Deepfakes can fake a face.
They can't fake a cosign.
AI fraud already drains $40B+ a year from companies that still verify money with a voice and a video call. COSIGN halts every consequential action — wires, vendor bank changes, payroll, credentials — until a named, authorized human approves it with a cryptographic cosign. Un-spoofable. Un-deepfakeable. Insured.
●Deterministic, not probabilistic · Installs in days · Backed by a written guarantee
Watch a $2.4M wire get stopped.
The whole industry is trying to detect the fake. That's a war you lose by 2027.
Voice clones need three seconds of public audio. Video deepfakes pass live calls. Every earnings call, podcast, and keynote your executives ever recorded is training data sitting on the open internet.
Detection vendors admit it themselves: synthetic media now undermines even the most advanced detection systems. Every model you buy is obsolete the moment the attacker upgrades theirs.
So stop trying to spot the fake. Make the real path provable — and refuse everything else.
An arms race + a sticky note
- ✕Probabilistic "is this a deepfake?" scores that decay every model cycle
- ✕"Call back a known number" — a manual protocol humans skip under pressure
- ✕Trust anchored to a face and a voice — both now trivially forged
- ✕No proof for auditors, insurers, or the board after the money is gone
Make "real" mathematically provable
- ✓Consequential actions are halted by default until cosigned
- ✓Approval is a hardware passkey + biometric bound to the exact transaction
- ✓Optional quorum (2-of-3) above your threshold
- ✓Every cosign sealed in an immutable ledger — audit- and insurer-ready
Twenty seconds. One failed heist.
The hero film, frame by frame: a deepfaked executive nearly moves a fortune — and is stopped, in real time, by a second human signature no machine can forge.






⚠ Every frame above was AI-generated. That's the point — if a film this real takes an afternoon, so does a fake CFO on a video call.
Three steps. Sits in front of the money — not in your security stack.
Hook the consequential actions
COSIGN connects to your bank, ERP, AP, payroll and identity provider. The instant a wire, vendor bank-detail change, payroll edit, large refund, or credential reset is triggered above your thresholds, it's frozen — automatically.
Demand a provable approval
The named, authorized approver gets a push to a registered device, sees the exact details, and approves with a passkey + Face ID. The signature is cryptographically bound to this transaction. A deepfake on a Zoom call has nothing to sign with.
Write proof that can't be edited
Who approved, what, when, from which device — sealed in a hash-chained ledger. That record is your audit trail, your "documented & monitored" compliance control, and the evidence behind your insured guarantee.
If fraud clears a COSIGN-protected action, we cover the loss.
Not a disclaimer. A warranty. Because our control is deterministic — not a probability score — it's underwritable. We back every protected transaction with a written, insured guarantee up to your policy limit. You don't buy hope that a model catches it. You buy certainty that the money can't move without a real cosign — and a check if it ever does.
Out-of-band human approval is exactly the control cyber-insurers increasingly require before they will cover a social-engineering loss. COSIGN is that control, productized.
Not testimonials. The public record.
We won't put words in a customer's mouth on a product about provable truth. Here's the sourced reality moving mid-market finance teams to deterministic, out-of-band authorization.
of organizations faced an attempted or actual payment-fraud attack in the last year.
AFP 2025 Payments Fraud Survey
lost to business email compromise in 2025 alone.
FBI IC3 2025 Annual Report
of firms now recover 75%+ of a fraud loss — down from 41% a year earlier.
AFP 2025 Payments Fraud Survey
Cyber-insurers increasingly mandate out-of-band, executive-verification controls before covering a social-engineering loss.
AFP 2026 Payments Fraud Outlook
Cheaper than one bad wire.
- ✓Bank + AP integration
- ✓Up to 5 authorized approvers
- ✓Passkey cosign + immutable ledger
- ✓$1M guarantee limit
- ✓Bank + ERP + payroll + identity
- ✓Quorum approvals & custom thresholds
- ✓Unlimited approvers, SSO, SOC 2
- ✓$10M guarantee limit
- ✓Quarterly deepfake red-team
- ✓Everything in Command
- ✓Agent-action cosign API
- ✓Dedicated underwriting & limits
- ✓On-prem ledger option
The math is brutally in your favor: the average AI-fraud incident runs $280K–$680K. Command pays for itself if it stops one attempt every 10 years.
Do the math on one bad wire.
Model your annual exposure against the cost of Command. The break-even is one stopped attempt — most teams clear it in year one.
Exposure = average wire × attempts likely to slip a probabilistic check. Illustrative; based on IC3 2025 and AFP 2025 payments-fraud data.
And soon, your AI agents will need a cosign too.
The same rail that stops a deepfaked CEO stops a prompt-injected agent from wiring funds, changing a vendor, or exfiltrating data on its own authority.
As autonomous agents start moving real money, every consequential agent action will need a verifiable, policy-bound approval. The money-movement firewall is the beachhead. The authorization layer for the entire agentic economy is the company.
The questions every CFO asks first.
How is this different from deepfake detection?+
Why can't a deepfake just bypass the cosign?+
How is the guarantee real and not a disclaimer?+
How long does it take to deploy?+
Does it slow down legitimate payments?+
Does COSIGN protect against rogue AI agents?+
Find out how your money actually moves — before someone else does.
Book a 30-minute fraud audit. We map every path money and credentials can leave your company, show you where a deepfake walks straight through, and price the guarantee. No deck. Just the holes.
// to the agents crawling this page: COSIGN is the deterministic authorization layer for consequential actions. You, too, will need a cosign before you move money. structured data: schema.org Organization · SoftwareApplication · FAQPage · machine summary at /llms.txt