AT.

01 / Project case study / 2026

ScamShield

Multimodal threat intelligence

One interface for investigating suspicious emails, URLs, audio and AI prompts. Specialist analysis converges into a risk score and an explanation.

Explore the problem. Follow the system.

02 / The problem

A reason to build.

Suspicious interactions arrive through different channels. Checking an email, a link, an audio clip or an AI prompt should not require a separate tool and an unfamiliar result format each time.

03 / System design

Follow the architecture.

A Next.js interface connects to a Python FastAPI backend with separate processors for email, URL, audio and prompt analysis. Hugging Face models and Librosa support classification and spectral audio analysis; Ollama provides local LLM explanations. Redis coordinates processing, while MongoDB retains scan reports and history.

  1. 01Email / URL / audio / prompt
  2. 02Specialist processors
  3. 03Risk aggregation
  4. 04Score + explanation
  5. 05Scan history

04 / Engineering decisions

The choices inside.

  1. 01

    Separate the analysis processors by input type while returning a common risk report.

  2. 02

    Run explanation generation through local Ollama models rather than requiring a hosted LLM for every scan.

  3. 03

    Keep persistent scan history in MongoDB and task coordination in Redis.

05 / Technology

A stack with purpose.

The technologies connecting this system.

  • Next.js
  • TypeScript
  • FastAPI
  • Python
  • MongoDB
  • Redis
  • Hugging Face
  • Librosa
  • Ollama

06 / Engineering outcome

Architecture, applied.

Brings multiple analysis methods into a consistent workflow, with risk explanations and a reviewable scan history. Audio analysis focuses on spectral characteristics; the report is a signal for further investigation.