Manav.id
Vertical · 4 min read

When the video recording stops being evidence

When the video recording stops being evidence

The statutory framework for remote notarisation was built when a recorded video of a person holding their identification was strong evidence. That assumption is aging faster than the statutes.

Is a RON recording still good evidence?

Weakening, for a specific reason. A recording proves a session was captured. Whether what was captured was a person in front of a camera is a separate question, and injected video arrives through the same media stack a real camera uses.

Key takeaways
  • RON statutes generally require credential analysis, knowledge-based authentication and a recorded session. Each was strong when written.
  • A recording establishes that a session took place, not that the person in it was who they appeared to be.
  • A hardware signature over the document hash gives the notary an artefact that does not depend on the video's evidentiary strength.

What the statutes require

Synthetic video injectedvirtual cameraPlatform captures it as a live feedsame media stackNotary interacts and is satisfiedreal-time synthesisRecording retainedan accurate record of a fabrication
If the notary was deceived, the recording preserves the deception faithfully.

State frameworks differ in detail and converge on a common set.

RequirementWhat it establishesCurrent strength
Credential analysisThe presented identity document appears genuineModerate — synthetic documents are improving
Knowledge-based authenticationThe signer knows facts about the identityWeak — answers are in breach data
Live audio-video sessionA person appeared and interactedWeakening
Recording retentionAn artefact exists for later reviewDepends on the recording's evidentiary value

The second row has been weak for years and is generally acknowledged as such. The third is the one that changed recently, and the frameworks have not caught up.

Why a recording is weaker than it looks

A recorded session is evidence that something was captured. Whether what was captured was a person in front of a camera is a separate question, and the video does not answer it.

A reviewer watching the recording months later sees what the notary saw. If the notary was deceived, the recording preserves the deception rather than revealing it.

Where this matters most

Not every notarised document is worth attacking. Two categories are.

  1. Instruments affecting title. Deeds and mortgage documents transfer or encumber property. A forged instrument recorded in the public record creates a problem that takes years and litigation to unwind.
  2. Powers of attorney. A notarised power of attorney is a general-purpose authority instrument. Its value to an attacker is larger than any single transaction.

In both cases the notarisation is the control that the rest of the system relies on. Recording offices, title underwriters and counterparties accept a notarised instrument largely on the strength of the acknowledgement.

Adding an artefact that does not depend on video

# Alongside the RON session, not replacing it

  Document:   Deed of Trust, 1420 Fillmore Street
  Hash:       sha256:9c1f8a3e...d7b2
  Signer:     [name as it appears on the instrument]
  Notary:     [commission number, jurisdiction]
  Session:    RON-2026-0447, recorded

  Signer authenticates with a credential enrolled at least
  N days earlier, on hardware, with user verification.

  → signature over the document hash
  → notary countersigns
  → both travel with the instrument

The enrolment delay in the middle is doing real work. A credential enrolled during the session proves nothing about who enrolled it; one enrolled weeks earlier through a separate process gives the attacker a second problem to solve, at a different time, through a different channel.

What this changes and what it does not

QuestionRecording aloneRecording plus signature
Did a session occur?YesYes
Was the document the one discussed?InferredBound by hash
Did a specific enrolled credential authorise it?NoYes
Was the human behind the credential the named person?Not establishedNot established

The last row is the honest limit and it is important. A signature proves control of an enrolled credential. Binding that credential to a real identified human is an enrolment problem that neither video nor cryptography solves on its own.

What changes is that the attack must defeat enrolment as well as the session, and enrolment happened at a different time through a different channel. Requiring two separate compromises is meaningfully harder than requiring one.

The regulatory position

Nothing in existing frameworks prevents adding a signature alongside the statutory requirements. A notary who performs credential analysis, knowledge-based authentication and a recorded session, and additionally obtains a hardware signature over the document hash, has exceeded the requirement.

Whether frameworks will eventually require it is a separate question and probably a slow one. In the meantime, a notary or title underwriter who wants a stronger artefact can have one without waiting for statute.

This describes regulatory structures at a general level and is not legal advice. Notarisation requirements are state-specific and change; take specifics to counsel.

Where this matters most

Two instrument classes worth the effort
InstrumentWhy
Deeds and mortgage documentsA forged instrument in the public record takes years to unwind
Powers of attorneyA general-purpose authority instrument, worth more than any single transaction

In both cases the notarisation is the control everything downstream relies on — recording offices, title underwriters and counterparties accept the instrument largely on the acknowledgement.

Objections and honest limits

“Credential analysis and knowledge-based authentication still apply.” They do. Knowledge-based answers have been in breach compilations for years and synthetic documents are improving. The session recording was the strongest remaining leg.

“A signature does not prove identity either.” Correct, and worth stating: it proves control of an enrolled credential. What it adds is that the attacker must also defeat enrolment, at a different time through a different channel.

This describes regulatory structures at a general level and is not legal advice. Notarisation requirements are state-specific and change.

Strengthening a RON act

  1. Require a credential enrolled days earlier. So enrolment is a second, separate obstacle.
  2. Bind the document hash into the signature. So the act covers this instrument.
  3. Have the notary countersign. Commission number inside the signed statement.
  4. Keep both with the instrument. It outlives the platform.

Terms used here

RON
Remote online notarization, conducted over audio-video with credential analysis and knowledge-based authentication.
Credential analysis
Automated examination of an identity document for authenticity indicators.
Injection attack
Feeding synthetic video into the capture path so the platform records it as a live feed.

Frequently asked questions

Do RON recordings have no value? They establish that a session occurred and preserve what the notary saw. They do not establish that the person on camera was who they appeared to be.

Why require the credential to be enrolled earlier? A credential enrolled during the session proves nothing about who enrolled it. Prior enrolment forces the attacker to defeat a second, separate process.

Does a signature prove identity? No. It proves control of an enrolled credential with user verification. Binding that credential to a named human is an enrolment problem.

Is adding a signature permitted under current statutes? Nothing prevents exceeding statutory requirements. This is general description rather than legal advice, and notarisation rules are state-specific.

Why require prior enrolment? A credential enrolled during the session proves nothing about who enrolled it. Prior enrolment forces a second, separate compromise.

Is adding a signature permitted? Nothing prevents exceeding statutory requirements. Rules are state-specific; take specifics to counsel.

Where this fits in Manav

Manav pairs the RON session with a hardware signature over the document hash, from a credential enrolled earlier through a separate process — so an attacker must defeat two things at two different times.

See document binding →

Sources and further reading