Skip to content

Trust & Safety Architecture ​


1. Executive Summary & Defense-in-Depth Strategy ​

Debelu operates in a high-risk environment: unvetted student buyers, independent third-party campus merchants, and real monetary transactions. Fraudsters routinely attempt to:

  1. Divert Payments Off-Platform: Coercing buyers into direct bank transfers (bypassing escrow) to execute exit scams.
  2. Manipulate Product Prices: Predatory price gouging or extreme underpricing (bait-and-switch listings).
  3. List Prohibited or Counterfeit Goods: Weapons, stolen electronics, narcotics, and adult content.
  4. Phishing & Contact Harvesting: Injecting WhatsApp links, obfuscated phone numbers, and bank account numbers into chat streams and product images.

Debelu implements a Defense-in-Depth Trust Architecture:

mermaid
graph TD
    subgraph Ingestion & Edge Gateways
        CHAT[Buyer-Vendor Real-time Chat]
        PROD[Product Listing & Price Creation]
        MEDIA[Image Upload / Media Attachments]
    end

    subgraph Automated Real-Time Guards
        CG[ChatGuardService]
        PG[PriceGuardService]
        MM[MediaModerationService - Gemini Vision]
    end

    subgraph Case & Enforcement Layer
        MC[ModerationCaseService]
        CACHE[Redis Edge Cache Invalidation]
        STRIKE[Vendor Strike & Account Restrictions]
        APPEAL[ModerationAppealService]
    end

    CHAT -->|Inspect Text Stream| CG
    PROD -->|Calculate Category Median| PG
    MEDIA -->|Vision Scan for Watermarks & Prohibited Goods| MM

    CG -->|Detect Contact Leak / NUBAN| MC
    PG -->|Gouging Ratio >= 3.0x / Underpriced <= 0.1x| MC
    MM -->|Flagged Media / Quarantine| MC

    MC -->|Action: remove| CACHE
    MC -->|Action: remove| STRIKE
    STRIKE -->|Vendor Right to Challenge| APPEAL

2. ChatGuard Architecture (ChatGuardService.ts) ​

ChatGuardService ([debelu-backend/src/services/ChatGuardService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/ChatGuardService.ts)) is an automated lexical and contextual scanner guarding all buyer-vendor conversations.

2.1 Threat Vector Detection Patterns ​

  1. Nigerian Mobile Numbers (PHONE_REGEX):
    regex
    /(?:(?:\+?234\s?)|0)[789][0-1](?:[\s.-]?\d){8}\b/g
    Matches 070, 080, 081, 090, 091, and +234 prefixes across varied spacing and formatting delimiters.
  2. Nigerian 10-Digit NUBAN Accounts (NUBAN_REGEX): Matches 10-digit numeric sequences accompanied by financial context cues (/(?:account|acct|bank|transfer|pay|send|nuban|opay|kuda|palmpay)/i).
  3. Fintech & Banking Ecosystems (FINTECH_KEYWORDS): Detects mentions of Nigerian and international payment apps: OPay, PalmPay, Kuda, Moniepoint, Chipper, Access Bank, GTBank, Zenith, UBA, FirstBank, Fidelity, Stanbic, PayPal, Venmo, CashApp, Zelle.
  4. Direct External Messaging Links (EXTERNAL_CHAT_LINKS): Detects click-out conduits: wa.me, api.whatsapp.com, chat.whatsapp.com, t.me, telegram.me.
  5. Disintermediation & Offline Payment Intent (DISINTERMEDIATION_PHRASES): Detects phrases like "pay offline", "send to my account", "don't pay on debelu", "avoid charges", "dm me on ig".

2.2 Inline Redaction & Moderation Routing ​

  • Zero Disruption Redaction: The message is delivered with offending fragments replaced by audit-safe placeholders:
    • Phone numbers $\to$ [PHONE NUMBER REDACTED]
    • Bank accounts $\to$ [ACCOUNT NUMBER REDACTED]
    • External links $\to$ [EXTERNAL LINK REDACTED]
  • System Warning Injection: A real-time warning banner is appended reminding users that off-platform transactions forfeit Debelu escrow protection.
  • Escalation: When high-severity disintermediation intent is confirmed, a flag is automatically posted to ModerationCaseService.

3. PriceGuard Architecture (PriceGuardService.ts) ​

PriceGuardService ([debelu-backend/src/services/PriceGuardService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/PriceGuardService.ts)) prevents predatory pricing, fat-finger mistakes, and fraudulent bait-and-switch listings.

3.1 Median Variance Algorithm ​

For every category with $\ge 3$ active products:

  1. Calculates the true Category Median Price ($M$): $$M = \begin{cases} P_{mid} & \text{if } N \text{ is odd} \ \frac{P_{mid-1} + P_{mid}}{2} & \text{if } N \text{ is even} \end{cases}$$
  2. Computes the deviation ratio: $$R = \frac{\text{Product Price}}{M}$$

3.2 Anomaly Classification Matrix ​

Anomaly TypeConditionSeveritySystem Action
Gouging (Extreme Overpricing)$R \ge 3.0$Medium ($R < 5.0$)
High ($R \ge 5.0$)
Flagged for price audit; vendor required to justify premium or adjust.
Suspicious Underpricing$R \le 0.1$ and $M \ge ₦2,000$Medium ($R > 0.05$)
High ($R \le 0.05$)
Listing hidden pending verification (mitigating stolen goods / fake listings).
Standard Price Range$0.1 < R < 3.0$LowAllowed without intervention.

4. MediaModeration Architecture (MediaModerationService.ts) ​

Product images, vendor storefront banners, and chat attachments are scanned using Google Gemini Computer Vision ([debelu-backend/src/services/MediaModerationService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/MediaModerationService.ts)).

4.1 Vision Inspection Dimensions ​

The AI evaluates media across four structured vectors:

  1. Adult & Racy: Sexually explicit imagery, nudity, suggestive content (scores $0.0 - 1.0$).
  2. Violence & Weapons: Firearms, bladed weapons, illicit drugs, dangerous chemicals.
  3. Embedded Text & QR Codes: Contact numbers (080, 090), bank account numbers, or QR codes watermarked into images to evade text scanners.
  4. Product Categorization: Automated verification that the image corresponds to the claimed product category.

4.2 Graceful Degradation & Heuristic Fallback ​

If the Gemini API encounters rate limits or network degradation, MediaModerationService falls back gracefully to deterministic URL and metadata heuristic scanning (/weapon|gun|knife|xxx|nude|drug/i), logging a warning while quarantining suspicious uploads.


5. Moderation Case & Appeal Lifecycle ​

When automated guards or user reports flag an entity, ModerationCaseService ([debelu-backend/src/services/ModerationCaseService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/ModerationCaseService.ts)) manages the end-to-end case resolution.

mermaid
stateDiagram-v2
    [*] --> Pending : Flag Created (Guard / Report)
    Pending --> HighRisk : High Severity / Risk Score > 0.8
    
    Pending --> Claimed : command('claim') [Staff Locked]
    HighRisk --> Claimed : command('claim') [Staff Locked]
    
    Claimed --> Pending : command('release') [Unassigned]
    Claimed --> Rejected : command('dismiss') [Content Kept]
    Claimed --> Resolved : command('remove') [Content Hidden / Restricted]
    
    Resolved --> [*] : Listing Hidden & Cache Flushed
    Rejected --> [*] : Case Closed

5.1 Command Discriminated Union & Side Effects ​

Every staff intervention records an immutable transition receipt:

  • claim: Assigns case to staff member (claimed_by = actor), locking out concurrent reviewers.
  • release: Relinquishes case back to the general triage queue.
  • dismiss: Rejects the flag with effect content_kept.
  • remove: Executes the appropriate domain restriction atomically:
    • For Products: Emits effect listing_hidden.
    • For Reviews: Emits effect review_hidden.
    • For Messages: Emits effect messaging_restricted (locks user out of the conversation).

5.2 Real-Time Edge Cache Eviction ​

When command('remove') executes on a product listing, the service immediately calls:

typescript
if (receipt.effect.kind === 'listing_hidden' && receipt.effect.campus) {
    await invalidateCampusCache(receipt.effect.campus);
}
await invalidateResponseCache();

This ensures hidden products vanish from edge search indexes and campus feeds within milliseconds, preventing further purchases of flagged items.


6. Vendor Strike & Deplatforming Policy ​

Debelu enforces an automated 3-strike escalation ladder:

Strike LevelTriggerEnforcement ActionDuration
Strike 1: WarningSingle ChatGuard violation or minor listing discrepancyFormal warning in vendor dashboard; mandatory re-acceptance of Terms of Service.Active for 90 days
Strike 2: ProbationSecond violation within 90 days7-day listing freeze; removal of "Verified Merchant" badge; payout delay increased to 48h.Active for 180 days
Strike 3: SuspensionThird strike or single instance of confirmed wire fraudAccount frozen; all active listings removed; pending escrow held for 90-day chargeback buffer.Permanent

Vendor Appeal Rights (ModerationAppealService.ts) ​

Vendors hold the statutory right to appeal Strikes within 14 calendar days. Appeals require proof of authenticity (distributor invoices, delivery slips) and must be reviewed by an independent staff arbiter who was not involved in the original strike decision.

Released under Proprietary Enterprise License.