Threat model and receipts
Can the browser simply lie about what was said? Against a hostile client, yes, and this page says how far that goes, what the vendor's own record adds, and what still cannot be proved.
The browser supplies the provenance, so a hostile client can forge it
The browser holds the recognizer socket directly, so the words, their millisecond timings and their per-word certainties never pass through our server. The client posts them, and the gate checks that a value traces to words the session reported, not that anyone spoke them.
| Question | Answer |
|---|---|
| What it stops | A recognizer quietly mishearing a drug name, which is the failure the product exists for. |
| What it does not stop | A caller with DevTools posting invented words. Forging your own transcript deceives only yourself, and the gate is not built against that adversary. |
| Why not relay the audio | It needs an always-on host, the process this design removed to fit the platform. The trade: we hold finer-grained evidence, per word, that a hostile client could fabricate; a relaying design holds coarser-grained evidence that a hostile client could not. |
The vendor witness is a second channel the browser cannot write
At finalize the server fetches the caller transcript AssemblyAI's own recognizer produced on the agent socket and seals one verdict per field into the receipt, so forging provenance means forging the vendor's record too.
| Verdict | What it means |
|---|---|
witnessed | The vendor's transcript of the caller supports the value, by the same spoken-support rule the gate uses. |
not_witnessed | The vendor's transcript was fetched and does not support the value. The receipt says so beside the field. |
unavailable | The timeline could not be fetched, so nothing is claimed either way, and the receipt names the reason. |
It also arrives too late to block anything: the timeline appears seconds after the session ends, so it seals a receipt rather than stopping a commit inside the call. It carries turn-level times, not word-level ones, so the word-to-gate latency stays a browser measurement.
npx tsx scripts/report/probe-witness.ts, measures the delay over the session list and each session's timeline artifact on AssemblyAI's agents API, read with the server's key
A receipt is rechecked in your browser, not taken on our word
Every committed live order links its receipt at /order/ followed by its session id. That page recomputes the sha256 over the receipt's canonical JSON, the NPI and DEA check digits, and whether a name on the published pair list was confirmed aloud, and shows the witness verdict beside each field.
The same page checks a downloaded receipt file: change one character and the digest no longer matches. No sample receipt is published here, because none has come from a recorded live call, and a synthesised one would be a record presented as genuine.