🔏 Voice Seal · launching

Seal a post as your real voice

Anyone can publish audio. Voice Seal lets you go one step further: when you publish a voice post, you can ask the network to measure the audio against your enrolled voice and co-sign the result. Listeners see a chip that says exactly what was measured — "sealed voice · matched enrolment" — no more, no less.

What it is

Opt-in, at the moment you publish

Sealing is a choice you make per post. When you publish a voice post and ask for a seal, the audio you're publishing is sent to our verification service — the same server-side system behind the live voice badge — which measures it against your enrolled voiceprint and scores the match on our side, with our model, under our threshold policy. If it matches, the service co-signs the result into the post.

STEP 1
🎙️

You record

A voice post, like any other

STEP 2
🔏

You opt in

"Seal this as my voice" — per post, never automatic

STEP 3
🧠

We measure

The audio is scored against your enrolment, on our servers

STEP 4
✍️

Two signatures

Yours + ours, sealed into the post

Why this exists: in a world of cheap voice cloning, "that clip of me is fake" and "this clip of me is real" are both unprovable by default. A sealed post gives your listeners a measured, co-signed statement to weigh — made at publish time, when you were there to make it.
The mechanism

Two signatures, two different claims

A seal is deliberately made of two separate signatures, because they answer two separate questions:

Your signature — who published this. Signed with your account key. It binds the post to your on-chain identity: this account, this audio, this moment.
Our signature — what we measured. Signed with the verification service's key. It attests one fact: this exact audio, scored against this account's enrolment, met our match policy at seal time. The score and the bar are ours — never self-reported by the publisher.

Anyone can check both signatures. And the "matched enrolment" verdict is ours to grant — it is computed on our servers and never accepted on the publisher's say-so. Our audit history taught us that rule the hard way: the signer is the adversary, so no field the publisher computes can ever drive the chip.

What listeners see

"Sealed voice · matched enrolment"

A sealed post carries a chip stating exactly what happened: the voice in this post matched the publisher's enrolled voiceprint when it was published. An unsealed post carries nothing — no warning, no penalty. Sealing is a claim you add, not a test you fail.

🔏 Sealed

Both signatures check out: the account signed it, and we measured a match against the enrolment it was sealed under.

✍️ Signed

The account's signature holds, but the measurement no longer stands — for example, the account has re-enrolled a new voiceprint since. The seal degrades honestly instead of pretending.

— Unsealed

Most posts. No claim was made, so no claim is shown. Speech never needs a seal to be published.

A seal is bound to the enrolment it was measured against. If you replace your voiceprint, old seals degrade to "signed" — a measurement can't outlive the thing it measured.

Honest limits · read this part

A seal attests a measurement, not certainty

We want this chip to be trusted, which means being exact about what it says:

It attests a measurement. "This audio matched this enrolment under our policy" is a statement about a model's score, not a metaphysical guarantee of authorship. Voice matching is strong evidence; it is not certainty, and we won't dress it up as certainty.
It inherits the limits of voice matching. Everything on the verification page about cloning, thresholds, and our log-only anti-spoof layer applies here too. We publish those limits; read them.
It says nothing about the content. A sealed post can still be wrong, misleading, or edited-by-the-speaker. The seal speaks to whose voice it is — never to whether what the voice says is true.
Status

Launching now

The measuring-and-signing service is built, live, and independently audited — including adversarial fuzzing of the envelope format with zero exemptions. The publish-flow UI is rolling out to the app. We ship the claim only when the whole path is as solid as the copy on this page.