##inspiration: Growing up in a household with a police officer, the reality of authentic law enforcement protocol is clear: real arrests require physical warrants, not WhatsApp video calls or "secret escrows." Yet, between 2022 and 2026, Indian citizens lost over ₹4,057 crore to "Digital Arrest" cyber extortion. Current security tools like Truecaller or standard spam filters are fundamentally reactive—they rely on the victim to recognize the scam. When an elderly citizen is terrified and isolated by an extortionist, logic fails. We were inspired to build a proactive, offline interception engine that breaks this psychological isolation before a single rupee is transferred.

What it does ScamPoint is an automated threat-interception ecosystem designed to protect non-tech-savvy users from authority-based social engineering. When a suspicious message is received, our heuristic engine evaluates the context against an offline database of known extortion scripts. If high-risk keywords (e.g., "Aadhaar blocked," "CBI investigation," "escrow") are detected, the system immediately triggers a visual and auditory warning. Crucially, it de-escalates panic by displaying real statutory laws (like Supreme Court guidelines or RBI rules) to prove the threat is legally impossible. Simultaneously, it deploys a Family Intervention SOS feature that dispatches a silent alert and live GPS coordinates to a trusted guardian.

How we built it I engineered a full-stack web simulator to prove the core logic. The frontend dashboard was built using HTML, CSS, and asynchronous JavaScript, integrating the native Web Speech API for accessible audio alerts tailored to elderly users.

​The backend is powered by a Python/Flask server acting as a lightweight API. To guarantee user privacy, I built the heuristic rulebook using SQLite—a localized, offline database. When a user inputs text, JavaScript sends a JSON payload via a fetch() POST request to Flask, which cross-references the text against the SQLite database in milliseconds and dynamically updates the UI without page reloads.

Challenges we ran into primary challenge was solving the privacy-versus-security dilemma. Scanning a user's private messages for threats typically requires sending that data to a cloud server, which is a massive privacy violation. We overcame this by architecting the SQLite database to run entirely locally. Proving that heuristic threat detection could be performed instantly on-device without internet reliance or cloud latency was a major technical hurdle we successfully navigated.

Accomplishments that we're proud of. incredibly proud of advancing past a basic UI mockup to deliver a fully functional backend infrastructure. Successfully connecting the Flask server to the SQLite database and handling asynchronous frontend requests under strict hackathon time constraints proves the technical viability of the threat-interception model.

What we learned Building ScamPoint taught me how to seamlessly bridge a dynamic frontend with a Python backend using RESTful API principles. Beyond the code, i learned that effective cybersecurity for vulnerable populations isn't just about blocking malicious links; it requires psychological de-escalation. Showing an actively panicking user an actual RBI guideline is vastly more effective than a generic "spam" warning.

What's next for Scampoint

This Flask prototype is the foundation for my market-ready architecture: a native Android application. I plan to utilize the Android Notification Listener and Accessibility APIs to run ScamPoint silently in the background. This will allow the engine to automatically scan incoming SMS and WhatsApp messages, triggering screen-dominating overlays and automated SOS dispatches without the elderly user ever needing to manually open an app or copy-paste text.

Share this project:

Updates

Submission history