Stop deepfake video before your team acts on it
Catch synthetic faces and manipulated video on Zoom, Teams, Meet, and Webex, scored continuously through the call, whether the fake is an executive, a vendor, or a job candidate.
From signals to one action your team can take.
- Synthetic detectedVideoGeneration artifacts consistent with a face swap or full avatar
- FailedLivenessStream characteristics point to injected rather than captured video
- All participantsCoverageEvery face on the call scored, not only whoever is speaking
- Pressure risingConversationAuthority framing and a compressed deadline alongside the media flag
Hold the call. When video and conversation cross threshold, the team verifies before the irreversible step.
How video scoring runs
The same pipeline runs on a live call and on a file you upload to the detector. Nothing is installed on the other participant's side.
- 1
Sample the stream
Frames are sampled continuously through the call rather than once at the start, so a clean opening does not buy the attacker the rest of the meeting.
Continuous · no caller-side install
- 2
Score against our own models
Each detected face is cropped and scored for generation artifacts by models Diopter builds and maintains, so a call with four participants produces four independently scored subjects.
Proprietary models · per-face attribution
- 3
Keep scoring to the end
Scoring does not stop after an opening sample. A participant who joins late, turns their camera on halfway through, or only speaks at the ask is scored the same as everyone else.
Real time · full call duration
- 4
Resolve one verdict
Per-face results combine into one band with a confidence level and the underlying evidence retained, so a reviewer can see which face drove it.
Bands: AI · mixed · clean · inconclusive
Where deepfake video shows up
- 01
Deepfaked executives on camera
Attackers join approval calls as a convincing on-camera executive or colleague, the way the Arup call put a fake CFO and fake colleagues in one meeting.
- 02
Synthetic candidates in interviews
Fraudulent candidates use deepfake video to pass remote screens and reach payroll and systems.
- 03
Spoofed vendors on video
A vendor rep on a video call who is not who they appear to be, pushing a payment or a change.
How a deepfake video attack unfolds
These attacks move through a recognizable sequence. Diopter scores that sequence while the call is still in progress.
A trusted face appears
An executive, colleague, vendor, or candidate shows up on camera, convincing at first glance.
A deadline compresses the check
A close, a payroll run, or an offer window pressures the team to act before verifying.
The call narrows
The conversation moves to a smaller meeting or an off-domain follow-up that removes witnesses.
The asks build
Each step normalizes the next, an approval, then access, then one more exception.
The decision lands
An approval, a hire, or a transfer goes through on the strength of a face that was never real.
Every call where a face is the credential.
Wherever a decision rests on recognizing someone on camera, this is the check that stands behind it.
Interview screens
A candidate whose face is generated or swapped, caught during the round rather than after the offer.
Treasury and closing calls
The finance lead authorizing a transfer, scored before the wire is released.
Supplier and AP calls
The rep on camera asking for a banking change, checked against who they claim to be.
Board and executive sessions
Larger calls where the quiet attendee matters, because every face is scored and not just whoever holds the floor.
One frame is a coin flip. A whole call is evidence.
Single-image detectors are graded on stills, and a current face-swap model beats them often enough to be worth the attacker's time. Video is a much harder thing to fake convincingly for an hour: the artifacts have to survive every head turn, every lighting change, and every compression pass. Diopter scores every face against models we build ourselves rather than a public detector an attacker can rehearse against, and it keeps scoring for the length of the call, so what your team gets is a verdict attributable to a person rather than a probability on one screenshot.
A deepfaked face on camera passes a frame check. The way that fake builds authority and pressures the room does not.
Where single-layer tools stop.
Each category below covers one part of the attack and is blind to the rest. The last column is the only one that correlates them into a single verdict.
Detects synthetic voice on a live call
- Awareness training
- Not supported
- Single-frame deepfake
- Not supported
- Identity / reputation
- Partial
- Live-call detection
- Supported
- Diopter Arc
- Supported
Detects deepfake video frames
- Awareness training
- Not supported
- Single-frame deepfake
- Supported
- Identity / reputation
- Not supported
- Live-call detection
- Partial
- Diopter Arc
- Supported
Verifies caller identity (reputation/biometric)
- Awareness training
- Not supported
- Single-frame deepfake
- Not supported
- Identity / reputation
- Supported
- Live-call detection
- Partial
- Diopter Arc
- Supported
Models the conversation arc (pressure → ask)
- Awareness training
- Partial
- Single-frame deepfake
- Not supported
- Identity / reputation
- Not supported
- Live-call detection
- Not supported
- Diopter Arc
- Supported
Correlates identity, media, and conversation signals on live calls
- Awareness training
- Not supported
- Single-frame deepfake
- Not supported
- Identity / reputation
- Partial
- Live-call detection
- Not supported
- Diopter Arc
- Supported
Forensic evidence chain for incident review
- Awareness training
- Not supported
- Single-frame deepfake
- Partial
- Identity / reputation
- Partial
- Live-call detection
- Partial
- Diopter Arc
- Supported
| Capability | Awareness training | Single-frame deepfake | Identity / reputation | Live-call detection | Diopter Arc |
|---|---|---|---|---|---|
| Detects synthetic voice on a live call | Not supported | Not supported | Partial | Supported | Supported |
| Detects deepfake video frames | Not supported | Supported | Not supported | Partial | Supported |
| Verifies caller identity (reputation/biometric) | Not supported | Not supported | Supported | Partial | Supported |
| Models the conversation arc (pressure → ask) | Partial | Not supported | Not supported | Not supported | Supported |
| Correlates identity, media, and conversation signals on live calls | Not supported | Not supported | Partial | Not supported | Supported |
| Forensic evidence chain for incident review | Not supported | Partial | Partial | Partial | Supported |
What video detection does not claim
Worth reading before a pilot, because these are the cases that generate a support ticket if nobody told you first.
A clean result is not proof of authenticity
Clean means our detectors found no manipulation in what they were able to evaluate. It is evidence, not a guarantee, and the report says so rather than implying certainty.
Coverage is reported, not assumed
If a participant kept their camera off, joined for twenty seconds, or came through at a bitrate too low to score, that is reported as inconclusive rather than quietly counted as clean.
Confidence never reads 100 percent
The highest the report will state is over 99 percent. A detector that claims certainty is the one number a buyer can hold against it later.
Light to deploy, clear about what runs where.
Pilot in days, roll wider through MDM, and keep sensitive call media inside your perimeter.
- On-prem and hybrid deployments supported
- No caller-side install
- Bot or bot-free capture
- Configurable retention, including ZDR
- MDM rollout (Intune, Jamf)
- SOC 2 Type II in progress
Walk an attack arc with Diopter.
We will replay a real incident, show the signals Diopter scored, and map the verdict your team would act on. We will sign your NDA first if you want one.
What security and fraud teams ask first.
Yes. Every face on the call is scored independently and continuously, so a synthetic participant who is sitting quietly rather than doing the talking is still flagged.
Zoom, Teams, Google Meet, and Webex, alongside the call rather than through a separate upload.
Yes. The same detection runs on interview calls, so a deepfaked candidate is flagged during the screen, not after access is granted.
No. Diopter scores the manipulation pattern, not isolated artifacts, so a normal call with real urgency does not trip it. Only the combination, an authority claim plus pressure plus an escalating ask, crosses the threshold. Your team sees fewer alerts with higher signal.
Diopter supports on-prem and hybrid deployments, with configurable retention including a zero-data-retention option. It runs with a meeting bot or bot-free, and needs no caller-side install. SOC 2 Type II is in progress.
Diopter works alongside the video and voice tools your team already uses, and rolls out through your existing MDM such as Intune or Jamf. There is no caller-side install and no change to how your team takes calls.
No. Every verdict carries a confidence level, not a flat flag, and if a call or file could not be fully checked, Diopter reports that rather than defaulting to a clean result. You can see this directly: every report from the Deepfake Detector shows the same confidence scoring behind Diopter's verdicts.
Research behind video deepfake detection
All research →Deepfake Detection for Video Conferencing: Zoom, Teams, Meet, and Webex
How deepfake attacks run on Zoom, Teams, Meet and Webex, why single-frame checks miss them, and what continuous detection during a live call looks at.
Deepfake Video Detection Explained: How to Spot Them and How to Stay Safe
How deepfake video detection works in 2026: seven method families, what each catches, where each breaks, and how to layer them across your stack.
Famous Deepfake Scams: The 2024 Arup Cyber Attack
Arup's official statement on the HK$200M deepfake scam: how attackers faked a video call in Hong Kong, and what could have stopped it.