Proof of person.

A quick check for important moments.

Sonavera runs in the browser, takes about 30 seconds, and returns signed evidence that a real, live person completed it. No app to install. No ID required.

  • Runs in browser
  • About 30s
  • User-friendly
  • No raw media or templates in your results
  • Your system decides

Do your riskiest flows have the weakest safeguards?

An SMS code proves someone has a phone. It doesn’t prove who’s holding it. Manual review is slow, expensive, and different every time. Legal ID is often overkill.

Sonavera takes a different path: a short, guided session in the browser that gathers positive evidence a real person is present (face, voice, liveness, and media signals), then sends the user straight back to your app. Done in about 30 seconds.

Handshake illustration

Confidence where it counts

Built for the moments that matter.

Trigger a handshake only when the stakes are high: when your risk engine flags something, or the action itself is too big to wave through.

Account recovery

They lost the password and the phone. Before you hand the account back, compare the person asking with the person who enrolled.

Sensitive support actions

Email changes, MFA resets, recovery settings: the moves attackers make right before they cash out. Add a live check before support clicks approve.

Privileged and agent actions

When an AI agent tries to do something dangerous, add a live check before your system approves it.

High-value payouts

Link our evidence to the payout, so the money moves only after you have proof-of-person.

How it works

Step 1

You send them to us

Your app starts a handshake over OIDC or a simple API redirect, tied to the exact action you’re protecting.

Step 2

We run the check

The user reviews what’s being asked and consents, then completes a short guided session with their camera and microphone.

Step 3

You get the evidence

Your backend fetches a signed result and applies your own rules. Strong evidence or weak, the decision is yours.

Watch a handshake happenProduct demo · about 2 minutes
Prefer to try it yourself? The live demo runs the real thing: nothing to install.

Evidence, not verdicts

See exactly why the number is what it is.

Every check returns an Evidence Index from 0 to 100, not a pass/fail, not a probability. It’s composed from fixed, published allocations: each signal earns points toward its share, and anything we couldn’t measure earns zero, in plain sight.

No hidden reweighting. No black box. You see every measurement, what it contributed, and why, so your policy can be as strict or as forgiving as your product needs.

Verification evidence · unsigned example
Identity match
30.50 / 40 pts
Face continuity
12.41 / 15 pts
Challenge integrity
20.50 / 25 pts
Media integrity
16.40 / 20 pts

Real structure, example numbers: rendered from the same generated fixture our tests use.

OIDC step-up

The pattern your identity stack already speaks: Authorization Code with PKCE and a signed ID token carrying the evidence.

API redirect

The simplest path. One call to start, a redirect, one call to fetch the result. Good for a pilot afternoon.

Signed webhooks

Get told when a check finishes instead of polling. Every delivery is HMAC-signed so your backend can verify it.

TypeScript SDK

Helpers for starting checks, validating results and tokens, verifying webhooks, and handling deletion requests.

Easy integration the way you work.

Sonavera isn’t your identity provider and doesn’t want to be. Keep your login, your user database, and your rules. Call us for the moments that need a real person.

A tenant-scoped Sonavera check connects explicit consent, protected templates, limited signed evidence, and scheduled deletion.
Your tenant boundaryOne consented check
Signed evidenceNo raw media or embeddings, ever.

Privacy-first, secure by design.

Consent comes first: no consent, no check. Biometric data stays inside our system, never compared across customers. Your results carry evidence, not recordings. And everything expires: deletion is on the calendar from the moment the check starts.

We run the check. You make the call.

Try it now: usually takes less than a minute.