Scope
Record the sanctioned purpose, customer, participants, channels, scenario boundaries and expected safe behavior.
Control who can authorize an exercise, whose voice may be used, what a scenario may request, which artifact was approved, what evidence is retained and how results are shared.
Deepfake and social-engineering assessments can expose sensitive identities, communication patterns and individual behavior. Deceptiment therefore treats governance as part of the execution path rather than a policy document attached after launch.
The customer defines the authorized objective, audience, scenario and approvers. Voice-based work requires voice-owner consent evidence. Generated audio is reviewed before launch, and material changes to scripts, audio modes or source recordings invalidate stale approval. Test-delivery evidence is required for governed WhatsApp voice campaigns.
Safe scenarios measure behavior without requesting real transfers, credentials, authentication codes or genuine sensitive information. Results are intended for coaching and control improvement, not public exposure or punitive use.
Record the sanctioned purpose, customer, participants, channels, scenario boundaries and expected safe behavior.
Document voice-owner consent and retain the evidence reference associated with the approved profile.
Block scenarios that solicit secrets, funds, control bypass or other real-world harmful outcomes.
Review the exact generated audio or campaign content. Changes invalidate prior review where relevant.
Use readiness checks, test sends, schedules, bounded audiences and customer approvals before delivery.
Record events, approvals and outcomes; apply configured retention, archive and confirmed-deletion workflows.
Deceptiment maintains a central operational event timeline covering authentication, governance, assessments, jobs, workers, webhooks, providers, integrations, retention and system actions. Events include source, severity, tenant, actor, outcome, target and correlation context where applicable.
Organizations can export normalized JSONL, CEF and CSV, configure worker-driven HTTP SIEM forwarding, or use a bearer-authenticated cursor-based SIEM pull endpoint. These controls help security teams bring assessment evidence into broader governance, monitoring and reporting workflows.
The customer’s designated stakeholders must formally sanction the exercise and its scope; platform access alone is not authorization.
The public responsible-use policy requires plain-language notice and supports withdrawal; voice use remains bound to documented consent status.
The product documents retention enforcement, customer-confirmed deletion and pseudonymization of expired target data according to configured policy.
No. Generated evidence may support controls and audits, but only the relevant auditor, regulator or qualified assessor can determine compliance.
Ask to see consent, approval invalidation, safe interaction design, retention and evidence export live.
Book a governance-led demonstration →