Manav.id
Regulated ยท 17 min read

The notary is watching a video. That is the whole control.

Remote online notarization took the oldest identity check in commerce, a human looking at another human, and moved it onto a video call. The video is no longer evidence that anybody was there. The industry's answer has been to add deepfake detection to the stream, which asks the notary to win a contest the tools themselves admit they often lose.

A Thursday afternoon closing

It is 4:47pm on a Thursday and a commissioned notary in Florida has one more session before the day ends. A refinance. The signer joins the call on time, which is already a good sign, because the ones who join late are the ones who have not read anything.

The platform runs its checks in order. The signer answers five knowledge-based authentication questions drawn from public and commercial records: a street they lived on in 2011, a lender they once held a car loan with, the county where a relative owns property. Four correct, one skipped, which is normal, because the questions are drawn from data that is often stale. The signer holds a driver licence up to the camera. The platform's credential analysis inspects the image for the security features it expects and returns a pass.

Then the human part. The notary looks at the face on screen, looks at the face on the licence, and forms the judgment that the office of notary public has always come down to: that is the same person, and they seem to know what they are signing. The seal goes on. The session recording is retained. The document goes to the recorder in the morning.

Nothing in that sequence was skipped, and nothing in it would have caught a signer who was not real. The knowledge questions were answerable from a breach corpus. The licence image was a rendering. The face was a live puppet driven by someone in another country who had never met the homeowner whose equity was about to move.

This is the uncomfortable position the notary profession now occupies. Not because notaries are careless, but because the one thing the profession was built on, a trained person forming a judgment about who is in front of them, has quietly stopped being a control.

Can a deepfake pass remote online notarization? Yes. Knowledge-based questions are answerable from breached records, identity document images can be synthesised, and a live video feed can be replaced at the capture layer so the notary sees a face that no camera ever recorded. The durable control is not a better detector on the stream. It is a signature from a device the signer enrolled before the transaction began, which an impostor cannot produce no matter how good the video is.

What does a notary actually do?

Most people, including many who have been notarised a dozen times, could not say what the notary was for. They think it is a rubber stamp that makes a document official. It is not. The notarial act is a specific, narrow set of duties, and understanding them precisely is the only way to see what has broken.

A notary public performs four functions. First, they identify the signer, traditionally by personal knowledge or by inspecting satisfactory evidence of identity such as a government-issued credential. Second, they confirm the signer is acting willingly, which is the anti-duress function that matters enormously in elder financial abuse and in coerced conveyances. Third, they confirm the signer appears aware of what they are doing, which is the capacity function. Fourth, they create and retain a record of the act in a journal.

Every one of those is a judgment made by a human being who is physically present with another human being. The notary is, in the language of computer science, an oracle: a trusted external party that answers a question the system cannot answer for itself. The system asks "is this the right person, and did they mean it", and the notary answers yes.

The legal weight of a notarised document flows entirely from confidence in that oracle. A recorded deed carries a presumption of validity, title insurers price policies on it, and lenders release funds against it, all because a commissioned officer attested that a specific person appeared and signed. Take away the reliability of the attestation and the paper is just paper with a seal on it.

The word that carries all the weight is "appeared"

Notarial certificates use a term of art: the signer personally appeared before the notary. For four hundred years that phrase meant exactly what it sounds like. Two people, one room, one set of eyes doing the work. Whatever else was uncertain, the physical presence of a body in front of another body was not in dispute.

Remote online notarization redefined appearance to include audio-visual presence over a communication link. That was a reasonable and necessary redefinition, and it is not the mistake. The mistake, which nobody made deliberately, is that everyone continued to treat the notary's perception as the control after the channel carrying that perception became something an attacker could author.

How does remote online notarization verify identity?

RON was authorised in most US states between roughly 2020 and 2023, with a large acceleration when in-person closings became difficult, and it is now embedded in mortgage, title and estate practice. It is genuinely useful. It lets a service member sign a closing from overseas, lets an adult child handle a parent's affairs from another state, and removes a category of scheduling friction that used to cost real money. Nothing in this post argues for going back, and any proposal that requires abandoning remote notarization is not a serious proposal.

A typical RON session layers three identity controls, and it is worth being precise about what each one actually establishes.

Knowledge-based authentication

The signer answers multiple-choice questions generated from public and commercial data: prior addresses, former lenders, vehicles, relatives. Many state rules specify a minimum number of questions, a pass threshold, and a limit on retries. The theory is that only the real person knows these facts.

The theory was reasonable in 2005. It is not reasonable now, because the underlying data has been breached repeatedly and is purchasable in bulk. KBA does not prove knowledge. It proves access to a dataset, and the dataset is not scarce.

Credential analysis

The platform inspects an image of a government-issued identity document for the features it expects: fonts, microprinting patterns, the machine-readable zone, security elements that show under certain conditions. A pass means the image is consistent with a genuine document.

Note the careful wording. It means the image is consistent with a genuine document. Credential analysis is a check on a picture, and the pipeline that produces the picture is on the signer's side of the connection. We wrote about how that pipeline is attacked in the camera is no longer evidence, and everything in that piece applies here without modification.

The audio-visual session

The notary sees and hears the signer, compares the face to the credential, asks questions, and forms a judgment. The session is recorded and retained, often for years, as evidence.

This is the control that everyone believes in, including notaries, regulators and title insurers, and it is the one that has degraded fastest.

Why has the video stopped being evidence?

There are two different attacks people conflate, and the difference decides whether detection can work at all.

A presentation attack holds something up to a real camera. A printed photograph, a mask, a phone screen playing a video. The camera faithfully captures whatever is in front of it, and the artefacts of the fake are physically present in the captured frames: screen moire, flat lighting on a mask, missing depth. Liveness detection was designed for exactly this, and against presentation attacks it works reasonably well.

An injection attack never goes near a camera. The attacker installs a virtual camera driver, or runs the session in an emulator, or uses a modified client, and feeds synthetic frames directly into the video pipeline. The application requests a camera stream and receives one. There is no glass, no lens, no room. Every liveness cue the system knows to look for is present in the frames, because the attacker generated frames containing those cues.

Here is the analogy that makes it stick. A presentation attack is someone holding a photograph up to a security camera, and you can often tell, because a photograph in a room looks like a photograph in a room. An injection attack is someone unplugging the security camera's cable and connecting their own video player to it. The monitor still shows a picture. The picture is still perfectly lit and perfectly convincing. It simply has no relationship to the room.

Identity verification vendors have reported injection attempts at very large volumes, in the millions annually across their client bases, with sharp spikes following regulatory events that pushed more users through identity checks. Treat those counts as vendor telemetry with the caveat that always applies: a vendor can only count what it detected, so the published number is a lower bound on attempts and says nothing directly about how many succeeded.

The point for a notary is simpler than the statistics. Your professional judgment operates on pixels delivered to you by software running on a stranger's machine. You are being asked to authenticate a video feed, which is not a skill any notary commission ever tested for, and which the best-funded detection teams in the world treat as an unsolved problem.

Why is deepfake detection the wrong job for a notary?

The industry has responded in the way industries do, by shipping a feature. Secured Signing announced Realify, a real-time deepfake detection capability for remote online notarization and video signing sessions, in October 2025, and subsequently reported strong month-on-month growth in notary adoption of it (Secured Signing announcements via Send2Press Newswire). Take that at face value in both directions: it is evidence that platforms take the threat seriously, and it is evidence that notaries are worried enough to adopt.

It is worth pausing on the fact that the strongest public scepticism has come from inside the profession rather than from outside it. At least one Florida document and notarization practitioner has publicly argued that deepfake detection in this setting is marketed far beyond what it delivers, and that it is nowhere near the security breakthrough some platforms present it as. That criticism deserves to be taken seriously precisely because it comes from someone with commercial reasons to like the technology.

The structural problem is not that detectors are bad. Some are quite good. The structural problem is the shape of the contest.

A detector must decide, in real time, whether a video stream is authentic. The attacker gets to iterate offline, test against the detector as often as they like, and only has to win once per closing. The defender has to win every time, at scale, with a false positive budget of approximately zero, because telling a genuine homeowner that they appear to be a deepfake is a catastrophic customer experience and a professional liability event in its own right. That asymmetry does not improve with better models. It is a property of the arrangement.

And there is a professional dimension that gets lost in the vendor conversation. A notary's commission is a public office with personal liability attached. Asking a notary to be the last line of defence against synthetic media places a duty on them that they cannot discharge, were never trained for, and cannot insure against with any confidence. That is not a fair thing to ask of a profession. It is also, from a systems perspective, a design smell: when the only remaining control is a human being asked to perceive something imperceptible, the design has failed somewhere upstream.

What would actually bind the signer to the document?

Go back to the four duties. Identify, confirm willingness, confirm awareness, keep a record. Only the first of those is broken by synthetic video. Willingness and awareness are still assessed through conversation, and a notary talking to a person about what they are signing remains valuable and hard to fake convincingly at length. The record keeping is fine. It is identification that has lost its instrument.

So replace the instrument, and leave the office intact.

The signer enrols a device before the transaction. Not on the day, and not inside the closing session, because a control established during the attack is not a control. Enrolment happens at an earlier, lower-stakes touchpoint where the relationship already exists: the lender's application, the title company's engagement, the county recorder's property alert programme, a prior closing. At that moment the human proves identity in whatever way that institution already requires, and a key is bound to them on a device they hold.

At the closing, the notarial act includes a signature from that enrolled device over the hash of the actual document. Not a session token, not a click in the platform, not a typed name. A cryptographic assertion produced by a key that lives in hardware on the signer's phone, over the exact bytes of the deed being signed.

An impostor with a perfect deepfake, a synthesised licence and every answer to every knowledge question does not have the device. They cannot produce the signature. The video becomes what it should always have been in a remote setting: a record of the interaction, useful evidence of willingness and awareness, and no longer the load-bearing identity control.

What the receipt contains

The output is a notarisation receipt: a small, self-contained object that a recorder, a title insurer or a court can verify years later without contacting anybody.

{
  "type": "notarization_receipt.v1",
  "document_hash": "sha256:9f2b41c8e7a3...c41e",
  "document_title": "Deed of Trust, Parcel 041-22-118",
  "signer": {
    "key_id": "ak_7bd2f4",
    "enrolled_at": "2026-07-02T15:22:10Z",
    "enrolled_by": "first-national-title",
    "presence": { "method": "companion_device", "liveness": "passed" }
  },
  "signed_at": "2026-09-16T20:47:33Z",
  "notary": {
    "commission_id": "FL-NP-118422",
    "jurisdiction": "FL",
    "session_recording_hash": "sha256:1d7790ab...9ab0"
  },
  "signature": "ed25519:MEUCIQD..."
}

Two fields carry most of the weight, and they are the two that no current RON control produces.

enrolled_at is a date before the transaction. That single fact is what an impostor cannot manufacture on the day. Fraud of this kind is opportunistic and time-boxed: the attacker finds a target, moves quickly, and closes before anyone notices. A control that requires them to have compromised the real owner months earlier, at an institution they had no reason to know would matter, changes the economics badly for them.

document_hash binds the signature to this document and no other. A signature that is not bound to content is a signature on a blank page. This is the same failure we described in Bybit's signers signed what the screen showed, and the fix has the same shape in both domains: sign the canonical bytes, and render those bytes on a device separate from the one presenting the transaction.

Verification is arithmetic, not a service call:

import nacl.signing, hashlib, json, base64

def verify_notarization(receipt, document_bytes, published_key):
    # 1. the document is the one that was signed
    h = "sha256:" + hashlib.sha256(document_bytes).hexdigest()
    assert h == receipt["document_hash"], "document does not match receipt"

    # 2. the signature is genuine, checked against a published key
    body = json.dumps({k: v for k, v in receipt.items()
                       if k != "signature"}, sort_keys=True, separators=(",", ":"))
    vk = nacl.signing.VerifyKey(published_key)
    vk.verify(body.encode(), base64.b64decode(receipt["signature"].split(":")[1]))

    # 3. enrolment predates the signing, which is the anti-impostor property
    assert receipt["signer"]["enrolled_at"] < receipt["signed_at"]
    return True

No callback to a vendor. No dependency on a platform still being in business in 2041 when the title is next examined. That property, which we cover in depth in can you verify a credential without phoning the issuer, matters more in property records than almost anywhere else, because the verification horizon is measured in decades.

How do the RON identity controls compare?

ControlWhat it establishesWhat defeats itSurvives injection attack
Knowledge-based authenticationAccess to a public and commercial records datasetBreach corpora, data brokers, a relativeNot applicable, never depended on the camera
Credential analysisAn image is consistent with a genuine documentSynthesised document images, injected framesNo
Notary visual comparisonTwo images resemble each otherFace swap, puppeteering, injected streamNo
Deepfake detection on the streamA probability that frames are syntheticIteration against the detector, novel generatorsPartially, and only while ahead of the generator
Session recording retentionA record of what the notary was shownNothing, but it records the fake faithfullyNot a control, an artefact
Signature from a pre-enrolled deviceThe holder of a specific key, enrolled earlier, signed this documentCompromise of the enrolled device, or of the enrolment itselfYes, the camera is not in the trust path

Read the last column as the summary of the whole argument. Five of the six controls sit downstream of a video pipeline the signer's machine controls. One does not.

What does this cost the honest signer?

An objection worth taking seriously: RON exists to make closings easier, and every control added is friction, and friction has a body count in abandoned transactions.

The honest accounting is that the enrolment step costs something and the signing step costs almost nothing. Enrolment is a one-time interaction at the lender or title company, roughly the effort of setting up a banking app, done at a moment when the customer is already filling in forms and is not in a hurry. The signing step is a prompt on a phone the signer is already holding, and a biometric unlock they perform dozens of times a day for less important reasons.

Compare that to what the current process asks: locate a physical identity document, hold it steady at the correct angle under adequate lighting, and answer five questions about a car loan from 2011. The device signature is not the friction in this workflow. It is arguably the least annoying step in it.

Where it does cost something real is the signer who has never enrolled anywhere, which brings us to the limits.

Honest limits

This proposal has four real weaknesses, and a notary or title professional will find all of them within a minute, so here they are first.

It requires enrolment before the transaction, and many signers will not have one. A first-time seller of inherited vacant land who has no prior relationship with the title company is exactly the profile most targeted by seller impersonation fraud, and exactly the profile least likely to be enrolled. There is no clever way around this. The realistic answer is that enrolment spreads gradually through lenders, title companies and recorder alert programmes, and in the meantime the control applies to the transactions where it can, which is refinances, repeat customers and anyone who has closed before. Partial coverage is still coverage, but nobody should describe it as a general fix.

Our own face match runs on a camera, and cameras can be injected. This deserves stating plainly because it would be hypocritical not to. Manav's presence check uses an on-device face match with liveness, and a camera is a camera. What the design does not do is rest the security of the transaction on that check. The load is carried by the hardware-bound key, which was enrolled earlier and cannot be produced by an attacker with a video pipeline. The face check adds continuity, the assurance that the same human who enrolled is present now. If you inverted that and made the camera check the primary control, you would have rebuilt the problem with a different logo on it.

Notarial law is state by state and prescribes methods. A vendor cannot change how a notarial act is performed in Florida or Texas by publishing a blog post. State statutes and administrative rules enumerate acceptable identity verification methods, and adding a new one requires legislative or regulatory change, plus attention from MISMO on the standards side and from the title insurance industry on the underwriting side. This is a multi-year path, and anyone selling it as a next-quarter deployment is misleading you. The near-term, honest positioning is a supplementary control on high-value conveyances, layered on top of what the statute already requires, not a replacement for it.

It does not address coercion or capacity. A real signer, with a real device, being pressured by a family member off camera, produces a perfectly valid signature. Elder financial abuse frequently looks exactly like this. The notary's conversational duties remain the only defence there, which is another reason this proposal keeps the notary in the room rather than automating them out of it.

Why does this matter more than the fraud numbers suggest?

Real estate fraud reported to the FBI's Internet Crime Complaint Center reached roughly $275 million across more than 12,000 complaints in 2025, with a substantial year-over-year increase (FBI IC3 2025 Internet Crime Report). That number understates the problem in two directions. Reported complaints are a fraction of incidents, and the figure counts money moved, not titles clouded.

The deeper cost is to a system that works because nobody has to check it. Property records function as a public good precisely because a recorded deed is presumed valid, and everyone downstream, buyers, lenders, insurers, tax authorities, relies on that presumption without independently verifying anything. A rising rate of fraudulent notarisations does not just transfer money to criminals. It puts a small crack in a presumption that a very large amount of economic activity rests on, and once title professionals stop trusting notarial certificates, the cost of every transaction goes up for everyone, including the honest majority.

That is the case for fixing the identification instrument rather than adding another detector to the stream. Detectors buy time. Instruments last.

What to do this week

  1. Write down what your RON platform actually proves. For each control it runs, state in one sentence what a successful pass establishes. If any sentence contains the word "image" or "probability", mark it. That list is your real risk register, and most firms have never written it.
  2. Find your enrolment moments. List every touchpoint where you already verify a customer's identity for another reason: loan application, engagement letter, prior closing, recorder alert sign-up. Those are where device enrolment belongs, because the customer is already there and already proving who they are.
  3. Segment by irreversibility, not by dollar value. A cash-out refinance and a conveyance of unencumbered land are different risks even at the same amount, because one has a lender watching and the other does not. Tier your sessions accordingly and put the strongest controls where recovery is hardest.
  4. Ask your platform vendor two specific questions. What is your detection false negative rate against injection attacks specifically, as opposed to presentation attacks, and who performed that evaluation. A vendor who cannot distinguish the two attack classes in their answer is not equipped for this threat.
  5. Stop treating the session recording as a control. It is an artefact. It records the fraud with the same fidelity as a genuine closing. Useful in litigation, worthless in prevention, and it should not appear in your controls documentation as though it prevents anything.
  6. Talk to your errors and omissions carrier. Ask directly whether they would price a policy differently for sessions carrying a device-bound signer signature. Carriers price controls they can verify, and an offline-verifiable receipt is unusually easy for an underwriter to check.
  7. Read one of the sanctions or fraud dockets in your own county. Not a vendor summary, the actual filing. The gap between how the fraud reads in a case document and how it reads in marketing material is where your intuition needs recalibrating.

If you want to see what a device-bound signature feels like from the signer's side before proposing it to anyone, the signing demo runs in a browser in about thirty seconds, and the developer documentation covers the receipt format and offline verification.

The notary's job was never to spot the fake

There is a version of this conversation that treats notaries as the weak link, and it is both unfair and analytically wrong. The notary is not failing. The instrument the notary was handed, a video feed, stopped being able to answer the question it was being used to answer, and nobody told the profession that the ground had moved.

The office is four hundred years old because the underlying idea is sound: before something irreversible happens to your property, a disinterested officer confirms it is really you and you really mean it. That idea does not need replacing. The identification instrument does. Give the notary a cryptographic fact instead of a perceptual judgment, and the office works again, in a world where faces are cheap and keys are not.

Frequently asked questions

Can a deepfake pass remote online notarization? Yes. Knowledge-based questions draw on data that has been breached repeatedly, credential analysis inspects an image that the signer's own machine produced, and the video feed can be replaced at the capture layer through a virtual camera or a modified client, so the notary sees frames that no lens ever recorded. Every control in a standard RON session sits downstream of software the signer controls.

Does deepfake detection in RON work? Partially, and only while the detector is ahead of the generator. Detection performs reasonably against presentation attacks, where something is held up to a real camera. It performs far worse against injection attacks, where synthetic frames are fed directly into the video pipeline. Ask any vendor to separate those two numbers, because a combined figure hides the one that matters.

What is an injection attack in identity verification? An attack that bypasses the camera entirely. Instead of showing something to a lens, the attacker uses a virtual camera driver, an emulator or a modified application to deliver synthetic video directly to the software requesting a camera stream. Because the attacker generates the frames, every liveness cue the system looks for can be present by construction.

Is remote online notarization less safe than in-person notarization? For identification, yes, and that is a fair statement rather than an attack on RON. In-person notarisation has a physical presence guarantee that no remote channel can reproduce. RON compensates with recording, credential analysis and knowledge questions, all of which are weaker than a body in a room. The way to close that gap is a device-bound signature, not a better camera.

What would a notarization receipt actually prove? That the holder of a specific cryptographic key, enrolled at a named institution on a date before the transaction, signed the exact bytes of this document at this time, with a liveness check passed on their own device, in a session recorded by a named commissioned notary. It can be verified years later against a published key with no call to any vendor.

Can this be adopted without changing state law? Only as a supplementary control. State statutes and administrative rules prescribe acceptable identity verification methods for notarial acts, so a device signature can be layered on top of the required steps today, but it cannot replace them until the rules change. Treat any vendor claiming otherwise with suspicion.

Who pays for this? Realistically, the parties carrying the loss: title insurers, lenders, and errors and omissions carriers, who all have an interest in a control they can verify independently. Per-session pricing through RON platforms is the natural mechanism, and the underwriting discount is the natural argument.

Sources

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, real estate fraud complaint and loss figures. ic3.gov/AnnualReport/Reports
  2. Secured Signing, announcement of Realify real-time deepfake detection for remote online notarization, October 2025. send2press.com
  3. Secured Signing, reported month-on-month growth in notary adoption of its deepfake detection feature. send2press.com
  4. National Notary Association, guidance on notarial duties and remote online notarization requirements by state. nationalnotary.org
  5. MISMO, remote online notarization standards and certification programme. mismo.org
  6. American Land Title Association, guidance on wire fraud and seller impersonation. alta.org
  7. NIST Special Publication 800-63, Digital Identity Guidelines, identity assurance levels and remote identity proofing. pages.nist.gov/800-63-3
  8. ISO/IEC 18013-5, personal identification, mobile driving licence application, including offline presentation. iso.org
The notary's job was never to spot the fake. It was to attest that a specific person signed. Give them a signature to check instead of a face to judge, and the office works again.