
Sensity AI
Sensity AI is a forensic-grade deepfake detector for video, image and audio. It combines pixel, voice, metadata and file-structure analysis to produce court-ready reports for law enforcement, courts, intelligence agencies, banks, insurers and newsrooms, in cloud or on-premise deployments.
What is Sensity AI?
Sensity AI is a detection engine for synthetic media. It takes a video, an image or an audio file — uploaded or pointed at by URL, with PDF also accepted as a media type on the API — and returns a verdict on whether the content was manipulated or generated by artificial intelligence. The company, founded in Amsterdam late in 2018 by Giorgio Patrini and Francesco Cavalli, presents itself as the world's first deepfake detection company; Patrini is described as possibly the first person to have trained a deepfake detector, in March 2018. The distinguishing choice is architectural. Rather than a single classifier, Sensity runs four named layers: Pixel Analysis for visual artefacts, Voice Analysis for formants, pitch contours, spectral characteristics and speech coherence, File Forensic Analysis for metadata, structural coherence, generation history and integrity anomalies, and a Forensic Report that assembles the result. Cross-modal inconsistencies and behavioural cues feed the same verdict. The threat taxonomy it covers includes face swaps, lip sync, reenactment and morphing, AI avatars, GAN-generated faces, text-to-image and text-to-video output, synthetic speech and voice cloning. What comes out is deliberately more than a yes or no. Each analysis returns a binary verdict, a confidence score, a manipulation type, pixel-level heatmaps and frame-by-frame bounding boxes. Segmentation-based explainability isolates the objects and regions carrying the decision, and generator attribution names the model behind a synthetic image. That emphasis on showing the reasoning is what makes the output usable in adversarial settings: reports are built with an audit trail, structured metadata and visual evidence, and are generated automatically in more than thirty languages. The published use cases follow the same audience: government and judicial work, disinformation, image-based sexual abuse, CSAM investigation, fraud and digital evidence authentication. An in-house threat intelligence unit intercepts malicious content targeting individuals, organisations and states. Claimed figures on the homepage are 98% accuracy on public datasets, over 900,000 incidents identified in 2025, 35 minutes saved per case on manual review, and deployment in more than 30 countries. Sensity also claims a listing in the NIST Computer Forensics Tools and Techniques Catalog.
What it does
- Check whether a video, an image or an audio file has been manipulated or generated by AI
- Produce an explainable forensic report designed to hold up in court, with audit trail and chain of custody
- Triage large volumes of digital evidence automatically before a human analyst looks at it
- Detect voice cloning and identity spoofing in KYC flows and call centres
- Authenticate contested content in a disinformation investigation
- Attribute AI-generated media to the generator model that produced it
- Embed detection into an existing pipeline through the REST API, an SDK, or an offline on-premise deployment
When to use Sensity AI / When not to
A quick filter to help you decide if Sensity AI is the right fit.
When to use Sensity AI
- Digital investigation units and forensic laboratories that must show how a verdict was reached, not just state it
- Law enforcement bodies and judicial authorities, including prosecutors and judges, who need evidence that survives cross-examination
- Intelligence and national security agencies, including teams working offline or under strict data-sovereignty constraints, thanks to the fully on-premise options
- Banks and insurers running KYC, identity verification, call-centre and fraud-prevention checks against voice cloning and identity spoofing
- Newsrooms and fact-checkers authenticating footage in investigations into synthetic disinformation
When not to use Sensity AI
- Individuals or small teams looking for a self-service product with a published price: no rate card exists anywhere and every route ends on a sales conversation
- Mobile-first users, since there is no iOS or Android application
- Anyone who needs to create, edit or restore media: Sensity only detects, it never generates
- Minors, as both the terms and the privacy policy restrict use to people aged 18 or over
- Buyers expecting a guaranteed answer: the claimed 98% accuracy is measured on public datasets, the terms supply the service “AS IS” without warranty of any kind, and the publisher itself acknowledges that detectors weaken against generators absent from their training data
How to use Sensity AI
A typical end-to-end flow, from setup to results.
- Start a 7-day trial or register an account on the Sensity platform; there is no installation on the cloud route
- Create a team and assign a role to each member
- Drop files into the interface, or paste public URLs — video, image and audio are all accepted
- Launch the analysis, described by the publisher as a two-click operation that can run on several items at once
- Read the verdict, the confidence score and the manipulation type, with heatmaps and bounding boxes to see which regions drove the decision
- Export the forensic evidence package, with its audit trail, metadata and chain of custody, in the language you need
- Track platform accounts and API token usage together in the single analytics dashboard
- For the API route, create a token through /auth/tokens, then submit through /v2/submissions/upload/ and confirm with /v2/submissions/{id}/complete/
- Choose the tasks to run per submission — face manipulation, AI-generated content detection, voice analysis, file analysis, with an optional transcription — and collect the “suspicious” or “valid” result with its plain-language summary
- Subscribe to the submission.completed and submission.failed webhooks, or deploy on-premise on an NVIDIA GPU server, a workstation or a USB dongle for disconnected environments
Pros & Cons
Pros
- A multi-layer approach rather than a single classifier, cross-checking pixels, file structure, metadata and audio
- Deep explainability — heatmaps, segmentation, generator attribution — built for settings where a verdict will be contested
- A complete on-premise option, down to a USB dongle for field teams in disconnected environments
- A documented, versioned REST API with webhooks, tokens and exports, alongside an SDK and web app
- Automatically generated reports in more than thirty languages, useful for cross-border judicial work
- A European publisher under Dutch law, with its subprocessors publicly disclosed
- Genuine seniority on the subject since late 2018, an in-house threat intelligence unit, and — by the company's own account — tripled revenue and reached profitability
Cons
- No public pricing whatsoever: no pricing page, no rate card, no amount anywhere on the site or inside the application
- No contact page either — reaching the company means opening a JavaScript modal form with no URL of its own
- No named security certification: neither ISO 27001 nor SOC 2 is claimed, only “internationally recognized security frameworks”
- Whether customer data is used to train models is never addressed, in any document
- A very open international transfer clause allowing data to be stored “anywhere in the world”, which sits awkwardly with the data-sovereignty argument the company makes elsewhere
- Terms and privacy policy both dated January 2024, more than two years before this review
- Mandatory individual arbitration with a waiver of jury trial and class action, and a 98% accuracy claim resting on public datasets rather than a published third-party protocol
Pricing & Plans
No price is published. Sensity operates no pricing page, lists no rate card, and no monetary amount appears anywhere on the website or in the platform's application code; the sitemap contains no pricing entry. A free 7-day trial is offered and can be started by self-service sign-up, and the application exposes subscription and credit mechanics — a default monthly period, a remaining-credit counter, a subscription expiry — without attaching any figure to them. Beyond the trial, every commercial path leads to a “Talk to sales” or “Talk to an expert” form, and the three on-premise configurations are quoted on request. No permanent free plan is announced, and the site does not state that there is none.
- the site advertises no tiers
- and every commercial route ends on a sales form
- Free 7-day trial
- started by self-service sign-up on the platform
- Cloud platform account
- with subscription and credit mechanics visible in the application but no monetary value attached to them
- On-premise deployment in three configurations — NVIDIA GPU server for high volumes
- workstation for fast local analysis
- USB dongle for field teams — all quoted on request
Data, GDPR & hosting
A consolidated view of how Sensity AI handles your data.
GDPR overview
The substance is there, the label is not. Sensity B.V. is established in Amsterdam and falls directly under EU law. Its privacy policy carries a dedicated section on lawful bases for the European Economic Area — consent and explicit consent, legal obligation, contract performance — lists data subject rights (access and copy, portability, objection, restriction, rectification, withdrawal of consent, erasure), and states that people in the EEA or the UK may complain to a supervisory authority. It is governed by Dutch law, names a Data Protection Officer (co-founder Francesco Cavalli, reachable via support@sensity.ai), includes a Data Processing Agreement section, and runs cookie consent through a dedicated page. No Article 27 representative is named, and none is required of an EU-established controller. Worth flagging: the acronym GDPR appears in no editorial text on the site — only in a homepage badge with an empty alt attribute and a WordPress plugin name.
Who owns the data?
The terms are unambiguous about the vendor's side: Sensity B.V. and its licensors exclusively own all right, title and interest in the Services, including the associated intellectual property. “Content” is defined broadly as the text, graphics, images, audio, video and works made available through the Services, and users receive only a limited, non-exclusive, non-transferable licence, with no right to sub-license, to access and view it for personal, non-commercial purposes. What the terms never say is that customers keep ownership of the files they upload; that question is simply left unaddressed. Feedback sent to support@sensity.ai is treated differently and explicitly: Sensity obtains a worldwide, perpetual, irrevocable, royalty-free and sub-licensable licence over it.
Reuse rights
Users are not granted any right to reuse Sensity's own content: the licence is read-only, personal and non-commercial, and the only counterpart asked of the user is an agreement to input their data, with everything else deferred to the privacy policy. That policy is far more detailed. Declared collection covers full name, email, phone, address, short selfie videos with sound, identity documents and the data they contain, and — with explicit consent — the biometric data extracted from those selfies and document photos. Automatic collection adds sign-up date, IP and MAC addresses, cookie identifiers, browser, operating system, device, mobile carrier, inferred location, ISP, pages visited, links clicked, and usage frequency and duration. Stated purposes run from contract performance, account management, multi-factor authentication texts, payment processing and support through to legitimate interests such as direct marketing, research and development, network security and fraud prevention, plus quality control, audits and legal obligations. De-identified, aggregated data may be created and used broadly. Data may be shared with the four disclosed subprocessors — HubSpot, GitHub, Xero and Google Cloud Platform — with third parties at the user's own instruction (biometric data included), on legal request, and in a merger, acquisition or asset sale. One subject is never raised anywhere on the site: whether customer data is used to train models, and whether it can be excluded from such training.
Data retention & training
Hosting summary
The privacy policy publishes a subprocessor table with a location column: HubSpot in the United States, GitHub in the United States, Xero in Australia, and Google Cloud Platform in the United States for cloud hosting and data sent through the API. That column describes where each subprocessor sits, not where customer data is guaranteed to live. The transfer clause itself is deliberately open: all information processed may be transferred, processed and stored anywhere in the world, including but not limited to the Netherlands or other countries. Sensity undertakes to protect that information in line with applicable law and to supply further detail on request, but no EU data residency commitment and no guaranteed hosting region is published. Declared security consists of physical, administrative and technical safeguards, encryption at rest and in transit, and best-practice controls said to comply with internationally recognised security frameworks — with no certification named. The major counterpoint is the on-premise route: a GPU server, a workstation or a USB dongle places hosting entirely with the customer, including fully offline, which is the answer the company puts forward for banks and agencies.
Things to keep in mind
Risks and trade-offs to weigh before adopting Sensity AI.
- The terms and privacy policy are dated January 2024 and were read on 31 August 2026: after more than two years they may no longer describe the service you are buying
- Mandatory individual arbitration under Dutch law, with a waiver of jury trial and class action; refusal is possible only in writing within 30 days
- The acronym GDPR is written nowhere in the site's editorial text — only a badge with an empty alt attribute and a WordPress plugin name carry it, so compliance has to be read from the substance of the privacy policy
- No security certification is named anywhere; “internationally recognized security frameworks” commits to no specific standard, and the data transfer clause permits storage “anywhere in the world” despite the sovereignty argument made elsewhere
- Biometric data — selfie videos and identity documents — is collected on the basis of explicit consent, which places a real burden on how you gather and record that consent
- The complete silence on model training from customer data is a blind spot: nothing is promised, and nothing is ruled out
- Marketing figures cannot be verified outside the site: 98% accuracy on undisclosed public datasets, 900,000+ incidents in 2025, 30+ countries, 35 minutes saved per case; likewise, the “Featured on” press logos and “Supported by” badges are neither customers nor integrations
Setup & Integrations
Technical difficulty
It depends entirely on the route. The cloud route is easy: self-service sign-up, a 7-day trial, no installation, drag and drop, and an analysis the publisher describes as two clicks; team and role management is built in. The API route is a developer job — create a token, submit by upload or URL, configure webhooks — and assumes back-end skills. The on-premise route is the demanding one: an NVIDIA GPU server, a workstation, or a dongle-activated install requires an infrastructure team and hardware sizing. Microsoft Teams is the one named integration.
Deployment
Integrations
Supported languages
Behind Sensity AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What kinds of media can Sensity AI analyse?
Which types of manipulation does it detect?
Is there an API?
Can it be installed on our own infrastructure?
How much does it cost, and is there a free trial?
How accurate is the detection?
Are the reports usable in court?
How long is biometric data kept?
Who are the subprocessors, and who publishes the tool?
Is there a mobile app, and in which languages is the tool available?
Should you pick Sensity AI?
Sensity AI is a narrow, seriously built tool rather than a general-purpose one, and it should be judged on that basis. Its differentiator is not the verdict but the reasoning behind it: heatmaps, segmentation, generator attribution, file forensics and an audit trail exist because the people it sells to — investigators, prosecutors, intelligence analysts, fraud teams — have to defend a conclusion against someone arguing the opposite. Very few detection products are designed for that moment. The publisher's own footing is solid enough to matter: a Dutch company identified down to its KVK and VAT numbers, active on the subject since late 2018, funded by a USD 3.2 million total raise plus EUR 4.9 million from the European Innovation Council, and profitable according to its own statements. The on-premise route, from GPU server to USB dongle, is a genuine answer for organisations that cannot send evidence to a third-party cloud. The reservations are equally concrete. Pricing is entirely opaque: beyond a 7-day trial, there is no figure to evaluate and no way to size a budget without talking to sales. The terms and privacy policy are dated January 2024, more than two years old at review, and they leave two significant subjects untouched — whether customers own the files they upload, and whether their data is used to train models. No security certification is named, and the international transfer clause is drafted very widely. The 98% accuracy claim rests on public datasets, not on an independent protocol. This is a tool for organisations, not individuals: worth the detour if you need explainable, exportable evidence and can negotiate a contract, less so if you want a quick, priced answer off the shelf.
- Choosing a selection results in a full page refresh.
- Opens in a new window.