-
The full Kicks store page with 4 sneakers + persona selector
-
The green "4 / allow" badge + "No concerning signals" text
-
The red "70 / challenge" + "Form also asks for ATM PIN"
-
The amber "38 / review" badge + factor list
-
The clay MFA modal with code input + "demo OTP"
-
The red "100 / challenge" badge + all risk factors listed
-
Live transaction feed showing Alex/Review/Shady entries
-
The "Is this payment page safe?" green verdict card
-
The red "70 / challenge" + "Form also asks for ATM PIN"
-
The "Is this payment page safe?" green verdict card
TrustPay — explainable fraud-risk for online checkout
Buy like a human. Get stopped like a pro.
TrustPay is an end-to-end fraud-risk engine that watches how you shop — typing cadence, paste-vs-type, mouse jitter, form-fill speed, device, network and order shape — and scores every checkout 0–100 with a human-readable explanation for every point. Legit shoppers glide through; risky ones are forced through an MFA identity check before a card is charged. Merchants see live verdicts on a dashboard. A Chrome extension turns any browser into a payment guard and page-trust scanner.
Built as a hackathon project (Visa Verify track). Demo-first, self-contained, no external APIs required.
The three surfaces
| Surface | What it does | Where |
|---|---|---|
| Web app | A tiny sneaker store ("The Kicks store") with TrustPay wired into checkout. Scripted personas make the demo deterministic. | client/ |
| Risk API | Node + Express. Weighted explainable model, transaction store, simulated MFA. | server/ |
| Guard extension | Chrome MV3. Watches checkout typing on any page, blocks risky submits with an MFA overlay, and scans any payment page for trust. | extension/ |
shopper's browser
┌───────────────────────────┐
│ Kicks checkout (Vite SPA) │──collector──┐
│ + TrustPay Guard ext │──guardInPage│
│ + pageScan (that page? │ │
│ safe to pay?) │ │
└───────────────────────────┘ ▼
┌─────────────────┐
│ explainable risk │
│ engine :4000 │
│ (Node/Express) │
├─────────────────┤
│ /api/risk │
│ /api/transactions│
│ /api/mfa/* │
└─────────────────┘
│
▼
merchant dashboard
Repo layout
server/ Express API — risk model, tx store, MFA sim, seed data
client/ Vite SPA — Kicks store, checkout collector, dashboard, demo pages
extension/ Chrome MV3 TrustPay Guard — content script, bridge, popup, page scanner
REPORT.md submission write-up
DEMO-SCRIPT.md 6-minute judged walkthrough
The risk model
Weighted linear model, score 0–100. Every contributing signal ships a readable factor so the "why" is never a black box.
| Threshold | Action |
|---|---|
| < 35 | allow — no friction |
| 35–64 | review — closer look, still smooth |
| ≥ 65 | challenge — MFA before any charge |
Weights (single source of truth: server/src/riskModel.js):
| Signal | Weight | Story |
|---|---|---|
base |
4 | neutral starting score |
deviceUnseen |
18 | first purchase on this device |
typingErratic |
15 | hunting-and-pecking cadence |
cardPasted |
16 | card number pasted, not typed |
vpn |
14 | anonymizing network |
countryMismatch |
12 | IP country ≠ card country |
amountScaleHigh |
10 | order ≫ your typical amount |
retryCount |
10 | repeated payment attempts |
mouseJitterHigh |
8 | robotic low-jitter mouse path |
rushTyping |
8 | impossibly fast typing |
autofillFast |
7 | form filled faster than a human |
The page scanner has its own weights for site-trust (cross-origin post +35, typosquat +45, sensitive overreach +30, no HTTPS +25, raw-IP host +20, odd port +15, no trust links +5) and recognizes iframes from Stripe / PayPal / Braintree / Adyen / Square / Razorpay / Checkout.com / 2Checkout / Cybersource / Worldline / Amazon Pay as legitimate hosted payment fields.
Quickstart
1. API
cd server
npm install
npm run start # :4000
2. Web app
cd client
npm install
npm run dev # :5173 (proxies /api → :4000)
When u clone the repo and after doing before steps
Open http://localhost:5173 → landing → Try the checkout demo → pick a persona or type
your own card details. Dashboard at #/dashboard shows the live feed.
3. Extension (Chrome)
- Zip install (recommended): grab
trustpay-guard-v0.2.0.zipfrom the release page, unzip →chrome://extensions→ Developer mode → Load unpacked → select the folder. Full guide:extension/INSTALL.md. - Checkout on any
http://localhostpage — the guard attaches automatically. - Use the popup "Is this payment page safe?" to scan a page before paying. Works on any site (activeTab).
Offline-first. The extension ships its own copy of the risk model (extension/riskModel.js,
a mirror of server/src/riskModel.js), so guard + scan + MFA work with no server running.
If the API is reachable it's used instead (and the merchant dashboard learns about the
checkout); a small "offline engine" tag on the popup tells you which mode you're in. Verdicts
are identical in both modes.
Demo pages (built-in)
http://localhost:5173/demo-checkout.html— a realistic standalone store checkout that the extension knows nothing about, and still protects.http://localhost:5173/demo-phish.html— a fake "verify your payment" clone that posts to a sketchy domain and asks for your ATM PIN. The scanner flags it 70/challenge (red) and auto-attaches the block-guard.
Deploy (at submission)
Backend stays on Railway (free tier), frontend on Vercel — both paused until submission to respect the free-tier budget.
# server → Railway
railway up # previously: railway link devoted-caring-production-534f
# client → Vercel, pointing at the live API
cd client
$env:VITE_API_URL = "https://devoted-caring-production-534f.up.railway.app"
vercel --prod
# extension → swap the API base in extension/background.js to the live Railway URL,
# then reload the unpacked extension for the live demo.
CORS on the API already allows trustpay.vercel.app and trustpay-zamirdevs-projects.vercel.app.
Testing
Server: curl http://localhost:4000/api/health · POST /api/risk with the documented signal
shape. The page scanner is exercised in the Node harness (see session notes): legit page
0/allow, phishing clone 70/challenge, Stripe-iframe page allow + hostedBy: Stripe,
stray card field outside a form no crash.
PITCH DECK
TRUSTPAY
Explainable Fraud-Risk Protection for Online Checkout
Bharat Innovation Challenge 2.0 — Theme: Cybersecurity & Ethical Tech
Team: ZamirDev (solo) · Mentor: Shailendra Bajpai, Podar International School File name: ZamirDev_TrustPay_PodarInternationalSchool
The Problem
Card-not-present fraud is exploding, and good shoppers are caught in the crossfire.
- Online payment fraud keeps rising year over year, and most of it happens at the checkout moment — the card never leaves the browser before a bad actor touches it.
- Merchants face an impossible trade-off:
- Too loose → chargebacks eat the margin, losses get passed to every honest customer.
- Too strict → friction (repeated 3DS-style prompts) makes real buyers abandon the cart.
- When a genuine order is declined, no one can say why — black-box fraud models give merchants a "no" and customers a mystery. Everyone loses trust.
- A second, dirtier problem: fake checkout pages. Typosquat domains ("paypal-verify.shop"), "verify your payment" clones, and pages that brazenly ask for your card and your ATM PIN or OTP.
Fraud isn't just a transaction problem. It is a trust problem at the moment you pay — and neither shoppers nor merchants can currently audit the decision.
The Opportunity
- Every online purchase in India and worldwide is a potential fraud target — and a potential false decline.
- There is a huge, unserved gap: explanations. Existing tools decide; almost none explain.
- The market that exists today is dominated by two extremes:
- Bank-level black-box consoles (expensive, built for fraud teams, opaque to the buyer).
- User-side password managers / 2FA (they check your accounts, not the page and the act of paying).
- Nobody sits in the middle: guarding the actual checkout page, in the browser, with reasons a human can read.
We are building for the gap between "fraud team dashboard" and "password manager": protection at the point of payment, explained end to end.
Existing Gaps (What's Missing Today)
| Gap | Today's tools | What TrustPay does |
|---|---|---|
| No explanation | Black-box models decline with a generic message | Shows top-3 factors + a one-line reason, live on the page |
| No page-level trust check | 2FA protects after you log in, not the fake page itself | Scans the page: cross-origin POSTs, typosquats, PIN/OTP overreach |
| Fraud-only tools are merchant-side | Shopper has zero visibility | Risk score shown to the shopper before they pay |
| Heavy infrastructure | Model servers, feature stores, big ML teams | Fully client-side, works offline, no external APIs |
Our Solution
TrustPay = trust you can see, at the moment you pay.
Two complementary products, one philosophy — explain everything.
Half 1 — Behavioral risk scoring at checkout. While a real human (or a script) fills the card form, we collect browser-side signals and turn them into a transparent 0–100 risk score:
- How fast and how evenly you type (erratic bursts = bot-like)
- Whether the card number was pasted vs typed
- How long the form took vs how many fields it has
- Mouse-path smoothness (robotic low-jitter = scripted)
- Device identity (first purchase on this device?)
- Network context (VPN, IP-vs-card country mismatch)
- Order shape (amount vs typical spend, retry velocity)
The verdict is shown before the customer pays:
- allow (< 35) → nothing slowed down
- review (35–64) → we look closer, zero friction
- challenge (≥ 65) → submit is blocked; MFA required before a single rupee is charged
Half 2 — the TrustPay Guard extension ("Is this payment page safe?") A Chrome extension that protects any checkout page it has never met:
- Attaches the behavioral guard to card forms anywhere
- Blocks the submit before the card leaves the browser when the score is critical
- Scans the page for trust: cross-origin POSTs, typosquat domains, sensitive overreach (ATM PIN / OTP / SSN beside a card), and real processor iframes (Stripe, PayPal, Razorpay…)
- Renders a banner + popup verdict; a red verdict auto-attaches the block
Technology & Innovation
The innovation is not "a score" — it is a score a human can audit.
68 Likely risky — identity check needed
+35 This page posts to evil.example.net, not its own domain
+25 Form also asks for "ATM PIN" — never alongside a card
+5 No privacy / terms / help links found
Not "transaction declined." Three readable reasons, reverified by the user, then a step-up MFA.
Stack (fully self-contained, zero external APIs):
- Server: Node + Express — stateless pure-function risk API, in-memory feed
- Client: Vite + vanilla JS — checkout storefront + dashboard (all local, offline-capable)
- Extension: Chrome MV3 — service-worker API bridge that bypasses page CORS (the page never learns what was sent), page scanner, auto-block guard
Design principles:
- Transparent weighted model — deliberately linear and auditable; humans can tune the weights. Not a gradient-boosted black box.
- Privacy-first — risk signals are computed locally; no PII leaks to analytics.
- Works offline — no geo-IP dependency in the demo; real IP detection is a drop-in.
Prototype / MVP (Working Demo)
A live, working prototype — not a mockup.
The Kicks storefront — a demo web shop where the risk engine runs in real time:
| Persona | What the user sees | Verdict |
|---|---|---|
| Alex 😊 known device, calm typing, normal order | instant green, zero friction | 4 / allow |
| Review 🟡 VPN + geo mismatch, rushed form | amber, still seamless | 38 / review |
| Shady 😈 new device, pasted card, erratic typing, big order | blocked → MFA required | 100 / challenge |
Guard extension demo (on two real local pages):
- A legitimate standalone store checkout → green / allow
- A phishing clone (posts to a fake domain, asks for ATM PIN) → red 70 / challenge + auto-block
- A real Stripe-iframe checkout → correctly recognized as a hosted payment page (allow)
Everything shown in the pitch is running code, with an MFA force-overlay and a live transaction dashboard.
Target Users
- Shoppers — anyone paying online who wants to know before they submit whether the page and the purchase look safe, and why their order got challenged.
- Small & mid-size merchants — no fraud team, no ML budget; they get professional-grade scrutiny with zero setup, and explanations they can actually act on.
- Fintechs & banks — as a shopper-facing trust layer and a merchant-side explainable signal to complement their own black-box systems.
- Schools & first-time digital buyers — India's newest internet users (UPI-era) are the most vulnerable to typosquats and PIN-overreach scams; TrustPay literally teaches safe checkout.
Impact
- Stops leaks of card data at the source — the submit is blocked inside the browser before the card leaves the device.
- Reduces both fraud losses and false declines — precise scoring means fewer honest customers are pushed away, and fewer fraudsters slip through.
- Kills the phishing page as a category — typosquat + overreach detection turns "help me detect phishing sites" into "my browser refuses the impostor page."
- Builds digital trust literacy — every verdict teaches the user one concrete signal of fraud, creating safer internet behavior beyond any single transaction.
Measurable promise: fewer chargebacks for the merchant, fewer abandoned carts, and — critically — users who can now explain why they were protected.
Implementation Plan
Phase 0 (done) — Working prototype: risk engine, checkout store, dashboard, Chrome extension, full demo. Everything in this deck is already built and running.
Phase 1 (months 1–3): Real geo-IP/proxy detection server-side; per-merchant model calibration; merchant rule editor on the dashboard.
Phase 2 (months 4–9): Extension auto-runs on payment pages across the open web (scanner already understands processor iframes); packaged for the Chrome Web Store.
Phase 3: Chargeback-informed retraining loop that feeds real outcomes back into the transparent weights — turning merchant results into better, still-auditable decisions.
Scalability & Competitive Advantage
Scalability:
- Client-side first — the core engine ships per-user; the server is a stateless function that scales horizontally. No heavy ML infrastructure.
- Distribution flywheel — works as (a) a merchant widget, (b) an extension protecting every page, and (c) an embeddable API. One engine, three surfaces.
- Local-first = global — runs offline and in low-bandwidth classrooms/labs, important for the Indian market.
Competitive advantage:
- Explainability is the product, not a feature — no major player shows the customer the reasons.
- Page-level trust + transaction risk in one tool — none of the incumbents cover both the fake page and the risky payment.
- Privacy + no black box = ethical tech by construction, which aligns with the values of banks, schools, and regulators alike.
Team Vision
- Founder: Zamir Memon, Grade 11, Podar International School — self-taught builder of browser-based software, already shipping.
- Mentor: Shailendra Bajpai — guiding product direction and school outreach.
Why this matters to us: Millions of people are coming online and to payments for the first time. They deserve a checkout that protects them and explains itself — never a silent "declined." We want TrustPay to be the reason the next generation of digital buyers can see when something is wrong, instead of trusting a black box.
Ask: a finalist slot to bring the live prototype to the Grand Finale and show the jury a checkout that talks back in plain language.
Thank You
TrustPay — Buy like a human. Get stopped like a pro.
- Live demo: the Kicks storefront + TrustPay Guard extension
- Source (open, public): github.com/ZamirDev/trustpay
- Contact: [email protected]
Theme: Cybersecurity & Ethical Tech
Note: The demo phishing page is visibly simulated — no real credentials are collected anywhere in the prototype.
Built With
- css
- html
- javascript
- powershell
Log in or sign up for Devpost to join the conversation.