Forensic Truthfor Every Exhibit
Digital evidence can be manipulated. Exiphore examines it across multiple forensic signals, preserves its provenance, exposes the evidence behind every finding, and makes uncertainty impossible to hide.
Deployed on your infrastructure. Evidence never leaves your estate.

The evidence is changing faster than the tools examining it
Investigators are being handed exhibits that no longer behave like exhibits. The material arrives re-encoded, stripped of provenance, and indistinguishable on inspection from the genuine article.
- AI-generated video
- Cloned voices
- Synthetic identities
- Manipulated documents
- Re-encoded social evidence
- AI-assisted forgery
Traditional detection asks
“Is this fake?”
One number, from one model, on media it may never have seen the like of. Nothing to interrogate and nothing to defend.
Exiphore asks
“What can we actually establish about this exhibit?”
Independent measurements, pooled and calibrated, each stating what it cannot show — and an examiner who signs the answer.
A real deepfake, examined
Around the Jantar Mantar demonstrations in New Delhi, a 47-second clip circulated on messaging apps showing a serving senior officer of the Delhi Police announcing his resignation and making allegations about the conduct of an investigation. It was sealed and examined. Below is what came back — the real numbers, including the ones that are unflattering.
- Duration
- 47.3 s
- Resolution
- 360 × 444
- Bitrate
- 167 kbps
- Faces
- 1 · 95 px wide
- Physiological2 signals41.3%
Pulse recovered from four facial regions disagrees between regions
- Frequency2 signals29.1%
High-frequency tail departs from the natural power law
- Temporal3 signals27.7%
Learned lip-sync analysis inconsistent with genuine capture
- Metadata2 signals1.9%
Transcoded; acquisition structure destroyed. Normal for redistributed media
- Artifact3 signals0.0%
No compositing boundary found — which alone cannot mean the exhibit is genuine
- Learned model1 signal0.0%
Manipulation probability low, but constrained so it can never assert authenticity
- Provenance1 signalexcluded
No content credentials recoverable. Non-informative, so it carries no weight in either direction rather than counting as a point against.
Manipulation Indicated
0.74Three independent families indicate the exhibit has been altered. Escalate to examiner review.
- Interval
- 0.59 – 0.88
- Examiner confidence
- 57%
- Quality ceiling
- 57%
- Exhibit quality caps achievable confidence at 57%: one face detected, 95 px wide. A face this small relative to the frame makes the pulse measurement unreliable.
- No provenance layer was recoverable. Absence of provenance is normal for re-encoded media and is not itself evidence of manipulation.
An automated result is not an expert opinion. A named examiner reviews the measurements and signs before this is relied upon.
What you receive for every exhibit
Not a score. A record: what was measured, what it establishes, what it does not, who examined it, and the bytes it all attaches to.

- 01
Examination result
Manipulated, authentic or inconclusive — with the headline stated in the language a case file uses, not a probability left for someone else to read.
- 02
Evidence breakdown
Which families of forensic evidence contributed, how much each moved the result, and which found nothing. Silence is recorded as silence.
- 03
Confidence and quality ceiling
A confidence interval rather than a point estimate, and the ceiling the exhibit's own quality places on how certain any result is allowed to be.
- 04
Chain of custody
Hashes taken at seal and re-verified before every run, custody events, and a hash-chained audit trail across every action anyone took.
- 05
Examiner adjudication
A named examiner's review, their recorded reasoning, and a signature that binds examiner, analysis and rationale together.
- 06
Court-ready report
Findings, limitations, custody history and the signed adjudication frozen into a digest-sealed PDF that travels with the exhibit.
Built to survive cross-examination
Anything can produce a score. What a case needs is a finding an examiner can defend under questioning — with its reasoning, its limits and its provenance intact.
Eight independent families of evidence
Physiological signals a generator has to fabricate. Cryptographic provenance. Spectral structure. Temporal coherence. Compression and editing traces. Each family is pooled separately, so related measurements are counted once rather than mistaken for corroboration.
Explainable, measurement by measurement
Every signal shows what it measured, how strongly it was weighted for this exhibit, and what it cannot establish. Visual exhibits are rendered for the findings that have one. Nothing is a black box, because a black box does not survive cross-examination.
Sealed chain of custody
Exhibits are hashed and sealed on intake and stored read-only. The seal is re-verified before every examination, and a mismatch refuses the run. Custody and audit records are hash-chained, so any later alteration is provable.
Calibrated confidence, not false precision
Results carry a confidence interval, and exhibit quality caps how confident any result can be. When signals disagree, the platform says so and returns inconclusive rather than inventing a verdict.
Cross-case linking
Fingerprints from every exhibit are indexed, so the registry answers the question that actually advances an investigation: have we seen this before? Matches surface across cases as investigative leads.
Reports built for court
Findings, limitations, custody history and the examiner's signed adjudication are frozen into a digest-sealed report. No result is released as an expert opinion until a named examiner has reviewed the measurements and signed.
A team of specialist agents, not one model
Exiphore is built as a coordinated system of AI agents. Each owns one part of the examination, works independently, and reports to an orchestrator that has to reconcile them. Independence is the point — agents that cannot see each other's conclusions cannot talk each other into one.
Intake agent
Seals and characterisesHashes the exhibit, writes it read-only, opens the chain of custody, and assesses what evidence is recoverable at all. Its quality assessment caps how confident every downstream agent is allowed to be.
Examination agents
Measure, in parallelA specialist per family of forensic evidence, each running independently on the sealed original. An agent that cannot obtain usable data reports that it could not, rather than guessing — silence is recorded as silence.
Adjudication agent
Reconciles and calibratesPools related findings so correlated measurements are not mistaken for corroboration, weighs each family's independence, and produces a confidence interval. Where agents disagree it reports the conflict instead of averaging it away.
Narrative agent
Explains, never decidesRenders the measurements into language an investigating officer can act on and a court can read. It receives the finding after it is fixed and cannot alter it — a language model must never be able to move a number that ends up in a charge sheet.
Action-plan agent
Recommends next stepsProduces the investigative actions that do not depend on the technical finding holding up — preservation, provenance, source attribution. The critical steps are generated by rule, so they appear even if every model is unavailable.
Review workflow
Human, and namedNo agent signs anything. A qualified examiner reviews the measurements and records their reasoning, and that signature binds examiner, analysis and rationale together. The agents produce the record; a person owns the opinion.
Every measurement shows its working
Signals are grouped into families and pooled so that related measurements count once. The result shows which families drove the finding, how much each contributed, and where they disagreed.
- Per-family influence, so you can see what actually moved the result
- Every signal states what it cannot establish, in band
- Visual exhibits rendered for the findings that have one
- Raw measurements available for an opposing expert to check


A caseload, not a one-off tool
Exhibits belong to cases. Cases carry custody, findings, reports and adjudications. Nothing is deleted — cases close and exhibits supersede, so the question of what else was run is answerable from the record.
- Single, batch, URL and monitored-path intake
- Role-based access with administrator-issued accounts only
- Hash-chained audit trail across every action taken
- Recommended investigative steps that survive an inconclusive result
Built for the people who handle digital evidence
Different desks bring the same exhibit for different reasons. What they share is that a wrong answer is expensive and an unexplained answer is useless.
Police and cyber crime
Triage viral media at the speed it spreads, investigate impersonation and harassment, and preserve the exhibit before the source account disappears.
How it is usedForensic science laboratories
Repeatable examinations with the raw measurements exposed, so an opposing expert can check the working rather than take a vendor's word for it.
How it is usedIntelligence and security
Identify coordinated synthetic-media campaigns and link exhibits across cases through the production characteristics they share.
How it is usedFinancial crime
Investigate voice-cloned authorisation, video-KYC abuse and executive impersonation, including retrospective review of onboarding at volume.
How it is usedProsecution and legal
Understand precisely what an examination establishes — and, just as importantly, where it stops — before the finding is tendered.
How it is usedSee how Exiphore fits your workflow
We will walk it through against your own casework, on your own material.
Request a demonstrationWhere it earns its place
Synthetic media is not one offence. It is a method that shows up across fraud, harassment, disinformation and forgery — each with its own evidential problem.

Economic offences · Cyber crime
Impersonation and payment fraud
A cloned executive authorises a transfer. A familiar voice calls a relative in distress. Examine the recording and preserve the source chain while it is still recoverable.
Read more
Women's safety · Cyber crime
Non-consensual intimate imagery
Victims need a finding quickly, and it has to hold. Seal on intake, examine for compositing evidence, and link a single offender's output across cases.
Read more
Intelligence · State command centre
Election and public-order disinformation
A clip of a public official circulates hours before polling. Triage at volume, escalate what matters, and link a coordinated campaign by what its media has in common.
Read more
Document examination · Economic offences
Forged documents and records
Altered certificates, tampered statements, doctored correspondence. Documents record their own revision history in places most forgers never clean.
Read more
Financial crime · Regulatory
Identity and video-KYC abuse
Synthetic faces defeat liveness checks and open mule accounts at scale. Examine onboarding captures and link recurring synthetic identities.
Read more
Prosecution · Forensic science laboratory
Evidentiary review and disclosure
Before an exhibit is tendered, establish what can and cannot be said about it — measurements, limitations, custody and signed reasoning as one sealed record.
Read moreSeal, examine, adjudicate, sign
The order matters. Nothing is analysed before it is sealed, and nothing is released before a person has signed it.
- 01Seal
Hashed, written read-only, custody opened. Nothing is examined before it is sealed.
- 02Examine
Specialist agents measure in parallel, independently, on the sealed original.
- 03Adjudicate
Related findings pool once. Disagreement is reported, not averaged away.
- 04Sign
A named examiner reviews the measurements and owns the opinion.
Most detectors are confidently wrong
The failure mode is always the same: a single number, produced from degraded evidence, with no way to interrogate it. These are the design decisions that follow from taking that seriously.
Absence of evidence is not evidence of absence
Most detectors can only evidence manipulation. One that finds nothing has shown its particular artefact is missing — which is exactly what a wholly generated exhibit looks like. Those signals are constrained so they can never assert authenticity, and a clean finding requires positive evidence of genuine capture.
Inconclusive is a real finding
When the evidence does not discriminate, that is reported as a substantive result. A platform that is never unsure is not being careful — it is guessing, and the guess will be found under cross-examination.
Detection alone is an arms race
Detectors generalise poorly to methods they have never seen, and degrade on compressed, redistributed media. Exiphore pairs detection with provenance and source attribution, and states its limits in every report.
Deployed on your infrastructure
Runs entirely on premises. Evidence never leaves your estate, which is what data-sovereignty obligations require and what makes the platform usable on material that cannot be sent to a third party.
Where the difference actually lies
Against a single deepfake detector, and against the conventional forensic tooling a laboratory already runs.
| Capability | Single detector | Conventional forensic suite | Exiphore |
|---|---|---|---|
| Detects AI-generated media | Yes | partialPartial | Yes |
| Multiple independent evidence families | No | Yes | Yes |
| Related measurements de-correlated before pooling | No | No | Yes |
| Confidence interval rather than a point score | No | No | Yes |
| Exhibit quality caps achievable confidence | No | No | Yes |
| Reports disagreement instead of averaging it | No | No | Yes |
| Cannot infer authenticity from absent artefacts | No | partialPartial | Yes |
| Sealed, hash-chained chain of custody | No | Yes | Yes |
| Cross-case fingerprint linking | No | partialPartial | Yes |
| Named examiner adjudication before release | No | Yes | Yes |
| Court-ready report | partialPartial | Yes | Yes |
| Air-gapped deployment | partialPartial | Yes | Yes |
| Validation limits published, not just headline accuracy | No | partialPartial | Yes |
It runs inside your estate, or it does not run
Exiphore is installed on your own infrastructure. There is no hosted tier, no public sign-up and no path by which an exhibit reaches a third party.
Deployment
- On premises, on standard server hardware — no specialised accelerators required
- Fully air-gapped operation supported once installed
- Private-cloud installation within your own tenancy
- No external API dependency in the examination path
Evidence handling
- Content-addressed, write-once evidence locker; originals are never modified
- Seal re-verified before every examination — a hash mismatch refuses the run
- Hash-chained, append-only chain of custody
- Hash-chained audit log covering every action taken by every account
Access control
- Five roles: administrator, supervisor, examiner, analyst, viewer
- Administrator-issued accounts only; no public sign-up, by design
- Configurable session lifetime, defaulting to 45 minutes
- Per-case classification from unclassified through secret
Optional narrative generation is the only component that can call an external model, it never touches the verdict or any measurement, and it can be disabled entirely by leaving its key unset.
The number, and everything you need to judge it
Here is our headline accuracy figure and the exact conditions that produced it. The two belong together — a number with no methodology behind it tells you nothing about what it will do on your casework.
0.983
Classifier ROC-AUC
through deployed preprocessing
86.7%
Manipulated exhibits flagged
end-to-end, after fusion
0.0%
Authentic exhibits wrongly flagged
false-alarm rate
Inconclusive
Undetected manipulations
never wrongly cleared
How it was measured
- Corpus
- Hemg/deepfake-and-real-images — a public, independently published dataset
- Sample
- 60 images, balanced between manipulated and authentic
- Measured through
- The deployed pipeline: face detection, 0.8 context pad, 224 px resize
- Measured at
- End-to-end, after multi-signal fusion — not the classifier in isolation
- Engine version
- 1.0.0
- Re-measurement
- Gated in CI; any model or preprocessing change re-runs the validation and fails the build if discrimination cannot be shown
Calibration is a measured parameter, not a default. On the same sample, changing the face-crop padding from 0.8 to 0.25 barely moves the ranking (AUC 0.983 to 0.962) while taking the false-alarm rate from 3.4% to 37.9%. Validation therefore runs through the deployed preprocessing, never around it.
Request the technical validation reportNotes from an adversarial field
Practical writing on detection, digital evidence, and what actually survives challenge.
How to detect a deepfake video
The visual tells everyone repeats stopped working years ago. A practical guide to what genuinely indicates a manipulated video in 2026, and why a single detector score is not enough.
Read articleLegal · 8 minIs deepfake evidence admissible in court?
A detection score is not evidence. What actually has to be established for a media authentication finding to survive challenge — custody, methodology, stated limitations and a named examiner.
Read articleFraud · 7 minVoice cloning scams
Seconds of reference audio is enough to clone a voice. How cloned-voice fraud is actually executed, what forensic evidence survives a phone call, and what to preserve first.
Read articleQuestions we get asked
What is Exiphore?
Exiphore is a forensic media authentication platform built for law enforcement and security agencies. It examines video, imagery, audio, documents and text for signs of deepfake generation or manipulation, and produces an explainable, court-ready record: the measurements taken, their limitations, a sealed chain of custody, and a named examiner's signed adjudication.
How accurate is Exiphore at detecting deepfakes?
Measured end-to-end through the deployed pipeline on a balanced 60-image sample of the public Hemg/deepfake-and-real-images corpus, the platform flagged 86.7% of manipulated exhibits with a 0.0% false-alarm rate, and returned undetected manipulations as inconclusive rather than wrongly cleared. The learned classifier scores ROC-AUC 0.983 through that same preprocessing. That is a small sample from one corpus of still images: it is a floor on discrimination, not a performance guarantee for casework. Accuracy falls substantially on compressed, re-encoded and redistributed media, the corpus under-represents South Asian faces, and learned detectors generalise poorly to generators absent from their training data. The platform lowers its own confidence accordingly rather than overstating a result, and the full conditions and limits are published on the site.
What do we actually receive after an examination?
Six things, for every exhibit: the examination result (manipulated, authentic or inconclusive); a breakdown of which families of forensic evidence contributed and by how much; a confidence interval together with the quality ceiling the exhibit itself imposes; the sealed chain of custody and hash-chained audit trail; a named examiner's review, reasoning and signature; and a digest-sealed, court-ready report containing all of it, including the stated limitations.
Can Exiphore results be used as evidence in court?
Exiphore produces the record a court needs — measurements, stated limitations, a tamper-evident chain of custody, and a signed examiner adjudication — but an automated result is never an expert opinion on its own. Every finding requires a qualified examiner to review the measurements and record their reasoning before it is tendered. The platform is explicit about what it cannot establish.
What types of media can Exiphore analyse?
Video, images, audio, documents and text. Each medium is examined by the measurements appropriate to it, and exhibits can be submitted individually, in batches, by URL, or from a monitored path.
Does Exiphore send our evidence to the cloud?
No. Exiphore is deployed on your own infrastructure and evidence never leaves your estate. This is a requirement for data-sovereignty obligations and it is what makes the platform usable on material that cannot lawfully be sent to a third-party service. Optional narrative generation can be disabled entirely.
How is Exiphore different from a single deepfake detector?
A single detector gives you one number with no way to interrogate it, and generalises poorly to generation methods it has not seen. Exiphore fuses eight independent families of forensic evidence, de-correlates related measurements so they are not counted twice, reports a confidence interval rather than a point estimate, and surfaces disagreement between signals instead of averaging it away.
What happens when the evidence is ambiguous?
The platform returns inconclusive and says why — which families disagreed, or what about the exhibit's quality limited the examination. It also recommends the investigative steps that do not depend on the detection result, such as preserving the source account and obtaining a higher-quality original.
Who is Exiphore designed for?
Security agencies, law-enforcement agencies and police units handling synthetic-media offences: cyber crime, economic offences, women's safety, intelligence and forensic science laboratories. Access is by administrator-issued account only; there is no public sign-up.
Is Exiphore a deepfake detector?
Yes, and more precisely it is a forensic examination platform built around deepfake detection. A conventional deepfake detector returns one probability from one model. Exiphore runs measurements across eight independent families of forensic evidence, pools them so correlated signals are not counted twice, reports a confidence interval capped by the exhibit's own quality, and hands the result to a named examiner who reviews and signs it. Full detail is on the deepfake detector page.
What is the difference between a deepfake detector and a synthetic media detector?
In practice they describe the same category. Deepfake usually implies a manipulated human face or voice; synthetic media is the broader term, covering fully generated video with no real subject, cloned speech, AI-generated imagery, fabricated documents and synthetic identities. Exiphore examines all of them and reports which family of evidence supported the finding in each case.
Can Exiphore detect AI-generated video from generators it has not seen before?
In part. Learned classifiers only recognise what resembles their training data, so a generator released after the model was trained can evade that one signal entirely — the documented weakness of the whole detector family. This is why Exiphore never relies on a learned classifier alone: physiological, frequency, temporal and provenance evidence do not depend on having seen a particular generator before, so a new method has to defeat all of them at once.
Can Exiphore link related cases?
Yes. Fingerprints derived from every exhibit are indexed, so the platform surfaces matches across cases — the same source media, the same production characteristics, or a recurring subject. These are presented as investigative leads requiring corroboration, never as identifications.
How is Exiphore deployed?
As a self-contained on-premises stack. It runs on standard server hardware without specialised accelerators, and can operate fully air-gapped once installed. Deployment, examiner training and validation against your own casework are part of onboarding.
Bring us an exhibit you already know the answer to
The most useful demonstration is on your own material — something from a closed case where the ground truth is settled. We will walk through what the platform finds, what it misses, and what it refuses to conclude.
- Deployment
- On premises, on standard server hardware. Air-gapped operation supported.
- Onboarding
- Installation, examiner training, and validation against your own casework.
- Access
- Administrator-issued accounts only. No public sign-up, by design.
Prefer email? contact@exiphore.com · Read the technical methodology