Human Trust for the AI era.

Proof of Person in 30 seconds

Confirm that a real, live person was present in 30s with a single API call.

  • Runs in browser
  • No legal IDs
  • User-friendly
  • We handle media and biometrics

We're building a handshake for the internet.

We believe the world needs a way to distinguish real humans from bots, deepfakes, and AI-driven impersonation. That means asking three, and only three, simple questions:

  1. Are you a real person?
  2. Are you the right person?
  3. Are you a unique person?

Requiring legal identity everywhere is not the answer. Nor is building centralized biometric databases. We believe in asking only what the moment requires.

Handshake illustration

How it works

Step 1

You send them to us

Your app starts a handshake over OIDC or a simple API redirect, tied to the exact action you’re protecting.

Step 2

We run the check

The user reviews what’s being asked and consents, then completes a short guided session with their camera and microphone.

Step 3

You get the evidence

Your backend fetches a signed result and applies your own rules. Strong evidence or weak, the decision is yours.

Prefer to try it yourself? The live demo runs the real thing: nothing to install.
A tenant-scoped Sonavera check connects explicit consent, protected templates, limited signed evidence, and scheduled deletion.
Your tenant boundaryOne consented check
Signed evidenceNo raw media or embeddings, ever.

Privacy-first, secure by design.

Consent comes first: no consent, no check. Biometric data stays inside our system, never compared across customers. Your results carry evidence, not recordings. And everything expires: deletion is on the calendar from the moment the check starts.

No face-search, cross-customer matching, or ID

Sonavera does not permit search-by-face or share records across customers. A passport is not required merely to prove that a real person is present.

Confidence when it counts

Made for moments that matter.

Trigger a handshake only when the stakes are high: when your risk engine flags something, or the action itself needs stronger proof.

Account recovery

They lost the password and the phone. Before you hand the account back, compare the person asking with the person who enrolled.

Sensitive support actions

Add a live check before support changes an email address, resets multifactor authentication, or modifies recovery settings.

Privileged and agent actions

When an AI agent tries to do something dangerous, add a live check before your system approves it.

High-value payouts

Bind signed proof-of-person evidence to the transaction before anything moves.

Evidence, not verdicts

See what happened, not just a score.

Every result shows what was measured, what was missing, and what each signal contributed.

The 0–100 Evidence Index is a versioned summary of the evidence, not a probability, a percentage, or a verdict about the person. Missing measurements remain visible, and your system applies the policy.

Verification evidence · unsigned example
Identity match
30.50 / 40 pts
Face continuity
12.41 / 15 pts
Challenge integrity
20.50 / 25 pts
Media integrity
16.40 / 20 pts

Real structure, example numbers: rendered from the same generated fixture our tests use.

OIDC step-up

The pattern your identity stack already speaks: Authorization Code with PKCE and a signed ID token carrying the evidence.

API redirect

The simplest path. One call to start, a redirect, one call to fetch the result. Good for a pilot afternoon.

Signed webhooks

Get told when a check finishes instead of polling. Every delivery is HMAC-signed so your backend can verify it.

TypeScript SDK

Helpers for starting checks, validating results and tokens, verifying webhooks, and handling deletion requests.

Easy integration the way you work.

Sonavera isn’t your identity provider and doesn’t want to be. Keep your login, your user database, and your rules. We're there for moments that need a real person.

Add Sonavera when an action requires strong evidence that a real person is present. Integrate through OIDC, an API redirect, signed webhooks, or the TypeScript SDK.

The long-term vision

One handshake is the beginning.

Our long-term goal is a portable, user-controlled trust network: a way for people to demonstrate human presence, continuity, scoped uniqueness, or a trusted eligibility claim without exposing their full identity or joining a global biometric database.

We are building toward an internet where people can prove what matters.

For moments that need real trust

Try the live demo, or show us the high-risk flow you are trying to protect.