Trust & Safety Architecture
1. Executive Summary & Defense-in-Depth Strategy
Debelu operates in a high-risk environment: unvetted student buyers, independent third-party campus merchants, and real monetary transactions. Fraudsters routinely attempt to:
- Divert Payments Off-Platform: Coercing buyers into direct bank transfers (bypassing escrow) to execute exit scams.
- Manipulate Product Prices: Predatory price gouging or extreme underpricing (bait-and-switch listings).
- List Prohibited or Counterfeit Goods: Weapons, stolen electronics, narcotics, and adult content.
- Phishing & Contact Harvesting: Injecting WhatsApp links, obfuscated phone numbers, and bank account numbers into chat streams and product images.
Debelu implements a Defense-in-Depth Trust Architecture:
graph TD
subgraph Ingestion & Edge Gateways
CHAT[Buyer-Vendor Real-time Chat]
PROD[Product Listing & Price Creation]
MEDIA[Image Upload / Media Attachments]
end
subgraph Automated Real-Time Guards
CG[ChatGuardService]
PG[PriceGuardService]
MM[MediaModerationService - Gemini Vision]
end
subgraph Case & Enforcement Layer
MC[ModerationCaseService]
CACHE[Redis Edge Cache Invalidation]
STRIKE[Vendor Strike & Account Restrictions]
APPEAL[ModerationAppealService]
end
CHAT -->|Inspect Text Stream| CG
PROD -->|Calculate Category Median| PG
MEDIA -->|Vision Scan for Watermarks & Prohibited Goods| MM
CG -->|Detect Contact Leak / NUBAN| MC
PG -->|Gouging Ratio >= 3.0x / Underpriced <= 0.1x| MC
MM -->|Flagged Media / Quarantine| MC
MC -->|Action: remove| CACHE
MC -->|Action: remove| STRIKE
STRIKE -->|Vendor Right to Challenge| APPEAL2. ChatGuard Architecture (ChatGuardService.ts)
ChatGuardService ([debelu-backend/src/services/ChatGuardService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/ChatGuardService.ts)) is an automated lexical and contextual scanner guarding all buyer-vendor conversations.
2.1 Threat Vector Detection Patterns
- Nigerian Mobile Numbers (
PHONE_REGEX):regexMatches 070, 080, 081, 090, 091, and +234 prefixes across varied spacing and formatting delimiters./(?:(?:\+?234\s?)|0)[789][0-1](?:[\s.-]?\d){8}\b/g - Nigerian 10-Digit NUBAN Accounts (
NUBAN_REGEX): Matches 10-digit numeric sequences accompanied by financial context cues (/(?:account|acct|bank|transfer|pay|send|nuban|opay|kuda|palmpay)/i). - Fintech & Banking Ecosystems (
FINTECH_KEYWORDS): Detects mentions of Nigerian and international payment apps: OPay, PalmPay, Kuda, Moniepoint, Chipper, Access Bank, GTBank, Zenith, UBA, FirstBank, Fidelity, Stanbic, PayPal, Venmo, CashApp, Zelle. - Direct External Messaging Links (
EXTERNAL_CHAT_LINKS): Detects click-out conduits:wa.me,api.whatsapp.com,chat.whatsapp.com,t.me,telegram.me. - Disintermediation & Offline Payment Intent (
DISINTERMEDIATION_PHRASES): Detects phrases like"pay offline","send to my account","don't pay on debelu","avoid charges","dm me on ig".
2.2 Inline Redaction & Moderation Routing
- Zero Disruption Redaction: The message is delivered with offending fragments replaced by audit-safe placeholders:
- Phone numbers $\to$
[PHONE NUMBER REDACTED] - Bank accounts $\to$
[ACCOUNT NUMBER REDACTED] - External links $\to$
[EXTERNAL LINK REDACTED]
- Phone numbers $\to$
- System Warning Injection: A real-time warning banner is appended reminding users that off-platform transactions forfeit Debelu escrow protection.
- Escalation: When high-severity disintermediation intent is confirmed, a flag is automatically posted to
ModerationCaseService.
3. PriceGuard Architecture (PriceGuardService.ts)
PriceGuardService ([debelu-backend/src/services/PriceGuardService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/PriceGuardService.ts)) prevents predatory pricing, fat-finger mistakes, and fraudulent bait-and-switch listings.
3.1 Median Variance Algorithm
For every category with $\ge 3$ active products:
- Calculates the true Category Median Price ($M$): $$M = \begin{cases} P_{mid} & \text{if } N \text{ is odd} \ \frac{P_{mid-1} + P_{mid}}{2} & \text{if } N \text{ is even} \end{cases}$$
- Computes the deviation ratio: $$R = \frac{\text{Product Price}}{M}$$
3.2 Anomaly Classification Matrix
| Anomaly Type | Condition | Severity | System Action |
|---|---|---|---|
| Gouging (Extreme Overpricing) | $R \ge 3.0$ | Medium ($R < 5.0$) High ($R \ge 5.0$) | Flagged for price audit; vendor required to justify premium or adjust. |
| Suspicious Underpricing | $R \le 0.1$ and $M \ge ₦2,000$ | Medium ($R > 0.05$) High ($R \le 0.05$) | Listing hidden pending verification (mitigating stolen goods / fake listings). |
| Standard Price Range | $0.1 < R < 3.0$ | Low | Allowed without intervention. |
4. MediaModeration Architecture (MediaModerationService.ts)
Product images, vendor storefront banners, and chat attachments are scanned using Google Gemini Computer Vision ([debelu-backend/src/services/MediaModerationService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/MediaModerationService.ts)).
4.1 Vision Inspection Dimensions
The AI evaluates media across four structured vectors:
- Adult & Racy: Sexually explicit imagery, nudity, suggestive content (scores $0.0 - 1.0$).
- Violence & Weapons: Firearms, bladed weapons, illicit drugs, dangerous chemicals.
- Embedded Text & QR Codes: Contact numbers (080, 090), bank account numbers, or QR codes watermarked into images to evade text scanners.
- Product Categorization: Automated verification that the image corresponds to the claimed product category.
4.2 Graceful Degradation & Heuristic Fallback
If the Gemini API encounters rate limits or network degradation, MediaModerationService falls back gracefully to deterministic URL and metadata heuristic scanning (/weapon|gun|knife|xxx|nude|drug/i), logging a warning while quarantining suspicious uploads.
5. Moderation Case & Appeal Lifecycle
When automated guards or user reports flag an entity, ModerationCaseService ([debelu-backend/src/services/ModerationCaseService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/ModerationCaseService.ts)) manages the end-to-end case resolution.
stateDiagram-v2
[*] --> Pending : Flag Created (Guard / Report)
Pending --> HighRisk : High Severity / Risk Score > 0.8
Pending --> Claimed : command('claim') [Staff Locked]
HighRisk --> Claimed : command('claim') [Staff Locked]
Claimed --> Pending : command('release') [Unassigned]
Claimed --> Rejected : command('dismiss') [Content Kept]
Claimed --> Resolved : command('remove') [Content Hidden / Restricted]
Resolved --> [*] : Listing Hidden & Cache Flushed
Rejected --> [*] : Case Closed5.1 Command Discriminated Union & Side Effects
Every staff intervention records an immutable transition receipt:
claim: Assigns case to staff member (claimed_by = actor), locking out concurrent reviewers.release: Relinquishes case back to the general triage queue.dismiss: Rejects the flag with effectcontent_kept.remove: Executes the appropriate domain restriction atomically:- For Products: Emits effect
listing_hidden. - For Reviews: Emits effect
review_hidden. - For Messages: Emits effect
messaging_restricted(locks user out of the conversation).
- For Products: Emits effect
5.2 Real-Time Edge Cache Eviction
When command('remove') executes on a product listing, the service immediately calls:
if (receipt.effect.kind === 'listing_hidden' && receipt.effect.campus) {
await invalidateCampusCache(receipt.effect.campus);
}
await invalidateResponseCache();This ensures hidden products vanish from edge search indexes and campus feeds within milliseconds, preventing further purchases of flagged items.
6. Vendor Strike & Deplatforming Policy
Debelu enforces an automated 3-strike escalation ladder:
| Strike Level | Trigger | Enforcement Action | Duration |
|---|---|---|---|
| Strike 1: Warning | Single ChatGuard violation or minor listing discrepancy | Formal warning in vendor dashboard; mandatory re-acceptance of Terms of Service. | Active for 90 days |
| Strike 2: Probation | Second violation within 90 days | 7-day listing freeze; removal of "Verified Merchant" badge; payout delay increased to 48h. | Active for 180 days |
| Strike 3: Suspension | Third strike or single instance of confirmed wire fraud | Account frozen; all active listings removed; pending escrow held for 90-day chargeback buffer. | Permanent |
Vendor Appeal Rights (ModerationAppealService.ts)
Vendors hold the statutory right to appeal Strikes within 14 calendar days. Appeals require proof of authenticity (distributor invoices, delivery slips) and must be reviewed by an independent staff arbiter who was not involved in the original strike decision.