Readback
Source code on GitHub (opens in a new tab)

Threat model and receipts

Can the browser simply lie about what was said? Against a hostile client, yes, and this page says how far that goes, what the vendor's own record adds, and what still cannot be proved.

The browser supplies the provenance, so a hostile client can forge it

The browser holds the recognizer socket directly, so the words, their millisecond timings and their per-word certainties never pass through our server. The client posts them, and the gate checks that a value traces to words the session reported, not that anyone spoke them.

QuestionAnswer
What it stopsA recognizer quietly mishearing a drug name, which is the failure the product exists for.
What it does not stopA caller with DevTools posting invented words. Forging your own transcript deceives only yourself, and the gate is not built against that adversary.
Why not relay the audioIt needs an always-on host, the process this design removed to fit the platform. The trade: we hold finer-grained evidence, per word, that a hostile client could fabricate; a relaying design holds coarser-grained evidence that a hostile client could not.

The limitation at full strength

The vendor witness is a second channel the browser cannot write

At finalize the server fetches the caller transcript AssemblyAI's own recognizer produced on the agent socket and seals one verdict per field into the receipt, so forging provenance means forging the vendor's record too.

VerdictWhat it means
witnessedThe vendor's transcript of the caller supports the value, by the same spoken-support rule the gate uses.
not_witnessedThe vendor's transcript was fetched and does not support the value. The receipt says so beside the field.
unavailableThe timeline could not be fetched, so nothing is claimed either way, and the receipt names the reason.

It also arrives too late to block anything: the timeline appears seconds after the session ends, so it seals a receipt rather than stopping a commit inside the call. It carries turn-level times, not word-level ones, so the word-to-gate latency stays a browser measurement.

npx tsx scripts/report/probe-witness.ts, measures the delay over the session list and each session's timeline artifact on AssemblyAI's agents API, read with the server's key

A receipt is rechecked in your browser, not taken on our word

Every committed live order links its receipt at /order/ followed by its session id. That page recomputes the sha256 over the receipt's canonical JSON, the NPI and DEA check digits, and whether a name on the published pair list was confirmed aloud, and shows the witness verdict beside each field.

The same page checks a downloaded receipt file: change one character and the digest no longer matches. No sample receipt is published here, because none has come from a recorded live call, and a synthesised one would be a record presented as genuine.