ZOREAL
Proof of human

Know there’s a real human on the other side.

ZOREAL is the trust layer that proves a real human is present behind digital interactions: across calls, messages, transactions, accounts and content.

Verify human presence in real time. Detect synthetic identities, deepfakes and AI-driven impersonation without turning every interaction into another identity check.

Businesses
Humans
Utopia
Passport
Specimen
9:41
Issued by DEEuropean Union
Specimen portrait on a specimen ZOREAL ID
32
Mei Ling Hoffmann
DE-C58274019
ZOREAL ID
ID
Verify
Settings
Identity Card
Specimen
Surname
SPECIMEN
Date of birth
01 JAN 1990
I<UTOD23145890<<<<<<<<<<<<<<<<
9001011M3001014UTO<<<<<<<<<<<2
SPECIMEN<<SPECIMEN<<<<<<<<<<<<
Real human
Proof of Human (POH)
A real person is here. No name, no document, nothing about who they are.
Proof of Human + KYC
A real person, and exactly who they are, when the situation calls for it.
You choose which
A message board needs a human. A bank needs a name. Ask for one or the other.
Held by the person
The proof belongs to the human it describes, and stays with them.
Built against
  • ICAO 9303
  • ISO/IEC 7810 ID-1
  • ISO/IEC 18013-5
  • eIDAS 2 / EUDI ARF
  • OpenID4VCI
  • OpenID4VP
Deepfake video meetings

The internet was built to trust humans. AI changed that.

A meeting is called. The faces are the right faces and the voices are the right voices. The request is urgent, and it comes from the person who is allowed to make it. Money moves, or access is granted, or a contract is agreed. Nobody on that call was there.

The control that used to catch this was to hang up and call the person back. That control now runs over the same channel the attack came in on. A face and a voice were evidence because faking them was expensive. That stopped being true.

A few reported cases

Companies and executives

  • ArupHong Kong · 2024 · HK$200m

    An employee joined a video call full of familiar colleagues and approved fifteen transfers. Everyone else on the call was fabricated.

  • Singapore finance director2025 · US$499,000

    He joined a call with his chief executive and wired the money. Singapore and Hong Kong police traced and withheld it within two days.

  • WPP2024 · attempt stopped

    A meeting built around the chief executive’s public photo and a cloned voice. The colleague it targeted did not go along with it.

  • Tirana exchange officeAlbania · 2026 · EUR 100,000

    An AI video call in the name of a local businessman, and three people charged over it.

Governments and officials

  • Singapore government impersonation2026 · at least S$4.9m

    A fabricated conference of Singapore’s Prime Minister, President and ministers. Police published the recording in full.

  • US Senator Ben Cardin2024 · attempt stopped

    A senator took a video call from Ukraine’s former foreign minister. The face and the voice held; the questions did not.

  • European MPs2021 · attempt stopped

    Members of parliament in four countries took video calls from a Russian opposition figure who was never on them.

  • David Cameron2024 · attempt stopped

    The UK Foreign Secretary took video calls from a man presenting as Ukraine’s former president. No AI was needed. The impersonation was enough.

Running campaigns

  • BlueNoroff2025-26 · crypto and Web3 staff

    Fake meeting lobbies filled with stolen and synthetic faces, used to talk staff into installing malware, and to harvest the next set of faces.

  • Romance and investment scamsongoing · sold as a service

    Live face-swap platforms marketed to scammers, so the person a victim video-calls for months does not exist.

  • Remote hiringongoing · North Korean IT workers

    The FBI has recorded face-swapping in video job interviews. Kraken caught one candidate by asking them to prove where they were sitting.

Seeing is no longer believing.

  • A face on a video call used to mean something.
  • A familiar voice used to mean something.
  • A message from a known account used to mean something.

AI changed that.

Deepfake video, cloned voices, autonomous agents and synthetic identities can now look and behave increasingly like real people. Traditional authentication can tell you that an account, device or credential is valid.

It cannot always tell you whether a real human is actually there.

ZOREAL can.

Getting in
  • Interviews and remote hiring
  • Onboarding checks, where a genuine capture taken once can be presented again
  • Exams and certifications sat by somebody else
Getting back in
  • Account recovery answered by voice or by video
  • Support desks talked into a reset
  • Takeover that passes every check for the device and the password
Signing and authorising
  • A key was used. Whether the holder was there is a separate question
  • Approvals that carry legal weight
At scale
  • Replies, reviews and matches written by nobody
  • One operator wearing thousands of faces

One question sits underneath all of them.

Not does this video look synthetic. That is a question about an artefact, it is answered with a probability, and it gets harder every time the generators improve.

The question ZOREAL asks is is there a specific, real person here. ZOREAL puts that question to the person, and comes back with an answer rather than a score. It does not matter how good the generator got, because nothing here is examining the picture.

Is it really your boss on that video call?

A face on a call. A voice on the phone. A message from the right account. These signals once made impersonation expensive. Now they can be copied on demand.

An anonymous human surrounded by synthetic copies, calls and digital transaction fragments

When every channel can be faked, trust becomes the attack surface.

Calls

A familiar face and voice can be generated, replayed or stolen. Seeing someone is no longer the same as verifying them.

Messages

A name, writing style and conversation history can be copied into a request that feels completely normal.

Transactions

A valid login proves access to an account. It does not prove the expected human approved the action.

Accounts

One operator can create, recover or control many convincing identities behind ordinary devices and credentials.

Content

Reviews, posts and support requests can look human even when no accountable person stands behind them.

The failure appears when trust matters most.

The attack changes by industry. The missing proof stays the same: is the expected human actually present at the moment of risk?

Some of these need to know who someone is. Most of them only need to know that someone real is there.

High-stakes calls

What breaks

The callback becomes part of the attack. The face and voice meant to verify the instruction can be the fake.

What ZOREAL adds

Ask the expected person for a separate proof of presence before the instruction is trusted.

Remote hiring

A synthetic candidate can look convincing long enough to enter interviews, payroll and internal systems.

Bind the account and the live check to the same verified human.

Account recovery

The weakest identity checks often appear exactly when passwords, devices and trusted factors are gone.

Reconnect recovery to a verified human, not another intercepted code or copied selfie.

Human-only platforms

One person can operate many accounts, while bots and synthetic profiles make every interaction less trustworthy.

Verify a human, or an eligible unique person, without exposing their identity to every service.

A synthetic identity branching into calls, messages, accounts, transactions and content

Stop asking if it looks real. Ask the human to prove they are there.

Deepfake detectors study the video and give you a probability. ZOREAL asks the person instead, and comes back with an answer: a real human is here, and, if you need it, this is who.

A document chip, phone and human portrait connected as one verification path

Is a real human there?

Proof of Human, on its own. The answer is yes or no, and it carries no name, no document and no personal data. Enough to keep AI out of a comment thread, a review or a reply.

And who is it?

Proof of Human with KYC, when the moment needs a name. The same check, plus an identity confirmed against the person’s own government ID.

You decide which one you get

A message board never needs to know who someone is. A bank does. Asking for the smaller answer is the default, not a downgrade.

Someone proves they are human once. After that they can show it again on a call, in a message, at a checkout or before a post goes live, without going through the whole thing a second time.

Verification should not become surveillance.

The answer to synthetic identity cannot be another central database of faces, voices and documents. Privacy is part of the security model.

  • The government

    Issues the ID and stands behind it.

  • The person

    Keeps the proof, and decides who sees it.

  • The business

    Gets the answer it asked for. Nothing else.

Ask for Proof of Human and no name, document or date of birth ever reaches you. There is nothing to store, and nothing to lose.

A holder-controlled credential sharing one limited proof with a verifier

Built to protect your organisation and the people you verify.

  • AICPA SOC certified
  • PCI DSS compliant
  • GDPR compliant
  • ISO/IEC 27001:2022 certified
  • CSA STAR Level One

Enterprise-grade admin controls, security integrations, full data governance, independent compliance audits and end-to-end privacy protection. The data behind every check is held to the same standard as the check itself.

See Bynn Intelligence’s reports and their scope

Make human presence part of the decision.

Add a human proof before access, approval or action. Keep the interaction fast, and keep unnecessary identity data out of it.

Businesses
Humans