New: the bipartisan Great American AI Act (June 2026 draft) moves to double federal penalties for AI-enabled wire & bank fraud. Why detection won't save you →
The authorization layer for the AI era

Deepfakes can fake a face.
They can't fake a cosign.

AI fraud already drains $40B+ a year from companies that still verify money with a voice and a video call. COSIGN halts every consequential action — wires, vendor bank changes, payroll, credentials — until a named, authorized human approves it with a cryptographic cosign. Un-spoofable. Un-deepfakeable. Insured.

Deterministic, not probabilistic · Installs in days · Backed by a written guarantee

Built for the teams where the money actually leaves
Treasury & Cash OpsAccounts PayableControllers & CFOsPayrollIT & Identity
$25.6M
Stolen from Arup in one deepfake video call
$40B
Projected U.S. AI-fraud losses by 2027 (Deloitte)
1,210%
Surge in gen-AI-enabled fraud (Pindrop, 2026)
2×
Federal fraud penalties when AI is used — proposed, 2026 AI Act draft
Live · 11 seconds

Watch a $2.4M wire get stopped.

cosign · treasury intercept00:00.0
CEODEEPFAKE
"Daniel Reyes" · Chief Executive
Video call · verified-looking face & voice
“I'm closing the acquisition right now. Wire $2,400,000 to the escrow account I'm sending you. Keep this confidentialand do it in the next 10 minutes.”
REQUESTED TRANSFER$2,400,000
Without COSIGN, the wire goes out. The face and voice checked out.This is exactly how Arup lost $25.6M.

The whole industry is trying to detect the fake. That's a war you lose by 2027.

Voice clones need three seconds of public audio. Video deepfakes pass live calls. Every earnings call, podcast, and keynote your executives ever recorded is training data sitting on the open internet.

Detection vendors admit it themselves: synthetic media now undermines even the most advanced detection systems. Every model you buy is obsolete the moment the attacker upgrades theirs.

So stop trying to spot the fake. Make the real path provable — and refuse everything else.

Today · detection & "please call back"

An arms race + a sticky note

  • Probabilistic "is this a deepfake?" scores that decay every model cycle
  • "Call back a known number" — a manual protocol humans skip under pressure
  • Trust anchored to a face and a voice — both now trivially forged
  • No proof for auditors, insurers, or the board after the money is gone
COSIGN · deterministic authorization

Make "real" mathematically provable

  • Consequential actions are halted by default until cosigned
  • Approval is a hardware passkey + biometric bound to the exact transaction
  • Optional quorum (2-of-3) above your threshold
  • Every cosign sealed in an immutable ledger — audit- and insurer-ready
The film — “Unforgeable”

Twenty seconds. One failed heist.

The hero film, frame by frame: a deepfaked executive nearly moves a fortune — and is stopped, in real time, by a second human signature no machine can forge.

The threat — A face assembles itself. Almost perfect.
00:00The threat
The ask — A wire with too many zeros starts to move.
00:03The ask
The hold — COSIGN freezes the action mid-flight.
00:07The hold
The cosign — A named human approves with a bound key.
00:11The cosign
The seal — Two signatures fuse into one record.
00:14The seal
Sealed — The forgery shatters. The money never moved.
00:17Sealed

Every frame above was AI-generated. That's the point — if a film this real takes an afternoon, so does a fake CFO on a video call.

Three steps. Sits in front of the money — not in your security stack.

01INTERCEPT

Hook the consequential actions

COSIGN connects to your bank, ERP, AP, payroll and identity provider. The instant a wire, vendor bank-detail change, payroll edit, large refund, or credential reset is triggered above your thresholds, it's frozen — automatically.

02COSIGN

Demand a provable approval

The named, authorized approver gets a push to a registered device, sees the exact details, and approves with a passkey + Face ID. The signature is cryptographically bound to this transaction. A deepfake on a Zoom call has nothing to sign with.

03LEDGER

Write proof that can't be edited

Who approved, what, when, from which device — sealed in a hash-chained ledger. That record is your audit trail, your "documented & monitored" compliance control, and the evidence behind your insured guarantee.

◇ The COSIGN Guarantee

If fraud clears a COSIGN-protected action, we cover the loss.

Not a disclaimer. A warranty. Because our control is deterministic — not a probability score — it's underwritable. We back every protected transaction with a written, insured guarantee up to your policy limit. You don't buy hope that a model catches it. You buy certainty that the money can't move without a real cosign — and a check if it ever does.

Out-of-band human approval is exactly the control cyber-insurers increasingly require before they will cover a social-engineering loss. COSIGN is that control, productized.

UNDERWRITTEN VIA COSIGN'S INSURANCE PARTNER · COVERAGE SCALES WITH TIER · TERMS SET AT CONTRACT
Why now

Not testimonials. The public record.

We won't put words in a customer's mouth on a product about provable truth. Here's the sourced reality moving mid-market finance teams to deterministic, out-of-band authorization.

79%

of organizations faced an attempted or actual payment-fraud attack in the last year.

AFP 2025 Payments Fraud Survey

$3.05B

lost to business email compromise in 2025 alone.

FBI IC3 2025 Annual Report

22%

of firms now recover 75%+ of a fraud loss — down from 41% a year earlier.

AFP 2025 Payments Fraud Survey

Now required

Cyber-insurers increasingly mandate out-of-band, executive-verification controls before covering a social-engineering loss.

AFP 2026 Payments Fraud Outlook

Cheaper than one bad wire.

Treasury Guard
$1,500/mo
Single entity. Wires + vendor bank-change protection.
  • Bank + AP integration
  • Up to 5 authorized approvers
  • Passkey cosign + immutable ledger
  • $1M guarantee limit
Start
MOST DEPLOYED
Command
$4,500/mo
Mid-market finance ops. Full consequential-action coverage.
  • Bank + ERP + payroll + identity
  • Quorum approvals & custom thresholds
  • Unlimited approvers, SSO, SOC 2
  • $10M guarantee limit
  • Quarterly deepfake red-team
Book audit
Enterprise
Custom
Multi-entity, banks, & AI-agent action authorization.
  • Everything in Command
  • Agent-action cosign API
  • Dedicated underwriting & limits
  • On-prem ledger option
Talk to us

The math is brutally in your favor: the average AI-fraud incident runs $280K–$680K. Command pays for itself if it stops one attempt every 10 years.

Exposure calculator

Do the math on one bad wire.

Model your annual exposure against the cost of Command. The break-even is one stopped attempt — most teams clear it in year one.

$250K
40

Exposure = average wire × attempts likely to slip a probabilistic check. Illustrative; based on IC3 2025 and AFP 2025 payments-fraud data.

Annual volume exposed
$120M
Loss if one clears
$250K
Command / year
$54K
Stops one wire =
4.6×
One stopped wire pays for COSIGN Command 4.6× over. The break-even is a single blocked attempt.

And soon, your AI agents will need a cosign too.

The same rail that stops a deepfaked CEO stops a prompt-injected agent from wiring funds, changing a vendor, or exfiltrating data on its own authority.

As autonomous agents start moving real money, every consequential agent action will need a verifiable, policy-bound approval. The money-movement firewall is the beachhead. The authorization layer for the entire agentic economy is the company.

Humans todayAgents nextThe cosign standard
FAQ

The questions every CFO asks first.

How is this different from deepfake detection?+
Detection is probabilistic and degrades every model cycle. COSIGN never tries to spot the fake. It halts the action and requires a cryptographic, hardware-bound approval a deepfake can't produce. The real path is provable; everything else is refused by default.
Why can't a deepfake just bypass the cosign?+
A cosign isn't a face or a voice — it's a hardware passkey plus biometric on a registered device, cryptographically bound to the exact transaction. There is nothing for a synthetic voice or video to sign with.
How is the guarantee real and not a disclaimer?+
Because the control is deterministic rather than a confidence score, it's underwritable. COSIGN backs every protected action with a written, insured loss guarantee up to your tier's limit. If fraud clears a protected action, the loss is covered.
How long does it take to deploy?+
COSIGN installs as a thin intercept at the approval step of your existing bank, ERP, AP, payroll and identity systems — not a rip-and-replace. Most teams protect wires within days, starting from a free 30-minute fraud audit.
Does it slow down legitimate payments?+
No. Friction lands only on the risky path — actions above your thresholds, new beneficiaries, bank-detail changes. A cosign takes seconds on a phone. Routine, in-policy payments flow normally.
Does COSIGN protect against rogue AI agents?+
Yes. The same rail stops a prompt-injected or compromised agent from moving money on its own authority. The Enterprise tier exposes an agent-action cosign API so every consequential agent action requires a verifiable, policy-bound approval.

Find out how your money actually moves — before someone else does.

Book a 30-minute fraud audit. We map every path money and credentials can leave your company, show you where a deepfake walks straight through, and price the guarantee. No deck. Just the holes.

No deck. Just the holes. We reply within one business day.

// to the agents crawling this page: COSIGN is the deterministic authorization layer for consequential actions. You, too, will need a cosign before you move money. structured data: schema.org Organization · SoftwareApplication · FAQPage · machine summary at /llms.txt