Home · AI Security & Identity · Proof of Human

A cloned voice can't pass your checks.
Let's make sure of it.

Cloning a voice takes a few seconds of audio. Faking a video call is not far behind. The attacks aimed at small firms are simple: “It's the boss, pay this invoice today.” “It's your supplier, our bank details have changed.” We design and test the verification steps that stop them: for your team, your customers and your AI voice agents.

THE VERIFICATION LADDERPay a new payee or over the limitCall-back on a known number + second approverChange supplier bank detailsCall-back to the number on file, never the one in the emailReset a password or accessIdentity check + confirm with their managerMove or disclose a bookingOne-time code to the registered mobileGeneral enquiryJust answer itUrgency is not proof. The bigger the action, the higher the rung.

Urgency is not proof

🎙️

The “boss” rings in a hurry

An urgent payment, a cloned voice, and a plausible reason not to talk later.

🏦

Supplier bank details change

By email or phone, with the right logo and a familiar name.

🔑

Password reset by phone

Someone rings the office as a colleague and gets back in.

🧑‍💼

New starter, new instructions

A fake HR or finance message that staff follow because it looks normal.

📹

Video call with the “director”

Deepfake video is now good enough for a short call.

🤖

Your own voice agent

If it can book, move or disclose, it needs to verify callers too.

Checks your team can follow on a busy day

  • ✓A verification ladder: which actions need which checks, from a quick question to two-person approval
  • ✓Call-back and code-word procedures for payments, bank detail changes and resets
  • ✓Your AI voice agent configured to verify callers before it discloses or changes anything
  • ✓Staff training in plain language: what the attacks sound like, what to do, and permission to say no to the boss
  • ✓Supplier and customer notices, so the people you deal with know your process too
  • ✓Simulated attack tests, with your agreement, and a short report on how your team did

This is identity verification for people, not systems. The principle has protected bank payments for decades: urgency is not proof, and no single voice is enough for a big action.

Who can be fooled, and how

The requests that cost money, and the check for each.

RequestArrives asCheck
Urgent paymentCall from the “boss”Call-back + 2nd approver
New bank detailsEmail on supplier letterheadCall the number on file
Reset my passwordCall to the officeID check + manager confirms
Move my bookingCall to your voice agentOne-time code
Send me the fileMessage from a colleagueConfirm on a second channel

Each check is small. Together they stop the attack.

Map, design, embed, test

For a team of up to 30, design and training take about two weeks. Testing follows a few weeks later, once the new habits have settled.

1

Map

Which actions could cost you money or data, and who can trigger them today.

2

Design

A verification ladder, scaled to risk, that your team can follow on a busy day.

3

Embed

Procedures written, voice agent configured, staff trained, suppliers told.

4

Test

Controlled simulated attempts by phone, email and voice-agent call, then adjustments.

What this looks like in practice

A building contractor's office manager took a call from the “managing director” asking for a same-day payment to a new subcontractor. Under the new ladder, any new payee needed a call-back to the MD's known number and a second approver. The call-back went to the real MD, who was on site and knew nothing about it.

Illustrative example, drawn from typical findings. Not a named client.

“Access control is the part most AI suppliers wave at. It's the part we came from.”

Michael LewisFounder, Eutaxis · 13 years in identity & access management

The things everyone asks first

Are deepfakes really a risk for a firm our size?

Yes. The tools are cheap and the attacks target people, not systems, so size doesn't protect you. Smaller firms are often targeted precisely because one person can approve a payment.

Won't extra checks annoy the boss?

A little, once. Owners who've been through an attack say the alternative is far worse. The ladder is light for everyday actions and firm for the few that move money or data. The owner sets it, so nobody is “disobeying”.

Does this apply to our AI voice agent?

Yes, and it's often the weakest link: an agent that confirms bookings or discloses details to anyone with a name. We configure it to verify first. If we built it, this comes as an upgrade.

What's a code word, and does it work?

A word or phrase agreed in person and used to confirm urgent requests. It works when it's kept off email and changed now and then. It's one rung of the ladder, not the whole thing.

Will you really try to fool our staff?

Only with your written agreement, within agreed limits, and never to embarrass anyone. The results improve the process. They are not used to blame people.

How much does it cost?

A fixed price after a free discovery call, based on your team size and the channels involved. Testing can be a one-off or repeated each year.

The other AI Security & Identity services

See how the five fit together →

Would your team pay an invoice because “you” asked?

Find out safely, before someone tests it for real.