Eight chapters. Two years of iteration. From a rough first detection layer to a platform that protects millions.
The detection pipeline takes shape.
We started with a simple question: can an AI analyze a suspicious URL the way a security analyst would? The first version of our conviction engine was born — a handful of independent layers that evaluated URLs, domains, and content. It was rough, but the architecture that would define everything was already there: structural signals over content signals, evidence over points.
Three feeds. One source of truth.
We integrated URLhaus, OpenPhish, and Phishing.Database into a unified lookup layer. 726,000+ confirmed phishing URLs, 430,000+ domain-level entries, refreshed on every container restart. Combined with Tranco's top 500 trusted domains, we had both the blocklist and the safelist — the foundation for the trust engine that came next.
66 brands. Fingerprinted. Matched.
Phishing sites don't just use similar text — they clone the visual identity. We pre-crawled 66 major brands (banks, government, social media, couriers) and stored their fingerprints: favicon perceptual hash, dominant color palette, page structure. Now, when a page looks like BRD bank but lives on brd-secure-verify.cc, we catch it with structural confidence.
Chrome MV3. Zero friction.
The browser extension became our reach multiplier. Real-time page scanning, popup with instant verdict, one-click deep scan. Auto-login via JWT token exchange means if you're signed into the web app, the extension just works. Safari and Firefox builds share the same codebase — one extension, three browsers.
XGBoost. 44 features. F1 0.904.
We moved beyond rules. Our XGBoost 3-class model (safe/suspicious/phishing) trained on 10,000+ real scans uses 44 features: URL structure, domain age, SPF/DMARC authentication, content signals, and TLD risk. Every Sunday at 03:00 UTC, it retrains automatically on fresh data. Each week it gets sharper — without us touching it.
Natural language understanding at scale.
Rules and ML catch patterns. But scams evolve — new variants, new lures, new emotional hooks. Claude Sonnet became our 8th layer: synchronous LLM analysis for ambiguous cases with a 3-second timeout. It can't override strong conviction rules, but it adds nuance where our other layers see only signals. The result: fewer false positives, richer reasoning.
Pub/Sub webhook. Real-time scanning.
Connect your Gmail account and SentriesAI scans every incoming email through the full conviction pipeline. Phishing attempts, scam campaigns, and brand impersonation get caught before you open them. Push notifications alert you on threats. Multi-account support for users managing personal and work inboxes together.
The platform matures.
React Native mobile apps for iOS and Android. Family plans with parental oversight. Organization dashboards with role-based permissions. Stripe billing with 90-day free trials on all paid plans. Image OCR for screenshot scanning. The scattered pieces became a cohesive platform that works across every way you communicate.
Six chapters. Eighteen months. From collective immunity to real-time voice fraud protection.
everyone is protected.
When a user detects a new scam, every other active user is instantly immunized against the same threat. No blocklist delay. No batch update. Real-time WebSocket push — 'a new threat was neutralized, 347 users protected in the last 5 minutes.' The more users join, the stronger everyone's protection becomes. Backend is 95% ready.
Without them installing anything.
Add your parents' or grandparents' WhatsApp number and SentriesAI auto-scans every message they receive. When a threat appears, both you and they get alerted. The first security product you gift to someone else — the one they don't have to set up, configure, or remember to use. Because the people most targeted by scams are often the least equipped to defend themselves.
Complete parity with the web.
Full feature parity with the web experience: URL scan, text scan, chat history, Gmail integration, recent scans sidebar with live updates, push notifications for threats. Native widgets for iOS and Android home screens. App Store and Google Play launch with zero compromises between platforms.
Three minutes a day.
Gamified training sends you simulated phishing messages across email, SMS, and chat. Can you spot the fake? Short daily sessions adjust difficulty to your real-world scan history. Enterprise vendors charge 50,000 euros a year for this. We're making it available to everyone — starting from day one of your free account.
Waste their time. Save others'.
Detect a scam, then with one click deploy an AI bot that plays a convincing target. It asks naive questions, creates technical problems, tergiversates for hours. You watch the conversation live. The best ones become viral content — and every minute the scammer spends on the bot is a minute they're not targeting a real victim.
Real-time protection against voice fraud.
68% of financial fraud happens over phone calls. On-device AI analyzes live audio for urgency patterns, authority impersonation, and social engineering tactics. A gentle vibration warns you mid-call — before the scammer gets what they want. No one in the world does this yet. We will.
User feedback directly influences our priorities. Tell us what you want us to build, and we'll build it.