VAARHAFT
Technology

Source Verification

Source Verification is VAARHAFT's proactive capture-time protection that secures digital images at the point of origin, preventing presentation attacks, GPS spoofing, virtual cameras, and injection attacks before a fake ever enters your pipeline.

Proprietary Technology2 Patents Pending, built in-house, not licensed.
Comprehensive DefenseStops fraud right at the point of origin. The system reliably detects and blocks complex threat vectors, including GPS-spoofing, presentation attacks, injection attacks, and the use of virtual cameras.
Ultra-Robust Trust Certificate beyond C2PASurvives both digital and physical transformations. The certificate remains fully intact through cropping, screenshots, messenger compression, and even printing. Seamlessly linkable to the blockchain for absolute immutability.
Chain of Trust

From shutter to seal: the chain of trust.

01

01

Capture

Photo taken through SafeCam SDK with all device sensors validated in real-time

02

02

Protect

GPS, camera authenticity, liveness, and injection checks executed on-device

03

03

Certify

We issue an ultra-robust certificate of authenticity. Unlike fragile metadata, a content hash of the visual data is permanently embedded directly into the pixels as a visible QR code (patent pending).

04

04

Verify

Signed hash + metadata anchored. Image is tamper-proof and verifiable

Threat Vectors

The Attacks Source Verification Prevents

Traditional image forensics only detects fakes after they enter your system. By then, the damage (fraudulent claims, forged evidence, manipulated inspections) is already in motion.

Source Verification eliminates these attack vectors at the point of origin, before a single fraudulent pixel reaches your pipeline.

Vector 01

GPS Spoofing

Attackers use GPS spoofing apps to fake their location, submitting photos that appear to be taken at a claimed site while sitting anywhere in the world. Common in insurance claims, field inspections, and delivery verification.

Vector 02

Virtual Camera

Software like OBS Virtual Camera or ManyCam feeds pre-recorded or AI-generated images into applications that expect a live camera feed. Bypasses naive camera-check implementations entirely.

Vector 03

Video Injection

Pre-recorded video streams are injected directly into the camera pipeline at the OS or driver level, bypassing the physical camera sensor completely. Undetectable by application-level checks.

Vector 04

Camera Injection

Hardware-level attacks using HDMI capture cards or modified camera drivers to inject synthetic imagery into the device's camera subsystem. The most sophisticated form of capture-time fraud.

Vector 05

Picture of a Picture

Submitting a photo taken of a screen, printed image, or secondary display instead of the real-world object. Bypasses naive camera checks by using a real device, but pointing it at a fake. Detected through optical consistency analysis and screen artifact recognition.

Protection Modules

Secure at Capture. Five Modules. Zero Trust.

Each module addresses a specific attack vector at the moment of image capture. Proprietary on-device algorithms for hardware validation, cryptographic watermarking for post-capture integrity. All working in concert to establish an unbroken chain of trust.

Module 01Real-Time

GPS Validation

Detects GPS spoofing in real time by cross-referencing satellite signals with device sensors, cell tower triangulation, and Wi-Fi positioning. Prevents fake location injection at the hardware level.

Module 02Proprietary Model

Device & Camera Authenticity

Detects compromised devices, including jailbroken iOS and rooted Android devices, that could be used to bypass capture-time protections. Distinguishes real physical cameras from virtual camera software, emulators, and screen-capture tools. Validates the image originates from a genuine hardware sensor on an unmodified device.

Module 03Proprietary Model

Injection Detection

Detects video injection and camera injection attacks where pre-recorded or AI-generated footage is fed into the camera pipeline. Blocks synthetic feeds before capture.

Module 04On-Device

Liveness Verification

Validates device sensor data (accelerometer, gyroscope, barometer, and ambient light) to confirm a real physical device is present at the stated time and location.

Module 05Cryptographic

Patented Physical Certification beyond C2PA

Embeds a visible QR-code-based certificate directly into the image at the moment of capture. Encodes location, timestamp, and device identity, with optional blockchain anchoring for an immutable, tamper-proof chain of custody from shutter to verification.

Deep Technology

Capture-Time Protection & Tamper-Proof Certification

Unlike reactive detection that analyzes images after the fact, Source Verification operates at the point of capture. On-device algorithms validate hardware integrity, then a robust visual certificate based on a content hash seals the image, creating an unbroken chain of trust from shutter press to final verification.

  • On-Device Hardware Validation

    All sensor checks run directly on the device before the image is saved. No round-trip to a server, no latency window for attackers to exploit.

  • Content Hash Certification

    Going beyond standard cryptography: each captured image generates a unique content hash. This hash binds visual data, location, timestamp, and device identity into a single, unforgeable package. The data can be optionally anchored to the blockchain, replacing fragile metadata with absolute proof.

  • Ultra-Robust Certificate of Authenticity

    The content hash is permanently embedded directly into the image's pixels as a visible QR code. This robust certificate survives JPEG compression down to quality 10, WhatsApp forwarding, screenshots, printing, and cropping.

  • Instant Decentralized Verification

    Verification doesn't rely on hidden metadata. By simply scanning the surviving QR code, users or endpoints can instantly retrieve the certified original image and its immutable chain of custody directly from the blockchain or a trusted database.

Capture & Verification PipelineLIVE
Capture Verification
Secured
GPS VALIDREAL CAMERANO INJECTIONLIVENESS OKCaptureProtectedWATERMARK ENGINESHA-256a3f8...c7d2TIMESTAMP2025-01-15T...DEVICEiPhone 15 ProWatermarkAppliedVERIFIEDCERTIFICATECHAININTEGRITY OKSealedTamper-ProofSECURE TRANSFERTLS 1.3PAYLOAD SIGNEDINTEGRITY VERIFIEDTRANSMITTEDSecureTransferCAPTURE → VERIFY → WATERMARK → SEALED IMAGE → SECURE TRANSFER
Checks: 4/4Watermark: AppliedIntegrity: SealedTransfer: Securedv2.1.0

A dual-stage pipeline: on-device capture protection validates hardware authenticity in real time. Instead of fragile metadata, the engine embeds a robust content hash as a visible QR-code certificate. Final verification simply extracts this visual hash to retrieve the unforgeable original. Proactive security, not reactive detection.

Performance

Proactive Protection, Measurable Results.

Source Verification does not detect fakes after the fact. It prevents them from being created in the first place. Every image that passes through our capture pipeline carries a robust visual certificate of authenticity based on its unique content hash.

Our patent-pending QR-based certification is designed for the real world: it goes beyond any cryptographic approach (such as C2PA), surviving messenger compression, social media sharing, screenshots, and intense print-scan cycles without losing its verifiable link to the original.

Zero-TrustCapture VerificationBlocks GPS Spoofing, Virtual Cams, Video Injections and presentation attacks
PersistentCertificate SurvivalSurvives Printing, Cropping, Screenshots and Messenger
JPEG 10%Min. Image QualityQR-Certificate Still Fully Extractable
<5sVerification LatencyEnd-to-End certificate verification
Infrastructure

From Device to Verification.

iOS + Android

Mobile SDK

Native iOS and Android SDK. Drop-in integration into existing camera flows, no custom camera UI required. Full documentation and sample apps provided.

REST API + BLOCKCHAIN

Cloud Verification

Server-side REST API for QR-certificate extraction and original image retrieval. Seamless scan-to-blockchain verification delivering deterministic results in under 5 seconds via auto-scaling infrastructure.

SHA-256 + QR

Visual Certification

Each image is instantly certified with a unique visual QR code at capture. We bind the content hash, GPS coordinates, timestamp, and hardware fingerprint into a single, unforgeable visible token.

Universal

Cross-Platform

Supports iOS, Android, and browser-based capture. Consistent QR-based certification and robust verification across all platforms and device generations.

TLS 1.3 + Signed Payload

Secure Transfer

All media and metadata are transmitted over TLS 1.3 with signed payloads. Transfer integrity is verified server-side, ensuring the chain of trust holds from capture through delivery, with no window for in-transit manipulation.

Why VAARHAFT

Proactive Protection vs. Reactive Detection

01

Secure Before It's Faked

Unlike forensic detection that analyzes images after the fact, Source Verification prevents fraud at the point of capture. By the time a fake reaches a reactive system, the damage is already underway.

02

Unbroken Chain of Trust

From shutter press to final verification, every image carries a robust visual QR certificate proving exactly when, where, and how it was captured. No gaps, no assumptions, zero-trust by default.

03

Hardware-Level Verification

We validate at the hardware sensor level, not at the application layer. GPS spoofing apps, virtual cameras, and injection attacks are detected before the image is even saved.

04

Survives the Real World

Our visual QR certificates survive WhatsApp compression, screenshots, cropping, and intense print-scan cycles. While standard metadata is stripped on the first share, our embedded content hash persists through every transformation.

05

Privacy by Design

Capture protection runs entirely on-device. While verification occurs in the cloud, our API is strictly stateless and zero-retention, all data is instantly wiped after the check. Permanent blockchain anchoring is an explicit, user-controlled option, ensuring full data sovereignty at all times.

06

Powers SafeCam

Source Verification is the core technology behind VAARHAFT SafeCam, our verified image capture product used by insurance companies, field service providers, and compliance teams worldwide.

In Production

Powering SafeCam

Source Verification is the foundational technology behind VAARHAFT SafeCam, providing verified image capture for field operations, claims documentation, and compliance workflows. No spoofing, no injections, no manipulations.

  • Native Mobile SDK for drop-in integration in days, not weeks
  • Cryptographic watermark embedded at capture, verified via REST API
  • GPS spoofing, virtual camera, and injection attacks blocked on-device
  • Offline-capable capture with deferred cloud verification
  • Trust score API for seamless integration into existing workflows
01

Capture

Photo taken with SafeCam SDK, all sensors validated

02

Verify

GPS, camera, liveness checks executed on-device

03

Certify

Ultra-robust certificate of authenticity: a content hash of the visual data is permanently embedded into the pixels as a visible QR code (patent pending)

04

Seal

Signed hash + metadata anchored to verification server

Frequently asked questions

Instead of analyzing images after the fact, Source Verification secures them at the moment they are taken. On-device checks validate GPS, camera hardware, and device integrity, then a robust visual certificate seals the image. Fraud is prevented before a fake ever enters your pipeline.

C2PA stores provenance in metadata, which is stripped by messengers, screenshots, and printing. Our patent-pending certificate embeds a content hash directly into the image pixels as a visible QR code. It survives JPEG compression down to quality 10, WhatsApp forwarding, cropping, screenshots, and even print-scan cycles.

GPS spoofing, virtual cameras such as OBS or ManyCam, video and camera injection at OS or driver level, presentation attacks (photos of screens or prints), and capture on compromised jailbroken or rooted devices. All checks run on-device before the image is saved.

Yes. All capture-time checks and the certification run entirely on-device with no network dependency. Images are sealed offline and can be verified later, as soon as connectivity is available.

By scanning the embedded QR certificate via the REST API. The certificate resolves to the certified original with its location, timestamp, and device identity, optionally anchored to the blockchain for an immutable chain of custody. Verification takes under 5 seconds.

The native iOS and Android SDK drops into existing camera flows in days, not weeks. No custom camera UI is required, and full documentation with sample apps is provided. Browser-based capture is supported as well.

VAARHAFT Trust Suite

One Technology Stack. Five Trust Layers.

Explore the full technology stack

Every VAARHAFT product is built on the same proprietary technology base: five specialized trust layers covering images, documents, audio, contextual information, and capture-time source verification. Combined, they form the technological foundation of the VAARHAFT Trust Suite.

In production, these layers power the VAARHAFT Trust Suite products:Fraud ScannerSafeCamSafeMic
Get Started

Secure your image pipeline at the source

Book a demo and see how Source Verification prevents capture-time fraud in your workflows. We'll walk you through SDK integration, watermark verification, and deployment options.