Two signals, not one
The classifier reads language and intent; the threat feeds read reputation. Either alone produces false positives a user will learn to dismiss — together they are worth interrupting someone for.
Catching the phishing emails that look legitimate, in real time.
Source is private — happy to walk through the architecture on a call.
A Chrome extension pairing a trained classifier with live threat intelligence to score phishing attempts before the user clicks.
Generative models made convincing phishing cheap. Filters tuned on the old signals — bad grammar, obvious spoofs — do not catch a well-written, contextually plausible message, and that is now the common case.
Phishing drives the majority of breaches. Existing tools reliably catch obvious spam, but far fewer catch AI-generated, contextually convincing attacks in the seconds before someone clicks.
The classifier reads language and intent; the threat feeds read reputation. Either alone produces false positives a user will learn to dismiss — together they are worth interrupting someone for.
A warning that arrives after the click is a post-mortem. The extension scores in the reading pane so the decision point and the warning are in the same place.
I am glad to go deeper on the architecture, the tradeoffs, or the parts that did not work the first time. That conversation is usually more useful than the README.