01 / Project case study / 2026
ScamShield
Multimodal threat intelligence
One interface for investigating suspicious emails, URLs, audio and AI prompts. Specialist analysis converges into a risk score and an explanation.
Explore the problem. Follow the system.
02 / The problem
A reason to build.
Suspicious interactions arrive through different channels. Checking an email, a link, an audio clip or an AI prompt should not require a separate tool and an unfamiliar result format each time.
03 / System design
Follow the architecture.
A Next.js interface connects to a Python FastAPI backend with separate processors for email, URL, audio and prompt analysis. Hugging Face models and Librosa support classification and spectral audio analysis; Ollama provides local LLM explanations. Redis coordinates processing, while MongoDB retains scan reports and history.
- 01Email / URL / audio / prompt
- 02Specialist processors
- 03Risk aggregation
- 04Score + explanation
- 05Scan history
04 / Engineering decisions
The choices inside.
- 01
Separate the analysis processors by input type while returning a common risk report.
- 02
Run explanation generation through local Ollama models rather than requiring a hosted LLM for every scan.
- 03
Keep persistent scan history in MongoDB and task coordination in Redis.
05 / Technology
A stack with purpose.
The technologies connecting this system.
- Next.js
- TypeScript
- FastAPI
- Python
- MongoDB
- Redis
- Hugging Face
- Librosa
- Ollama
06 / Engineering outcome
Architecture, applied.
Brings multiple analysis methods into a consistent workflow, with risk explanations and a reviewable scan history. Audio analysis focuses on spectral characteristics; the report is a signal for further investigation.