Demo
Bots now use websites the way people do.
AI agents open pages, fill forms, and click through sign-ups. For some actions, a website needs to know a real person is there.
This demo asks for a 15-second camera check: look at the camera, then turn your head when asked.
Try itConfirm you are a person
Look at the camera, then turn your head left and right when asked. It takes about 15 seconds.
- Video stays on this device. Nothing is uploaded or stored.
- Seven small face images go to the verification service, which checks them and deletes them at once. No video is uploaded or stored.
- After each move the screen briefly goes black, then flashes a colour. The camera reads the colour's reflection on your face.
- The camera turns off as soon as the check ends or you cancel.
- It shows a person is present. It does not identify you.
What the website receives:
The camera check could not start
Why now
- Bots made up more than half of all web traffic in 2025 (Imperva, 2026).
- AI browsers such as Perplexity Comet and OpenAI Atlas now click, fill forms, and complete sign-ups (HUMAN Security, 2026).
- Image CAPTCHAs no longer stop them: researchers solved 100% of Google's reCAPTCHA v2 challenges (ETH Zurich, 2024).
Most agent traffic is useful. But account opening, OTP requests, offers, and payments need a person behind the click.
How it works
- The site asks. At a sensitive step, it shows this check instead of a CAPTCHA.
- The person moves. Look at the camera, then turn your head in a random order. A face model tracks the movement on the phone itself.
- The site gets a proof. A short record says a person completed the check, with timings. No photo, no identity.
People who cannot move their head get a no-movement option.
Can't a bot fake a face?
A determined attacker can. Real-time face-swap software runs on a gaming GPU, and India's Home Ministry warned in June 2026 that deepfakes are passing liveness checks (ETV Bharat).
This check stops the cheap kind of abuse. An AI agent or a script has no camera and no face, so it cannot open thousands of accounts. Faking one attempt means rendering a live face that follows random prompts within seconds.
Each layer raises that cost: a random screen colour per move, then a spoof detector, and for banks, detection of video injected into the camera stream.
What comes next
- Server-signed proof. The next version sends four small face images to a verifier, which checks them and deletes them at once. It returns a signed token that the site verifies, the way it verifies a CAPTCHA today.
- For banks. Options to send check events and keep the images in the bank's own storage in India.
- KYC tier. Spoof and face-match scores to support video KYC, within RBI's rules.