Deepfake Detector logo
Content Authenticity Detection · Security Fraud

Deepfake Detector

Deepfake Detector checks whether a video, image or voice recording is authentic or AI-generated, returning a verdict, a confidence score and the signals behind it through a web app, a free Chrome extension or a REST API.

Active GDPR compliant Free plan Freemium API available 16+ Verified by Guidaio
Overview

What is Deepfake Detector?

Deepfake Detector is a synthetic-media detection service: it takes an audio file, a video or an image and tells you whether it looks authentic or machine-generated. Three purpose-built detectors — AI Video Detector, AI Image Detector and AI Voice Detector — sit behind a single account and a single API, and each returns the same shape of answer: a verdict of Authentic, Likely Synthetic or Inconclusive, a confidence score between 0 and 1, a TrustScore from 0 to 100, and the list of signals that produced it. What each model looks for differs. The video detector works frame by frame on clips of up to ten minutes, hunting lip-sync drift, generator signatures and per-frame artefacts, and marks the segments that fail. The image detector examines skin texture, colour distribution, geometric symmetry and cloned facial features, with announced coverage of MidJourney, DALL·E, Stable Diffusion, Flux, Firefly, Imagen, Recraft and Ideogram. The voice detector listens for unnatural pauses, pitch inconsistencies and sub-millisecond timing anomalies in formants, is built to survive added background noise, and claims coverage of ElevenLabs, Resemble, PlayHT and OpenAI; on the video side Sora, Runway, Pika and Kling are named. Three surfaces reach the same engine: a web application, a free Chrome extension built on Manifest V3 that requests only contextMenus and activeTab permissions, and a REST API exposing POST endpoints for voice, image and video plus a job-status call, with published latencies, a 99.9% service-level objective and SDKs announced for Python, Node, Go and Ruby. The company behind it, Deepfake Detector Inc., was founded in Montreal in 2023 after a member of the founding team received a voicemail cloning a relative's voice. It positions itself as detection-only and says it will never build generation tools. Four use cases are documented: KYC and identity, financial fraud and executive impersonation, newsroom verification, and platform trust and safety. One caveat belongs in any description: accuracy is never quantified. The site claims high accuracy throughout and cites an internal benchmark, but publishes no figure.

What it does

  • Determine whether a video, image or audio file is authentic or AI-generated
  • Return a confidence score and a TrustScore alongside every verdict
  • Flag the exact segments and the specific signals that drove the decision
  • Scan any media found on a web page straight from the right-click menu
  • Detect cloned speech in noisy or heavily compressed phone audio
  • Screen submissions automatically through a single REST API call
  • Export a detection report as PDF or CSV
Audience

When to use Deepfake Detector / When not to

A quick filter to help you decide if Deepfake Detector is the right fit.

When to use Deepfake Detector

  • Newsroom editors and fact-checkers who must verify user-generated video, images or audio before publishing
  • Finance and treasury teams exposed to voice-clone calls and executive impersonation ahead of a payment
  • KYC and identity-verification analysts screening face swaps and synthetic identities at onboarding
  • Trust and safety teams filtering synthetic profiles and media at scale through the API
  • Individuals who want to check a suspicious voice message or call attributed to a relative

When not to use Deepfake Detector

  • Anyone looking to create or edit synthetic media: the vendor builds detection only and states it never will build generation tools
  • Teams that need definitive proof of authenticity, since every result is a probabilistic verdict and the terms require out-of-band verification for high-stakes decisions
  • Organisations requiring a self-hosted or on-premise deployment, which is not documented anywhere on the site
  • Users who need a mobile app, as access is limited to the web application, the Chrome extension and the API
  • Free-tier users who need programmatic access, because the REST API only opens from the Starter plan onwards
Get started

How to use Deepfake Detector

A typical end-to-end flow, from setup to results.

  1. Try the free image demo on the home page: drop a JPG, PNG or WebP of up to 6 MB and read the score without creating an account
  2. Create an account to open the free tier, which covers 50 detections a month across image, audio and video
  3. Upload a file by drag-and-drop, or paste the URL of the media you want checked
  4. Read the verdict, the confidence score and the specific signals that drove it
  5. Export the report as PDF, or as CSV from the Starter plan onwards
  6. Install the Chrome extension and use the right-click menu to check any image, video or audio clip found on a page
  7. For programmatic use, generate an API key and send a single POST to the voice, image or video endpoint with an Authorization Bearer header
  8. Pass a media_url or a multipart upload, and set media_type, strict_mode or retain depending on what the case requires
  9. Register a callback_url webhook so results for files longer than sixty seconds are pushed back instead of polled
  10. Upgrade once the monthly quota or the two-minute media limit of the free tier becomes the constraint
Quick read

Pros & Cons

Pros

  • Three media types covered by a single integration, where most detectors handle only one
  • Permanent free plan with 50 detections a month and no credit card required
  • Files purged from primary storage within sixty seconds of the verdict by default
  • No training on submitted media without an explicit opt-in at upload time
  • Output oriented towards evidence: signals and flagged segments rather than a bare label
  • Public pricing with a side-by-side comparison table and no hidden enquiry on standard features
  • Unusually thorough legal documentation, including a published subprocessor list with regions

Cons

  • Accuracy is never quantified: the site repeats a claim of high accuracy but publishes no figure or benchmark
  • SOC 2 is described as in progress, while the privacy policy separately mentions an annual Type II assessment; the two statements do not agree
  • No API access on the free plan, which is also capped at two minutes of voice or video per detection
  • The site contradicts itself on the company's base, placing it in the United Kingdom in one privacy section and in Quebec everywhere else
  • The Article 27 EU representative is said to exist but is never named, and no customer-facing DPA is offered
  • No mobile application and no self-hosted option: access is limited to the web, the extension and the API
  • Client logos are displayed without a single case study, testimonial or named reference
Pricing

Pricing & Plans

A permanent free plan is available at no cost and covers 50 detections per month. The cheapest paid tier is Starter at USD 49.00 per month on monthly billing, or USD 39.00 per month when billed annually at USD 468.00 per year. Prices are exclusive of applicable taxes and payment is processed through Stripe.

Free — USD 0 per month
  • 50 detections per month
  • up to 2 minutes of voice and 2 minutes of video per detection
  • AI/Human verdict
  • TrustScore (0-100)
  • web application access
Business — USD 199 per month, or USD 159 per month billed annually (USD 1,908 per year)
  • 5
  • 000 detections per month
  • up to 10 minutes of voice and video
  • API access
  • priority email support
  • EU data residency
  • plus all Starter features
Enterprise — USD 599 per month, or USD 479 per month billed annually (USD 5,748 per year)
  • 20
  • 000 detections per month
  • up to 10 minutes of voice and video
  • API access
  • priority email support
  • plus all Business features
Plan 5
  • Chrome extension included at no cost on all four plans
  • an uptime SLA with service credits applies to Business and Enterprise only
Special offers — Annual billing saves up to 20%: USD 120 per year on Starter, USD 480 on Business and USD 1,440 on Enterprise · 50% off the Starter plan for verified newsrooms, fact-checking organisations and 501(c)(3) non-profits, on request to press@deepfakedetector.ai with credentials · Free Chrome extension, installable without an account · Permanent free plan with 50 detections per month and no credit card required · Free image detection demo on the home page, with no sign-up
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Deepfake Detector handles your data.

GDPR overview

GDPR coverage is explicit and detailed. The privacy policy, effective 25 May 2026 in version 1.0, states it was written to comply with the EU GDPR and the UK GDPR alongside Canada's PIPEDA, Quebec's Law 25 and several US state statutes. It publishes an Article 6(1) legal-basis table, names a Data Protection Officer reachable at privacy@deepfakedetector.ai, and lists the full set of data-subject rights with a thirty-day response window, extended to forty-five days for complex requests. International transfers rely on adequacy decisions, the 2021 Standard Contractual Clauses and the UK addendum, with TLS 1.3 and AES-256 as supplementary measures, and breaches are notified within seventy-two hours. An Article 27 representative is said to be appointed in the European Union, but is never named: contact details are only available on request.

Who owns the data?

Under the terms of service, you keep all rights, title and interest in the content you submit, and the vendor claims no ownership of it. You grant Deepfake Detector Inc. a worldwide, non-exclusive, royalty-free licence limited to hosting, storing, processing, analysing and displaying that content so it can return a verdict, secure the service and meet its legal obligations; the licence extends to improving detection models only where you have explicitly opted in. It ends when you delete the content or when the retention period expires, whichever comes first. Detection outputs are licensed back to you perpetually, including for publication in reporting, research and litigation, subject to attribution.

Reuse rights

Detection outputs come back to you under a worldwide, non-exclusive, perpetual licence for your own internal business purposes, and you may publish verdicts externally in news reporting, research and litigation provided you credit Deepfake Detector as the source and never present a result as an unconditional guarantee of authenticity. Reuse is otherwise bounded: outputs may be cached for at most twenty-four hours for the same input without written consent, and using them to train a competing model is prohibited. On the vendor's side, submitted media feeds model training only where you have explicitly opted in through a separate consent dialogue shown at upload time; otherwise only aggregated, de-identified metrics inform retraining, alongside logged detection metadata such as the file hash, the verdict, the confidence score and the model version.

Data retention & training

Retention summary
Submitted media is deleted from primary storage within sixty seconds of analysis unless you opt into retention; through the API, setting retain to true keeps the file for thirty days for audit. Detection metadata — verdict, confidence and file hash — is held for thirteen months, then aggregated and de-identified. Account information survives the account by ninety days after closure. Billing and tax records are kept for seven years to satisfy Canadian and US requirements, email correspondence for three years from the last interaction, raw server logs for thirty days and aggregated analytics for thirteen months. Backups roll off after thirty-five days. Deletion requests are honoured, generally within thirty days, except where the law requires retention or a legal claim must be defended.
Trains on customer data
Configurable
Training opt-out available
Yes
Subprocessors disclosed
Yes

Hosting summary

The privacy policy publishes its subprocessor list with a region for each. Vercel handles web hosting and edge delivery from the United States and the EU; Cloudflare provides DNS, CDN and DDoS protection over a global anycast network; Amazon Web Services runs object storage, compute and model inference in the EU (eu-west-1) and the United States; Stripe processes payments from the United States and Ireland; Resend delivers transactional email from the United States; Google Workspace and Google Analytics 4 operate across the EU and the United States; Sentry and Datadog handle error monitoring and performance telemetry in the United States. EU data residency is offered from the Business plan onwards. Data is encrypted with TLS 1.3 in transit and AES-256 at rest, in primary storage and backups alike, and transfers out of the UK or the EEA rely on adequacy decisions, the 2021 Standard Contractual Clauses or the UK addendum. Enterprise customers may request thirty days' notice of new subprocessors. The domain itself resolves to a United States address on Amazon infrastructure, flagged as anycast.

Hosting countries
🇺🇸 United States🇮🇪 Ireland
Hosting regions
EUUnited States
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Deepfake Detector.

  • Detection is probabilistic: the vendor explicitly acknowledges both false positives and false negatives, so a verdict is a signal rather than a finding
  • Accuracy varies with media type, generator model, file quality, compression artefacts and deliberate adversarial manipulation
  • Heavy compression can push a result to Inconclusive, and the temptation is then to read the absence of an answer as innocence
  • For financial, identity, legal, journalistic and law-enforcement decisions the terms require out-of-band verification and expert review, which is easy to skip once a tool starts to feel authoritative
  • Publishing a verdict externally obliges you to credit the source and forbids presenting it as an unconditional guarantee of authenticity
  • Setting retain to true in the API extends storage of the media from sixty seconds to thirty days, which changes the privacy profile of a scan
  • Liability is capped at the greater of twelve months of fees or CAD 100, and Free and Starter plans carry no SLA
Setup

Setup & Integrations

Technical difficulty

Minimal for everyday use. The web application needs no configuration — the site states that no training, tuning or integration is required — and the free image demo on the home page runs without an account at all. The Chrome extension installs in one click at 1.4 MB and works in any Chromium browser. The API is a single POST with a Bearer token, using the same authentication, response shape and error semantics for all three media types, with code samples in cURL, JavaScript, Python, Java and Go and SDKs announced for Python, Node, Go and Ruby.

Deployment

Web appAPIBrowser extensionChrome extension

Supported languages

English
Company

Behind Deepfake Detector

Company name
Deepfake Detector Inc.
Founded
18/05/2023
Country of origin
🇨🇦 Canada
Headquarters
410 rue Saint-Nicolas, Suite 236, Montreal, Quebec H2Y 2P5, Canada
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What can Deepfake Detector check?
Video, images and voice, all from the same account. You submit a clip, a photo or an audio file and receive a verdict — Authentic, Likely Synthetic or Inconclusive — with a confidence score, in seconds.
How accurate is the detection?
The vendor claims high accuracy across the major generators but publishes no figure. Detection is described as probabilistic rather than absolute, so every result is a confidence-scored verdict rather than a guarantee.
Is there a free version?
Yes. A free account includes 50 detections a month across video, image and audio, with no credit card required. It is capped at two minutes of voice or video per detection and carries no API access.
What happens to the files I upload?
Media is processed in memory and deleted from primary storage within sixty seconds of the verdict, unless you opt into retention. Through the API, setting retain to true keeps the file for thirty days for audit purposes.
Which file formats are accepted?
MP4, MOV and WEBM for video, JPG, PNG and WEBP for images, and MP3, WAV, OGG and M4A for audio. Size and length limits depend on the plan you are on.
Is my media used to train the models?
Not unless you explicitly opt in through a separate consent dialogue shown at upload time. Otherwise only aggregated, de-identified metrics feed retraining, and consent can be withdrawn at any time.
Is there a mobile app?
No. Access is through the web application, the free Chrome extension or the REST API. No iOS or Android application is offered.
Are any discounts available?
Annual billing saves up to 20%, and verified newsrooms, fact-checking organisations and 501(c)(3) non-profits qualify for 50% off the Starter plan by writing to press@deepfakedetector.ai with credentials.
Conclusion

Should you pick Deepfake Detector?

Deepfake Detector does one thing and makes no attempt to do more: it tells you whether a piece of media is real or machine-made. That focus is its main argument. Video, image and voice detection sit behind the same account, the same API and the same response format, which is rare in a field where most tools cover a single medium, and the answer comes back as evidence — a confidence score, a TrustScore and the specific signals involved — rather than a bare label. The supporting material is unusually solid for a product of this size. Pricing is published in full with a comparison table, the subprocessor list names each provider and its region, the retention schedule is itemised category by category, and the privacy policy maps its legal bases article by article. Files are purged within sixty seconds by default and nothing is used for training without an explicit opt-in. The gap sits exactly where it matters most. For a detector, accuracy is the only metric that counts, and it is never published: high accuracy is asserted throughout without a single figure. SOC 2 is described as in progress, the EU Article 27 representative is said to exist but is never named, and the site contradicts itself on where the company is based. The vendor's own terms instruct you to seek out-of-band verification and expert review for financial, identity, legal, journalistic and law-enforcement decisions. Read that instruction as the honest summary. Deepfake Detector is a fast, well-documented and inexpensive way to add a strong signal to a verification workflow, and a sensible first check for anyone facing a suspicious voice message. It is not, and does not claim to be, proof.