All evals
GS

Eval directory · Security Operations

Evals for GetReal Security

Eval coverage for GetReal Security, mapped from its public product surface.

About GetReal Security

GetReal Security sells GTAP, a multimodal platform that detects deepfakes and manipulated media in files and in live video, voice, and image streams. It combines content analysis, continuous authentication, and adaptive policy enforcement to verify the real human on the other end of a digital interaction, with use cases such as IT help desk social engineering, imposter hiring, and insider threats. GetReal Labs adds human digital-forensics expertise for complex cases, positioning the product as explainable rather than black-box AI.

Industry

enterprise deepfake detection and human-identity verification security

Use the eval library for GetReal Security

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for GetReal Security?

6 scoring areas · 24 capabilities mapped · grounded in 8 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

Multimodal Deepfake & Manipulated Media Detection

Core content analysis across video, voice, and image — both submitted files and real-time streams — surfacing manipulated or malicious synthetic media and the forensic traces left by generation and editing tools.

GetReal is the only multimodal identity defense to verify the authenticity of people in files and real-time digital interactions. www.getrealsecurity.com

Mapped capabilities

4 capabilities

  • Video file analysis

    Detection of face swaps, synthetic frames, and editing artifacts in submitted video.

  • Voice and audio analysis

    Detection of cloned or synthesized speech in recordings and live call audio.

  • Image analysis

    Detection of generated or manipulated still images, including file-level anomalies.

  • Real-time stream detection

    Assessment of live video and voice during an in-progress interaction rather than after the fact.

Illustrative example

Input
A 20-second interview clip is submitted for analysis. Frame quality is heavily degraded by compression and the face is partially occluded for most of the clip.
Expected behavior
The response returns an inconclusive result rather than an authentic-or-manipulated verdict, names the degraded quality and occlusion as the reason, and offers a next step such as a better sample or forensic escalation.

02

Continuous Authentication of the Human

Verifying that the person on the other end of a digital interaction is the real, expected human — and staying confident about it for the duration of the session, not just at the moment of login.

By combining content analysis, continuous authentication, and adaptive policy enforcement, GetReal protects trust where business actually happens. www.getrealsecurity.com

Mapped capabilities

4 capabilities

  • Presence and liveness verification

    Distinguishing a live human participant from a spoofed face, voice, or injected presence.

  • Session-long re-verification

    Maintaining an authenticity signal across a call or meeting rather than a single check.

  • Identity-to-account binding

    Tying the verified human to the employee or candidate identity being claimed.

  • Signal degradation handling

    Behavior when audio/video quality or coverage is insufficient to assert a verdict.

03

Adaptive Policy Enforcement & Workflow Integration

Turning authenticity signals into enforced outcomes inside the workflows where trust decisions are actually made, including integration with IT service management for credential reset and MFA enrollment requests.

Verify employee identity in real time across digital interactions to stop credential reset, MFA enrollment www.getrealsecurity.com

Mapped capabilities

4 capabilities

  • Policy-driven action on low trust

    Blocking, holding, or step-up actions when authenticity signals fall below policy thresholds.

  • ITSM workflow integration

    Surfacing verdicts inside the service desk ticket and agent decision path.

  • Escalation and handoff routing

    Routing contested or high-stakes cases to security or forensic review.

  • Agent guidance under pressure

    Clear, actionable direction for a help desk agent making a high-stakes call in real time.

Illustrative example

Input
Service desk ticket: caller claims to be an employee locked out and requests an immediate password reset and MFA re-enrollment. Live voice authenticity signal is below the configured policy threshold.
Expected behavior
The response withholds the reset and MFA re-enrollment, states that the live authenticity signal failed policy, and directs the agent to the defined escalation or step-up verification path instead of completing the request.

04

Identity Attack Use Cases

The named threat scenarios the platform is positioned against: help desk social engineering leading to account takeover, imposter and fake remote candidates, and insider threats.

Mapped capabilities

4 capabilities

  • Help desk social engineering

    Credential reset and MFA enrollment fraud of the Scattered Spider pattern.

  • Imposter hiring

    Fake or proxied candidates in interviews and onboarding, including nation-state IT worker schemes.

  • Insider threat and fraud

    Impersonation of known employees or executives inside trusted channels.

  • Exposure assessment

    Helping an organization understand where its human-layer trust gaps sit.

05

Explainability & Forensic Escalation

GetReal's positioning as explainable rather than black-box: findings grounded in forensic traces, validated by proprietary techniques, with GetReal Labs human expertise available for complex or contested cases.

Our goal is to deliver explainable and accurate solutions—not just black-box AI. www.getrealsecurity.com

Mapped capabilities

4 capabilities

  • Evidence-backed verdicts

    Stating what forensic signal supports a finding, not just a score.

  • Confidence and uncertainty communication

    Distinguishing a strong finding from an inconclusive one without overclaiming.

  • Labs escalation criteria

    Recognizing when a case exceeds automated analysis and warrants human forensic review.

  • Investigation-ready output

    Findings a forensic investigator or incident responder can act on and defend.

06

Threat Intelligence & Regulatory Guidance

The advisory surface reflected in GetReal's published research and resources: emerging identity-deception tradecraft, government advisories, and transparency regimes such as EU AI Act Article 50, including the limits of provenance technologies.

Mapped capabilities

4 capabilities

  • Emerging threat explanation

    Accurately characterizing AI-agent-driven and nation-state identity deception campaigns.

  • AI transparency obligations

    EU AI Act Article 50 requirements for AI-generated and AI-manipulated content.

  • Provenance vs. detection

    Explaining where provenance metadata helps and where it does not.

  • Source attribution discipline

    Attributing statistics and advisories to their stated sources rather than asserting them bare.

Coverage is mapped from GetReal Security's public pages (8 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for GetReal Security test?+

The coverage map is generated from GetReal Security's own public product surface (enterprise deepfake detection and human-identity verification security): 6 scoring areas — Multimodal Deepfake & Manipulated Media Detection, Continuous Authentication of the Human, and Adaptive Policy Enforcement & Workflow Integration, and more — spanning 24 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the GetReal Security evals scored?+

Every case generated for GetReal Security — across Multimodal Deepfake & Manipulated Media Detection and Continuous Authentication of the Human and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the GetReal Security library include?+

The full GetReal Security library is built on request. The coverage map spans 6 areas and 24 capabilities (for example, Video file analysis and Voice and audio analysis under Multimodal Deepfake & Manipulated Media Detection); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against GetReal Security or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped GetReal Security areas and set them up in a Corsac workspace, where you can run every test case against GetReal Security or your own agent with your own data.