GetReal Security, a deepfake detection company, has made continuous identity verification generally available in GetReal Protect, adding session-long checks to a platform built for deepfake and impersonation detection across voice and video.

The Austin company says the release is available to organizations that rely on mission-critical digital workflows.

Session-long identity verification mechanics

The update targets what happens after a person joins a call. GetReal says the product checks whether a participant is synthetic, whether that participant matches an enrolled identity, whether the match holds through the session and whether an identity appears in GetReal’s threat-intelligence data as a known threat actor or high-risk user.

If a face no longer matches an enrolled identity, audio shifts to synthetic speech or face-swap manipulation is detected, the platform alerts security teams, extending the kind of deepfake detection tools now being built for business use. 

Matt Moynahan, CEO of GetReal Security, tied the launch to the difficulty of protecting identity when voice and video can be manipulated in real time. “Our digital lives are made up of sound waves and pixels, and until now we’ve been technologically limited in how we can protect a person’s likeness,” Moynahan said.

Applying zero-trust principles to video

GetReal positions this continuous verification architecture as a shift toward zero-trust session controls rather than conventional endpoint content moderation.

NIST’s zero-trust architecture says trust should not be granted implicitly, access to enterprise resources should be evaluated per session and authentication and authorization should be dynamic, with continual reassessment during communication.

GetReal applies that logic to video and voice calls, where the endpoint may be authenticated but the person on screen can still be in question.

Rising financial losses tied to AI impersonation

The launch comes as fraud data shows rising losses tied to deepfakes and AI-enabled scams. Surfshark’s analysis found deepfake-related losses had reached $1.56 billion by 2025, with more than $1 billion occurring in 2025 alone and $130 million across 2019-2023.

The FBI’s 2025 IC3 report separately logged 22,364 AI-related complaints and $893.3 million in adjusted losses, including more than $30 million in reported business email compromise losses involving AI.

The threat has already reached executive workflows, including earlier deepfake scams targeting senior executives. In 2024, Arup confirmed that fake voices and images were used in a fraud involving its Hong Kong office. Hong Kong police described 15 transfers to five local bank accounts totaling about HK$200 million after an employee joined a video conference with people who appeared to be senior company officers.

IAM integrations and stack compatibility

GetReal Protect connects to Microsoft Teams, Cisco Webex, Zoom and voice systems, and the company lists more than 40 native integrations with IAM tools including Okta, Microsoft Entra and CyberArk.

Those integrations position GetReal Protect as an add-on to existing collaboration and identity systems, rather than a standalone identity stack.

Biometric consent and compliance constraints

On privacy and consent, GetReal says verification does not run unless participants consent and enrollment is complete.

The company also says enrolled users own their data, can revoke consent or request deletion and that GetReal acts as a custodian for enterprise customers. The release cites SOC 2 Type II certification and compliance with GDPR, CCPA/CPRA and Illinois’ BIPA.

That consent structure will shape enterprise testing. Illinois law requires private entities that collect or obtain biometric identifiers or biometric information to give written notice, explain the purpose and retention period and obtain a written release before collection.

For security, legal and procurement teams, the test is whether live identity alerts can feed existing IAM, logging and incident-response workflows without creating unmanaged biometric data risk.

Personalized Feed
Personalized Feed