Muhammad Shahwaiz
  • Live

NextAct

Verify before you act.

A decision-support tool for the moment before you click, pay or share a code. It turns a suspicious message, link, document or payment request into claims, evidence, contradictions, unknowns, a risk level and the safest next step.

Scope & stage

The public check, results, history, sharing and deletion run at nextact.tech. NextAct Business, a payment-change guard for finance teams, is an invitation-only preview. The browser extension is built and tested locally but not yet enabled against production.

My role

  • I built the case-submission and browser-extension APIs, and the workspace-scoped database access behind them.
  • I wrote the evidence collection for URLs, DNS and TLS with server-side request forgery controls, so a submitted link can't be used to reach internal addresses.
  • I wrote adversarial API tests and the GitHub Actions checks, plus the Docker and Compose setup.
  • I designed the AI adapter interfaces: redaction before a model sees anything, and validation of what comes back.

Architecture

A pnpm monorepo. The web app is thin. Analysis, risk policy and AI access live in separate packages with shared contracts.

Conceptual flow, simplified from the codebase.

  1. Submit

    Message, link, PDF, saved email or image, through the site or the extension

  2. Extract

    What is being asked: pay, sign in, share a code, change bank details

  3. Collect evidence

    URL, DNS, RDAP and TLS lookups behind SSRF controls

  4. Evaluate

    Versioned rules produce a risk band, with contradictions and unknowns listed

  5. Explain

    An optional AI layer, redacted and validated, that cannot change the band

  6. Next step

    Always through a channel independent of the suspicious message

Key decisions

  • NextAct never says something is safe. The strongest result is that no material risk was observed and specific facts were verified, with the evidence shown.
  • The risk level comes from a deterministic engine. A language model can help explain a result but can never set or raise it.
  • Unknowns are first-class output. What couldn't be checked is shown next to what could.

Validation and failure handling

  • Unit and adversarial API tests run in CI on every change.
  • A production smoke suite checks the live site. The last recorded run passed 133 of 133 checks (28 Sep 2026).
  • The extension has its own verification run in Edge, covering popup accessibility.

Limitations and next steps

  • Detection figures so far are regression results on cases written by the author. There is no independent accuracy figure yet.
  • Analysis is written for English. Text that is mostly Urdu or Roman Urdu is flagged as not read rather than guessed at.
  • No penetration test has been performed yet.