Inspiration
Generative AI has made it increasingly difficult to trust what we see and hear online. Faces can be cloned, voices can be replicated, livestreams can be restreamed, and compromised creator accounts can be used to impersonate people in real time.
Most solutions approach this as a detection problem: Can AI determine whether this video is fake?
We wanted to ask a different question:
Can the creator prove that they actually authorized this broadcast?
That question became StreamProof.
What it does
StreamProof provides an independent verification layer between creators and their audiences.
When a creator starts an authorized broadcast, StreamProof generates a time-bound QR proof linked to the creator's identity, channel, and current streaming session.
A viewer can scan that QR with StreamProof and verify:
- which creator authorized the broadcast;
- which channel the authorization belongs to;
- whether the StreamProof session is currently active;
- and where to find the original authorized stream.
This is intentionally different from claiming that the content itself is true or that a creator is trustworthy.
StreamProof verifies authorization and provenance — not opinions, claims, or content.
Viewers can also follow verified creators. When a creator starts another authorized broadcast, StreamProof can notify those followers and direct them back to the original stream.
This creates a useful loop for both sides: viewers gain an independent verification channel, while creators gain identity protection and a way to bring verified viewers back to their broadcasts.
How we built it
StreamProof started as a web proof of concept before we discovered Shipaton.
The original experiment focused on a simple question: could we create short-lived proofs that allowed a viewer to distinguish an authorized livestream from a copy?
For Shipaton, we expanded that concept into a mobile-first verification product.
The system combines:
- creator and channel identity;
- time-bound streaming sessions;
- dynamically generated QR proofs;
- independent verification;
- links back to the original stream;
- creator following and verified-live notifications;
- and RevenueCat-powered premium features for creators.
The mobile app became an important part of the security model. A fraudulent website can imitate StreamProof's colors, logo, or verification screen, but the official app provides an independent environment for validating StreamProof proofs.
Challenges
Our biggest challenge was defining exactly what StreamProof should — and should not — prove.
A copied QR can be replayed. A legitimate creator can retransmit older content. A creator can make misleading claims during an authentic broadcast. An attacker can compromise the creator's actual social account. Someone could even imitate StreamProof itself.
We repeatedly tried to break our own concept.
That process led us to an important principle:
StreamProof does not prove that content is true. It proves that a specific identity authorized a specific broadcast.
This distinction allowed us to keep the system neutral while making the verification meaningful.
It also revealed one of StreamProof's most interesting security properties: compromising a creator's streaming account does not necessarily compromise their independent StreamProof identity. A historically protected channel suddenly broadcasting without a valid StreamProof authorization can therefore provide viewers with an additional warning signal.
What we learned
The most important thing we learned is that authenticity and authorization are different problems.
AI-based detection can estimate whether content appears synthetic. StreamProof takes another approach: establish an independent chain of authorization that does not depend on determining whether pixels, voices, or faces look real.
We also learned that security alone is not enough to create a useful consumer product.
Verification needed to become a habit.
That led us to creator following and verified-live notifications. A viewer who verifies a creator once can follow that identity and be notified when the creator authorizes a future broadcast.
The QR therefore becomes more than a security feature. It creates a loop:
Creator → QR → Verification → Follow → Verified-live notification → Original stream
Our goal is simple:
Don't trust the face. Verify the source.
Generative AI made impersonation scalable.
We didn't add more AI. We added proof.


Log in or sign up for Devpost to join the conversation.