- Live
NextAct
Verify before you act.
A decision-support tool for the moment before you click, pay or share a code. It turns a suspicious message, link, document or payment request into claims, evidence, contradictions, unknowns, a risk level and the safest next step.
Scope & stage
The public check, results, history, sharing and deletion run at nextact.tech. NextAct Business, a payment-change guard for finance teams, is an invitation-only preview. The browser extension is built and tested locally but not yet enabled against production.
My role
- I built the case-submission and browser-extension APIs, and the workspace-scoped database access behind them.
- I wrote the evidence collection for URLs, DNS and TLS with server-side request forgery controls, so a submitted link can't be used to reach internal addresses.
- I wrote adversarial API tests and the GitHub Actions checks, plus the Docker and Compose setup.
- I designed the AI adapter interfaces: redaction before a model sees anything, and validation of what comes back.
Architecture
A pnpm monorepo. The web app is thin. Analysis, risk policy and AI access live in separate packages with shared contracts.
Conceptual flow, simplified from the codebase.
Submit
Message, link, PDF, saved email or image, through the site or the extension
Extract
What is being asked: pay, sign in, share a code, change bank details
Collect evidence
URL, DNS, RDAP and TLS lookups behind SSRF controls
Evaluate
Versioned rules produce a risk band, with contradictions and unknowns listed
Explain
An optional AI layer, redacted and validated, that cannot change the band
Next step
Always through a channel independent of the suspicious message
Key decisions
- NextAct never says something is safe. The strongest result is that no material risk was observed and specific facts were verified, with the evidence shown.
- The risk level comes from a deterministic engine. A language model can help explain a result but can never set or raise it.
- Unknowns are first-class output. What couldn't be checked is shown next to what could.
Validation and failure handling
- Unit and adversarial API tests run in CI on every change.
- A production smoke suite checks the live site. The last recorded run passed 133 of 133 checks (28 Sep 2026).
- The extension has its own verification run in Edge, covering popup accessibility.
Limitations and next steps
- Detection figures so far are regression results on cases written by the author. There is no independent accuracy figure yet.
- Analysis is written for English. Text that is mostly Urdu or Roman Urdu is flagged as not read rather than guessed at.
- No penetration test has been performed yet.