Inspiration
Online scams are becoming increasingly convincing. Fraudulent messages can impersonate banks, electricity providers, employers, delivery services, and even people we know. Many users are forced to decide whether a message is trustworthy without understanding the warning signs.
We built VELORA — Verify before you trust around one simple idea: people need more than a warning. They need evidence, an understandable explanation, and a safe next step.
What It Does
VELORA is an evidence-first digital trust layer designed to help users assess suspicious digital communications.
Its prototype analyzes message content, identifies risk indicators such as urgency, impersonation, suspicious payment requests, and credential theft, then presents a risk score, supporting evidence, and recommended actions.
The goal is not to label everything unfamiliar as a scam. VELORA aims to distinguish observed evidence from assumptions and communicate uncertainty when there is not enough information to make a confident assessment.
How We Built It
We developed a web-based interface with HTML, CSS, and JavaScript, supported by a Python backend. The current analyzer uses local, rule-based analysis to identify suspicious patterns and explain why they matter.
We also prepared an email-ingestion workflow using Agentboxd so incoming messages can be reviewed before users choose to analyze them. Adaption Labs was used to improve our initial threat-analysis dataset. In our first experiment, the platform reported a quality-score increase from 6.0 to 7.4 out of 10 across ten examples.
These experiments establish a foundation for future model-based analysis. The current prototype does not yet represent a fully trained and deployed AI detection model, and the adapted dataset will require further validation.
Challenges We Faced
One of our biggest challenges was balancing useful warnings with false alarms. For example, a message saying “Never share your OTP” is a safety warning, while “Send me your OTP” is a potential credential-theft attempt. A reliable system must understand this difference rather than simply flagging every mention of an OTP.
We also worked on keeping API credentials on the backend, handling email content safely, and designing explanations that do not turn assumptions into facts. Integrating separate services while preserving privacy and keeping users in control added another layer of complexity.
What We Learned
Building VELORA taught us that security is not just about producing a risk score. A useful security tool must explain its reasoning, acknowledge uncertainty, protect sensitive information, and recommend actions that users can verify independently.
We also learned that better dataset quality does not automatically mean better real-world detection accuracy. Meaningful evaluation requires diverse examples, careful testing, and honest reporting of limitations.
What's Next
Our next steps are to validate the adapted dataset, test the service integrations with valid credentials, expand our evaluation data, and investigate model-based analysis. We also aim to improve support for Indian-language scam messages and build stronger evaluation procedures to measure false positives and missed threats.
Our long-term vision is to make VELORA a practical digital trust layer that helps people make safer decisions across messages, emails, and other digital interactions.
VELORA — Verify before you trust.
Built With
- adaption
- agentboxd
- api
- css
- html
- javascript
- labs
- python
- rest
Log in or sign up for Devpost to join the conversation.