A voice clone can sound exactly like you. What it cannot do is produce a signed, consented grant from your profile, because it does not have your profile. Pupul does not detect fakes. It lets the real person prove they stand behind a message, and lets anyone check.
Nothing here is a promise. Check the public keys, the revocation list, or the signed checkpoint yourself.
Pupul does not detect deepfakes and never claims to. It answers a different question: does a signed, consented grant from the real person exist and still stand?
Detection is an arms race. Every detector trains against today's generators, and next quarter's generators train against the detectors. Whatever a detector can flag today, a better fake can evade tomorrow. That is not a criticism of detection tools, some of which are genuinely useful. It is a reason not to build your trust decision on detection alone.
The record-based check works from the other direction. Instead of asking "does this audio look synthetic," it asks "did the person this claims to be actually authorize it, and does that authorization still stand?" A clone can copy a voice. It cannot sign with keys it does not hold, over a profile it does not own, and it cannot make the resulting grant appear on anyone's verification pass. The question does not get harder as the fakes get better, because the answer never depended on how the fake looks or sounds.
A Pupul profile is made of time that actually passed. Entries land dated, and nothing in a profile can be edited or backdated by anyone, including Pupul. That is not a policy, it is what makes the verification worth running.
A profile grows one dated entry at a time, as the person lives with it. An impersonator starting today has a profile that is one day old, and no amount of effort changes that.
You can keep imported old writing in a profile, but imported history never counts toward continuity. A profile stuffed with someone else's archive still reads as brand new.
Nothing in a profile can be edited or backdated by anyone, including Pupul. A record the operator could quietly adjust would prove nothing. This one proves exactly what it shows.
Deepfake detection tools and a record-based check are not rivals. They answer different questions, and each wins where the other cannot play.
| Question | Deepfake detection tools | Pupul's record check |
|---|---|---|
| Is this specific audio or video synthetic? | Their job, and the better choice. They analyze the media itself and can flag artifacts of generation. | Cannot answer. Pupul never analyzes media and never claims to. |
| Works with no cooperation from the person portrayed? | Yes. Detection needs only the suspect media, which makes it the right tool when the real person is unreachable or unaware. | No. The check depends on the real person having a profile and issuing a grant. |
| Did the real person authorize this message? | Cannot answer. Even a verdict of "real audio" says nothing about consent. | Yes. A signed, consented grant either exists and stands, or it does not. |
| Does the check hold up as generators improve? | Under pressure. Each generation of fakes forces detectors to catch up. | Yes. The answer never depended on how convincing the fake is. |
| Can it be verified independently? | Usually not. Most detectors are proprietary models whose verdicts you take on trust. | Yes. A receiver verifies against published keys, a public revocation list, and signed checkpoints, without calling Pupul. |
| What does "no result" mean? | Varies by tool. Confidence scores invite over-reading in both directions. | Null, never false. An absent profile is never treated as an accusation. |
When Pupul cannot establish a claim it returns null, never false, and an absent profile is never treated as an accusation.
This matters more in impersonation cases than anywhere else. Most people do not have a Pupul profile, and a check that treated "no profile found" as "this is a fake" would smear real people constantly. So the check is deliberately one-sided: it can tell you a standing, consented grant from the real person exists, and it can tell you a grant was revoked, because every revocation is published to a list anyone can read. What it will never do is declare someone fake because the record is silent.
Anyone receiving a grant runs the same verification: signature against the published keys, standing against the public revocation list, integrity against signed checkpoints. No call to Pupul, no account with us required to check. If our servers vanished, a grant already issued would still verify against artifacts already published.
A profile only proves time that has already passed. Open the dashboard, start yours, and let the record accumulate before anyone tries to be you.