How we protect evidence, who processes it, and where we are on the path to independent certification.
Every user must use an authenticator app (TOTP). Organisations can add SAML single sign-on, SCIM provisioning, idle timeouts and an IP allow-list.
Access is role-based (Viewer, Auditor, Analyst, Supervisor, Org Admin) and enforced by database access rules on every request, not only in the interface. Each organisation's data is isolated from every other organisation.
Every important action is written to an append-only, hash-chained audit log that can be exported or streamed to a SIEM.
All traffic uses TLS 1.2 or higher. Databases and file storage are encrypted at rest (AES-256). Provider keys and signing keys are kept as server-side secrets and never reach the browser.
Forensic reports and deletion certificates are signed with Ed25519; sealed content uses C2PA Content Credentials.
Each original file is fingerprinted (SHA-256) on intake and kept in private storage. Files are sent only to the detection providers your organisation has switched on.
Organisations choose a data region and retention period per media type. Originals past retention are deleted nightly, except evidence in open cases or under legal hold, and a signed deletion certificate is issued.
Face match is off by default, searches only collections the organisation owns, and needs a recorded reason for every search.
| Provider | Purpose | Processing region |
|---|---|---|
| AI or Not | Image, video and audio deepfake detection | United States |
| Hive | Image, video and audio deepfake detection | United States |
| Reality Defender | Image, video and audio deepfake detection | United States |
| Sightengine | Image and video AI-generation detection | European Union (France) |
| Resemble AI | Synthetic voice detection | United States |
| AssemblyAI | Transcription and audio intelligence | United States |
| AWS Rekognition | Face detection and organisation-scoped face match (opt-in) | Region configured for the account |
| GPTZero | AI-written text detection (when enabled) | United States |
| Lovable AI (Google Gemini models) | Visual review, summaries, text checks, Ask assistant | United States |
| Lovable Cloud | Hosting, database, authentication, file storage | Platform region |
Regions are as published by each provider. Each organisation only uses the providers it has enabled.
Detection scores are probabilities, not proof. sealverity.ai combines several independent detectors, shows when they disagree, and never makes a final decision: a trained analyst does, with a recorded reason.
Accuracy is measured on labelled test sets and published as aggregates. Risk scores support analyst judgement and are not determinations about any person.
Report a vulnerability or security concern to security@lavisho.com. We acknowledge reports within two business days.