Safe Call: verify who is on a phone call
How to use Safe Call to prove — or check — who is really on a phone call before sharing anything sensitive.
Safe Call is a website you open from your phone or computer to prove who is on a phone call. It is built for the moment when someone calls you claiming to be from IT, the help desk, or another trusted team and asks you to do something sensitive — reset a password, approve a sign-in, read back a code, or install software.
Instead of trusting the caller’s voice (which can be faked or spoofed), Safe Call has the caller prove their identity with Nametag: a scan of their government ID, a Spatial Selfie™, and Deepfake Defense™. Both of you watch the result appear live, so you both know the verification is real and happening right now.
Safe Call runs entirely in your web browser. There is nothing to install.
When to use Safe Call
Use Safe Call any time you are unsure who is really on the other end of a call and the call involves anything sensitive, for example:
- A “help desk” or “IT support” agent asks you to share or reset a password, MFA code, or recovery code.
- Someone asks you to approve a sign-in prompt, disable security, or grant access.
- A caller claims to be a coworker, executive, or vendor and the request feels urgent or unusual.
If anything about a call feels off, ask the caller to verify through Safe Call. A legitimate caller will be able to. An attacker will not.
Opening Safe Call
Go to your organization’s recovery website and add /safecall to the address — for
example https://recovery.your-company.com/safecall. Your IT team can give you the
exact link.
The first screen asks which side of the call you are on:
- “I received a call” — choose this if someone called you. You are the employee, and you will ask the caller to prove who they are.
- “I’m making a call” — choose this if you are the one calling someone and they have asked you to prove who you are. You are the caller.
Both people open the same Safe Call site and pick opposite roles. The two devices then join the same verification session.
If you received a call (employee)
-
Open Safe Call and choose “I received a call.”
-
Read the 6-digit code aloud. Safe Call shows you a 6-digit code. Read it to the caller over the phone and ask them to type it into their own Safe Call screen.
The code changes every 30 seconds for security. Always read the code that is on your screen right now — never a screenshot or an old code. If the code changes while you are talking, just read the new one.
-
Wait and watch. After the caller enters the code, the two screens connect. You will see the caller’s progress as they scan their ID and take their selfie. You do not have to do anything except watch.
-
Read the result.
-
Verified — Safe Call shows the caller’s verified name, photo, and a list of the checks that passed (see What “verified” means below), along with the time of verification. You now have strong evidence of who the caller is. Confirm the name and photo match who they claim to be before continuing.
-
Could not verify — Safe Call shows that the caller could not be verified. Do not share passwords, codes, approvals, or any sensitive information. Treat the call as suspicious and follow your organization’s process for reporting a possible social-engineering attempt.
-
What “verified” means
A verified result confirms that Nametag checked and passed all of the following:
- Government ID — the caller presented an authentic, unexpired government-issued ID.
- Spatial Selfie™ — a live three-dimensional selfie that matches the photo on the ID.
- Deepfake Defense™ — confirmation that a real, live person took the selfie, not a photo, video, mask, or deepfake.
A verified result tells you the person is who their ID says they are. It is still up to you to decide whether that person is authorized to make the request — for example, whether a verified individual is actually a member of your IT team.
If you are making a call (caller)
-
Open Safe Call and choose “I’m making a call.”
-
Enter the 6-digit code. The employee will read you a 6-digit code over the phone. Type it into your Safe Call screen and continue. This links your device to theirs.
If the code is rejected, ask the employee to read you the current code again — it refreshes every 30 seconds, so an older code may have already expired.
-
Scan the QR code to verify. Safe Call shows a QR code. Scan it with your phone camera to start Nametag identity verification. Follow the prompts to:
- Scan the front (and, if asked, the back) of your government ID.
- Take a Spatial Selfie™ by moving your head as directed.
-
You’re done. When verification finishes, both your screen and the employee’s screen update at the same time to show the result. If you were verified, the employee sees your verified name and photo and can continue the call.
Your ID and selfie are processed by Nametag to produce the verification result. Nametag does not hand your ID images to the employee — the employee only sees the outcome (your verified name, photo, and which checks passed).
Safety guidance
- No verification, no secrets. If Safe Call shows “could not verify,” or the caller refuses or fails to verify, do not share passwords, one-time codes, recovery codes, or approvals, and do not make account changes. Legitimate support staff can verify.
- Never read a code from a screenshot. The 6-digit code is only valid for a short time and is meant to be spoken live during the call. A caller who already “has the code” without you reading it to them is a red flag.
- The code proves the call, not the person. Entering the code only links the two devices. Identity is proven by the ID scan and selfie, not by the code.
- Take your time. There is no penalty for asking a caller to verify, and no rush to act on an urgent-sounding request. Safe Call sessions stay open for up to an hour.
- Report suspicious calls. If a caller cannot or will not verify, end the call and report it to your security or IT team.
What happens if it takes too long?
A Safe Call session lasts up to one hour, after which it expires and both sides see an “expired” message. You can always start a new session.
The session also expires if the employee’s screen stops responding for more than about 30 seconds — for example, if the browser tab is closed. If this happens, reopen Safe Call and start again with a fresh code.