only, custody opened. Nothing is examined before it is sealed.

  2. 02Examine

    Specialist agents measure in parallel, independently, on the sealed original.

  3. 03Adjudicate

    Related findings pool once. Disagreement is reported, not averaged away.

  4. 04Sign

    A named examiner reviews the measurements and owns the opinion.

Why it is different

Most detectors are confidently wrong

The failure mode is always the same: a single number, produced from degraded evidence, with no way to interrogate it. These are the design decisions that follow from taking that seriously.

01

Absence of evidence is not evidence of absence

Most detectors can only evidence manipulation. One that finds nothing has shown its particular artefact is missing — which is exactly what a wholly generated exhibit looks like. Those signals are constrained so they can never assert authenticity, and a clean finding requires positive evidence of genuine capture.

02

Inconclusive is a real finding

When the evidence does not discriminate, that is reported as a substantive result. A platform that is never unsure is not being careful — it is guessing, and the guess will be found under cross-examination.

03

Detection alone is an arms race

Detectors generalise poorly to methods they have never seen, and degrade on compressed, redistributed media. Exiphore pairs detection with provenance and source attribution, and states its limits in every report.

04

Deployed on your infrastructure

Runs entirely on premises. Evidence never leaves your estate, which is what data-sovereignty obligations require and what makes the platform usable on material that cannot be sent to a third party.

Where the difference actually lies

Against a single deepfake detector, and against the conventional forensic tooling a laboratory already runs.

Capability comparison between a single deepfake detector, a conventional forensic suite, and Exiphore.
CapabilitySingle detectorConventional forensic suiteExiphore
Detects AI-generated mediaYespartialPartialYes
Multiple independent evidence familiesNoYesYes
Related measurements de-correlated before poolingNoNoYes
Confidence interval rather than a point scoreNoNoYes
Exhibit quality caps achievable confidenceNoNoYes
Reports disagreement instead of averaging itNoNoYes
Cannot infer authenticity from absent artefactsNopartialPartialYes
Sealed, hash-chained chain of custodyNoYesYes
Cross-case fingerprint linkingNopartialPartialYes
Named examiner adjudication before releaseNoYesYes
Court-ready reportpartialPartialYesYes
Air-gapped deploymentpartialPartialYesYes
Validation limits published, not just headline accuracyNopartialPartialYes
Deployment and security

It runs inside your estate, or it does not run

Exiphore is installed on your own infrastructure. There is no hosted tier, no public sign-up and no path by which an exhibit reaches a third party.

Deployment

  • On premises, on standard server hardware — no specialised accelerators required
  • Fully air-gapped operation supported once installed
  • Private-cloud installation within your own tenancy
  • No external API dependency in the examination path

Evidence handling

  • Content-addressed, write-once evidence locker; originals are never modified
  • Seal re-verified before every examination — a hash mismatch refuses the run
  • Hash-chained, append-only chain of custody
  • Hash-chained audit log covering every action taken by every account

Access control

  • Five roles: administrator, supervisor, examiner, analyst, viewer
  • Administrator-issued accounts only; no public sign-up, by design
  • Configurable session lifetime, defaulting to 45 minutes
  • Per-case classification from unclassified through secret

Optional narrative generation is the only component that can call an external model, it never touches the verdict or any measurement, and it can be disabled entirely by leaving its key unset.

Validation

The number, and everything you need to judge it

Here is our headline accuracy figure and the exact conditions that produced it. The two belong together — a number with no methodology behind it tells you nothing about what it will do on your casework.

0.983

Classifier ROC-AUC

through deployed preprocessing

86.7%

Manipulated exhibits flagged

end-to-end, after fusion

0.0%

Authentic exhibits wrongly flagged

false-alarm rate

Inconclusive

Undetected manipulations

never wrongly cleared

How it was measured

Corpus
Hemg/deepfake-and-real-images — a public, independently published dataset
Sample
60 images, balanced between manipulated and authentic
Measured through
The deployed pipeline: face detection, 0.8 context pad, 224 px resize
Measured at
End-to-end, after multi-signal fusion — not the classifier in isolation
Engine version
1.0.0
Re-measurement
Gated in CI; any model or preprocessing change re-runs the validation and fails the build if discrimination cannot be shown

Calibration is a measured parameter, not a default. On the same sample, changing the face-crop padding from 0.8 to 0.25 barely moves the ranking (AUC 0.983 to 0.962) while taking the false-alarm rate from 3.4% to 37.9%. Validation therefore runs through the deployed preprocessing, never around it.

Request the technical validation report
FAQ

Questions we get asked

What is Exiphore?

Exiphore is a forensic media authentication platform built for law enforcement and security agencies. It examines video, imagery, audio, documents and text for signs of deepfake generation or manipulation, and produces an explainable, court-ready record: the measurements taken, their limitations, a sealed chain of custody, and a named examiner's signed adjudication.

How accurate is Exiphore at detecting deepfakes?

Measured end-to-end through the deployed pipeline on a balanced 60-image sample of the public Hemg/deepfake-and-real-images corpus, the platform flagged 86.7% of manipulated exhibits with a 0.0% false-alarm rate, and returned undetected manipulations as inconclusive rather than wrongly cleared. The learned classifier scores ROC-AUC 0.983 through that same preprocessing. That is a small sample from one corpus of still images: it is a floor on discrimination, not a performance guarantee for casework. Accuracy falls substantially on compressed, re-encoded and redistributed media, the corpus under-represents South Asian faces, and learned detectors generalise poorly to generators absent from their training data. The platform lowers its own confidence accordingly rather than overstating a result, and the full conditions and limits are published on the site.

What do we actually receive after an examination?

Six things, for every exhibit: the examination result (manipulated, authentic or inconclusive); a breakdown of which families of forensic evidence contributed and by how much; a confidence interval together with the quality ceiling the exhibit itself imposes; the sealed chain of custody and hash-chained audit trail; a named examiner's review, reasoning and signature; and a digest-sealed, court-ready report containing all of it, including the stated limitations.

Can Exiphore results be used as evidence in court?

Exiphore produces the record a court needs — measurements, stated limitations, a tamper-evident chain of custody, and a signed examiner adjudication — but an automated result is never an expert opinion on its own. Every finding requires a qualified examiner to review the measurements and record their reasoning before it is tendered. The platform is explicit about what it cannot establish.

What types of media can Exiphore analyse?

Video, images, audio, documents and text. Each medium is examined by the measurements appropriate to it, and exhibits can be submitted individually, in batches, by URL, or from a monitored path.

Does Exiphore send our evidence to the cloud?

No. Exiphore is deployed on your own infrastructure and evidence never leaves your estate. This is a requirement for data-sovereignty obligations and it is what makes the platform usable on material that cannot lawfully be sent to a third-party service. Optional narrative generation can be disabled entirely.

How is Exiphore different from a single deepfake detector?

A single detector gives you one number with no way to interrogate it, and generalises poorly to generation methods it has not seen. Exiphore fuses eight independent families of forensic evidence, de-correlates related measurements so they are not counted twice, reports a confidence interval rather than a point estimate, and surfaces disagreement between signals instead of averaging it away.

What happens when the evidence is ambiguous?

The platform returns inconclusive and says why — which families disagreed, or what about the exhibit's quality limited the examination. It also recommends the investigative steps that do not depend on the detection result, such as preserving the source account and obtaining a higher-quality original.

Who is Exiphore designed for?

Security agencies, law-enforcement agencies and police units handling synthetic-media offences: cyber crime, economic offences, women's safety, intelligence and forensic science laboratories. Access is by administrator-issued account only; there is no public sign-up.

Is Exiphore a deepfake detector?

Yes, and more precisely it is a forensic examination platform built around deepfake detection. A conventional deepfake detector returns one probability from one model. Exiphore runs measurements across eight independent families of forensic evidence, pools them so correlated signals are not counted twice, reports a confidence interval capped by the exhibit's own quality, and hands the result to a named examiner who reviews and signs it. Full detail is on the deepfake detector page.

What is the difference between a deepfake detector and a synthetic media detector?

In practice they describe the same category. Deepfake usually implies a manipulated human face or voice; synthetic media is the broader term, covering fully generated video with no real subject, cloned speech, AI-generated imagery, fabricated documents and synthetic identities. Exiphore examines all of them and reports which family of evidence supported the finding in each case.

Can Exiphore detect AI-generated video from generators it has not seen before?

In part. Learned classifiers only recognise what resembles their training data, so a generator released after the model was trained can evade that one signal entirely — the documented weakness of the whole detector family. This is why Exiphore never relies on a learned classifier alone: physiological, frequency, temporal and provenance evidence do not depend on having seen a particular generator before, so a new method has to defeat all of them at once.

Can Exiphore link related cases?

Yes. Fingerprints derived from every exhibit are indexed, so the platform surfaces matches across cases — the same source media, the same production characteristics, or a recurring subject. These are presented as investigative leads requiring corroboration, never as identifications.

How is Exiphore deployed?

As a self-contained on-premises stack. It runs on standard server hardware without specialised accelerators, and can operate fully air-gapped once installed. Deployment, examiner training and validation against your own casework are part of onboarding.

Request a demo

Bring us an exhibit you already know the answer to

The most useful demonstration is on your own material — something from a closed case where the ground truth is settled. We will walk through what the platform finds, what it misses, and what it refuses to conclude.

Deployment
On premises, on standard server hardware. Air-gapped operation supported.
Onboarding
Installation, examiner training, and validation against your own casework.
Access
Administrator-issued accounts only. No public sign-up, by design.

Prefer email? contact@exiphore.com · Read the technical methodology

We use your details only to respond to this enquiry. See our privacy policy.