T‑Frame "Scam or Safe?"
Go-to-market plan, v2.0
This is the deck, taken deeper. Every slide (S02 to S22) opens up into concrete steps: what to do, which tool, what it costs, and who does it, a Claude agent or a person. Work starts Monday 20 July 2026. Review gates: 19 August, 18 September, 19 October. The plan runs month by month to the end of 2026.
How we mark confidence. Every key number was checked twice: one agent found it with a source, a second agent opened the source and ruled on it. The marks: fact confirmed in the source, vendor a company's own claim, not audited, estimate a modelled or second-hand figure, practice a common industry norm with no hard stat. Of 84 key claims: 25 confirmed word for word, 50 refined (the edits are in the text), 4 turned out wrong (dropped), 5 we could not check. The ledger is in Appendix B.
What changed since the deck (13 to 14 July)
The July 2026 research backed the deck's thesis but moved three things.
Built-in protection has arrived, but it is thin and silent
Chrome now runs a scam detector on the device itself fact. Android has one in 12 countries, but it is off by default fact. So the story shifts from "the window is closing" to "the basic layer is already free and built in." We win on what it does not do: check any format, hold a real back-and-forth, check people and documents, and give a clear verdict you can actually see.
The 2025 official numbers are bigger than the deck's
US FTC: $15.9B in reported losses (up 27%). FBI IC3: $20.9B (up 26%), with a first-ever AI-scam line at about $900M. UK: £1.28B, with 89% of in-scope cases now repaid. We refresh the "size of the problem" slide with these.
Two risks need action in week one
(a) Since 15 January 2026 Meta bans general-purpose AI chatbots on WhatsApp. Our bot does one job, so it likely passes, but we need that in writing before we spend. (b) From 1 October 2026 replies inside the chat window start costing money, so the "almost free per check" math only holds until October.
The market at a glance (2025 official)
The target has not changed
- 500,000 users by month 6 to 9
- B2C free forever
- Four engines: organic (core), influencers (flagship), ecosystems (multiplier), paid (accelerator only)
- Three budgets: $150k / $500k / $1M+ over three months
- One calendar fix: SOC 2 Type I takes 14 to 22 weeks (median 16), not 8 to 12, so the report lands in November 2026.
Week one (20 to 26 July): six from the deck, three new
- Start SOC 2 (pick an auditor and a platform)
- Publish the transparency page and FAQ
- Submit the Chrome extension (review now takes up to 3 weeks)
- First 50 programmatic pages; set an AEO baseline
- Stand up the agent stack; open 5 to 10 micro-influencer chats
- New: Meta Business Verification and a written WhatsApp-bot compliance request
- New: fix the deck, drop the unprovable "7.4M" Scamio figure
- New: put the 1 October bot-cost recount on the calendar
How to read this plan
This is the deck, taken two levels deeper. Every slide (S02 to S22) turns into concrete steps: the tool, the price, the effort, and who does each one, a Claude agent or a person. The short version sits in the executive briefing above. This note explains the ground rules.
Confidence marks
Every key number was checked twice. One agent found it with a source and a date. A second agent opened that source and ruled on it. The marks read: fact confirmed in the source, vendor a company's own claim (not audited), estimate a modelled or second-hand figure, practice a common industry norm with no hard stat. Of 84 key claims, 25 held word for word, 50 were refined (the fixes are in the text), 4 were wrong (dropped), and 5 could not be checked. The dropped and unproven ones are listed in Appendix B.
The realism principle
No invented numbers. If a benchmark does not exist, we say so and set an internal checkpoint instead of a made-up external target. Where a vendor's claim is not confirmed by anyone else (Advantage+ returns, Guardio revenue), the plan leans on our own A/B tests, not on their promises.
The role of Claude
Every step splits the work in two: what the agent does (Claude plus n8n plus MCP) and what stays with a person (anything legal, published, financial, or about a relationship). One rule throughout: the agent prepares, the person approves. The full map of agent loops is in chapter 10.2.
Market: $442B stays the frame, and 2025 makes the case stronger
S021.1 What the data update showed
- United States. The FTC counted $15.9B in reported losses for 2025, up 27% on 2024. Imposter scams (someone pretending to be a bank, agency, or company) are the top category for the fifth year running, at $3.5B, with a $700 median loss fact (CNBC and FTC, 26 Jun 2026). The FBI's IC3 counted $20.9B, up 26%, from over 1M complaints. Biggest losses: investment fraud $8.6B, business-email fraud $3.04B. For the first time there is an "AI-related" line: 22,000+ complaints, about $900M (deepfakes, cloned voices, mass AI phishing) fact (via SpyCloud, since the IC3 PDF returns a 403).
- United Kingdom. UK Finance reported £1.28B stolen in 2025. Unauthorised fraud was £703.4M, down 5%. £1.68B was stopped before it left. That is about 8 victims a minute fact. On repayment of APP scams (where the victim is tricked into sending the money themselves): 89% of cases inside the mandatory scheme were repaid over its first 15 months (PSR dashboard, Oct 2024 to Dec 2025, £243M). A wider UK Finance figure for all of 2025 is 61%. These count different things, so we use 89% with a footnote on scope fact (refined on review).
- Australia. The NASC Targeting Scams report (March 2026): losses above A$2B for the year. People 65 and older are 17.1% of the population but 26.5% of reported losses. Phishing complaints fell to 65,361 (down 33.2%), and text-message scam complaints fell from 77,365 to 29,058 (down 62.4%) as scammers moved to social media fact (the average-loss figure, A$209 to A$476, was not in the full report, so we dropped it).
- Singapore. The police put national losses at S$913.1M for 2025, down 17.9%, with 24.8% fewer cases and 85.2% of victims under 65 fact. ScamShield: 1.53M app downloads, 2.24M site visits fact. One caution: S$913.1M is the country's total loss in Singapore dollars, not "blocked by ScamShield" and not USD.
- Canada. The CAFC logged 112,000+ complaints and losses above C$704M, the worst year on record fact. In March 2026 the country opened consultations on a first national anti-fraud strategy, and Bill C-15 will require banks to hold anti-fraud policies fact.
- Global. There is no single global 2026 report yet (GASA and Feedzai usually publish in October). The 2026 regional ones exist: Europe (75% met a scam in the year), Germany (about €12B lost, €2,619 average), the US with Iris. We keep $442B (2025) as the frame with a footnote and wait for October fact.
- An AI hook for PR. Three numbers for pitches: the IC3 AI line at $900M; Hoxhunt, where the share of phishing emails showing AI traits rose from 4% (Nov 2025) to 56% (Dec 2025) vendor; and the FTC imposter figure of $3.5B. Germany's BKA puts online fraud there above €22B in 2025, up 18% fact (for Tier-2 materials).
1.2 Steps
- Update the stats block in the deck and on the site. Swap the S02 slide lines for the 2025 official numbers (FTC $15.9B, IC3 $20.9B plus the AI $900M, UK £1.28B and 89% with a footnote, Australia above A$2B, Singapore S$913.1M down, Canada C$704M), and keep $442B as the frame. Claude drafts the change with a source link in a comment on each figure; a person approves publishing. Effort: 1 to 2 hours. Cost: 0.
- Five local landing paragraphs. On each market, a local number instead of the global one (US: FTC and IC3; UK: £1.28B, 8 victims a minute; Australia: the 65+ carry 26.5% of losses; Singapore: 85.2% of victims are under 65, which flips the "scams are for the old" cliche; Canada: worst year). Claude writes five paragraphs with footnotes; a person approves each market. Effort: 1 day.
- An "AI scams 2026" press pitch. 300 words on three numbers (IC3 $900M, Hoxhunt 4% to 56%, FTC $3.5B), sent to journalists who cover AI scams, through a Qwoted or HARO tool and directly. Claude drafts the pitch and a list of 15 to 20 journalists with their latest pieces; a person checks and sends. Effort: 3 to 4 hours. Cost: $0 to $300/mo (Qwoted paid tier is optional).
- Auto-monitor for the global report. A weekly agent check of gasa.org/research and feedzai.com. When the global report drops, it sends a short summary and a proposal to update our materials. Fully automatic; a person only confirms edits. Setup: 30 minutes.
- Data-limits hygiene. In the appendix: the FTC and IC3 PDFs do not open automatically (403), so those figures come through second-hand write-ups; there is no 60+ age breakdown in IC3 2025 in the open; currency conversions are not "facts." Claude keeps a register of these caveats next to the source register.
Chapter KPIEvery public number carries a mark and a verified source. The deck is updated by 26 July. The pitch goes out by 31 July.
Product and positioning: how we win against free, built-in tools
S032.1 The white space we confirmed
Looking across every mid-2026 competitor estimate (our reading of verified facts), no single product does all of these at once: (a) one place to check any format, text, link, QR, screenshot, document, a person or contact; (b) a real back-and-forth in one session (Norton Genie makes you paste into a separate app, with no continuous multi-check); (c) checks on identities and documents; (d) a design that works for older users and a "check this for my parent" flow; (e) a clear verdict you can see and understand, not a silent background filter. Two verified facts help: Scamio does no video or deepfake checks, and Truecaller's AI Call Scanner (cloned-voice detection) is paid and Android-only. If T-Frame really checks video and voice, that is a claim we can make. Before each campaign an agent re-checks that the comparison still holds.
2.2 Positioning against "the built-in tool is enough"
- Copy against Chrome and Android. "Chrome and Android catch some calls and links on their own. T-Frame checks text, a link, a screenshot, a document, and a person, in one chat, in 30 seconds." The backing: Android Scam Detection is off by default and only covers calls and texts; the Chrome filter gives no verdict screen and only works in the browser fact. Claude (copywriter skill) drafts three versions plus an A/B plan; a person approves.
- Slogan for the slide and the landing page: "Built-in tools filter. T-Frame answers." It goes on the top line of the landing page and into the first 10 seconds of influencer scripts.
- Mirror Truecaller Family (v1.1, not a launch blocker). In March 2026 Truecaller shipped a free Family Group that alerts relatives to fraud calls vendor. We add a "Share this verdict with someone you love" button after the result (text, WhatsApp, email), 3 to 5 dev-days, and a full "Protect a Parent" loop in chapter 4.
2.3 Product hygiene before any paid program
- One-click cancel and an honest scope. The loudest complaints about Guardio: it keeps billing after you cancel, cancelling is hard, and people expect it to block calls and texts when it does not (PissedConsumer 1.5/5 across 235 reviews, versus 4.4/5 on Trustpilot) fact. So before any paid tier: self-serve cancel confirmed on screen and by email, plus plain scope text in the product ("we check what you send us; we do not block calls automatically"). 2 to 3 dev-days. Claude writes the copy and the spec; a legal or support lead approves.
- Groundwork on the "two ratings" gap. Competitors get praised in the app stores and slammed on complaint sites, mostly over billing. Our answer is a commitments page, one "we do not do this" line per complaint type, built by an agent from the top 50 complaints about competitors. 1 day.
Chapter KPIEvery brief re-checks the competitor comparison with a fresh agent pass no older than 2 weeks. The scope-and-cancel page is live before the first paid experiment.
The competitive window: the July 2026 map, and what to do with it
S04, S06 to S103.1 The verified map
| Player | Where it stands, July 2026 | Mark | What we take or exploit |
|---|---|---|---|
| Guardio | Raised $80M (ION, Nov 2025; the source says "institutional round," not "Series B"). Claims about $100M revenue and roughly 500k paying. Premium $14.99/mo, VIP support $199.99/yr. Grows through affiliate review sites and paid ads. 1.5/5 on PissedConsumer over billing and cancel. | vendorfact | Mine their complaints and fix those pains in our product. Their affiliate model ($65 per sale at Aura is the benchmark) is a template for our own program later. |
| Norton Genie / 360 | Genie folded into "Scam Protection" inside Norton 360. A separate app you paste into. JustUseApp scored its language 0/100 against a 4.8 average. | fact | Our edge: one running chat, no pasting into a second app. |
| Bitdefender Scamio | Free on web, WhatsApp, Messenger, Discord. Unchanged since 2024. No video or deepfake checks. No published usage numbers. | fact | Proof a task-bot can live on WhatsApp after Meta's ban, plus a clear gap on video and deepfakes. |
| McAfee / Malwarebytes | McAfee Scam Detector is paid-plan only. Malwarebytes Scam Guard shipped on desktop in Feb 2026 and claims it stops $1k+ losses in 15% of flags. | factvendor | The "genuinely free, no upsells" argument. |
| Scam.org (GASA + OpenAI) | Launched 12 Mar 2026, 50+ languages, its own AI checker, partners include Malwarebytes, Netcraft, ScamAdviser, Seraph Secure and AARP. Traffic not disclosed. | vendor | A partnership target (see 8.3): join the partner row for a credibility channel. |
| Chrome / Android / Edge | Gemini Nano on the device (about 4 GB) with background scam detection. Android Scam Detection in 12 countries, off by default, on Samsung S26. Google claims 10B call and message checks a month. | factvendor | The basic layer is free, so we sit on top and check the platforms monthly as an awareness tailwind. |
| Truecaller | 450M+ monthly users (Apr 2025), 500M+ total (Mar 2026). AI Call Scanner (deepfake voice) is paid and Android. Free Family Group since Mar 2026. | vendor | Its family alerts are a reference for our "Protect a Parent." |
| ScamAdviser | 4.5M visits/mo (Similarweb, Jun 2026) versus 7.3M by Semrush, 71.5% organic on desktop. Claims it "checks 1M+ sites a month." White-labelled at Get Safe Online. 400+ B2B partners, built over about 10 years. | estimatefact | An SEO benchmark and a page model. Their UK slot is taken, so we aim at the equivalent slot in other markets. |
3.2 Steps
- A living competitor matrix. A Google Sheet: rows are competitors, columns are the 7 jobs from the white space. An agent refreshes the same queries monthly and hands back a diff. A person reads the diff in 10 minutes. Setup: 4 hours.
- A complaint-mining sprint. The agent gathers and sorts the top 50 complaints (PissedConsumer, BBB, Trustpilot aggregators) and turns them into "we do not do this" lines for the FAQ and trust page. A person approves the wording. 1 day.
- Watch the platforms as a tailwind. A monthly agent over blog.google/security and related feeds. Each new built-in feature raises awareness (good for us) and shrinks the "no one protects me" feeling (a risk for us). A 10-minute monthly digest.
- An SEO target for month 6. Aim for 10 to 15% of ScamAdviser's traffic, roughly 450k to 1,000k visits/mo on the low and high reads of its traffic. This is an internal target, not a promise. A monthly log from Similarweb and Semrush.
Chapter KPIThe matrix stays alive and is refreshed monthly. No comparison claim is older than 2 weeks without a re-check.
Growth model: four engines, paced, with viral loops
S054.1 The engine order stays; we add pace discipline
Organic is the core. Influencers are the flagship. Ecosystems are the multiplier. Paid traffic only speeds up what already works. The new rule from the research is about when to turn paid on. Guardio, with a paid funnel and $80M behind it, reached about 500k paying in roughly 7 years vendor: paid alone is slow and expensive. So the rule is simple. Paid campaigns do not start until organic weekly sign-ups have grown 4 weeks in a row (small $500 to $1,000 tests to calibrate cost per customer are fine).
4.2 Calibrating "time to 500k" against real curves
- Truecaller: 10M users by Jan 2013, 100M by Dec 2014, about 5 years from launch to 100M fact. Its engine was a shared contact network that got more useful with every user.
- Guardio: about 1M extension users by Dec 2021 fact, about 500k paying by Nov 2025 vendor. A paid funnel, slow.
- HIBP: press and word of mouth, no share buttons. A screenshot of the blunt verdict ("Oh no, pwned!") spread on its own. A historical marker of about 160k visits a day (2019, dated) estimate.
- ScamAdviser: about 10 years to 400+ B2B partners and 4.5M to 7.3M visits/mo factestimate. Organic is a long game.
Action: a month-by-month pacing chart with those three curves as dashed references (the agent updates it from analytics, 15 minutes a month). If our real curve sits below Guardio's, the slowest of the three, that is the signal to move effort between engines at the next gate.
4.3 Viral loop: a shareable verdict from week 1, referrals from day 61
- The verdict card, built to share. Two or three looks (Scam, Safe, Uncertain), a big badge, one reason line ("Flagged: fake bank domain"), and no personal data or victim text on the public card (the Wordle lesson: share an abstract thing; the HIBP lesson: keep it black and white). Build: an image made with @vercel/og, cached for a year, up to 300 KB (Meta's WhatsApp guide allows 600 KB, so we keep room), sized 1200x630 factpractice. Smoke-test the preview by hand in WhatsApp, Telegram, and iMessage before release. 3 to 4 dev-days. Claude: the card template, copy options, a size check in CI; a person: the visual sign-off and a check that no personal data slipped in.
- Track shares from week 1. Every share link carries a source tag and the user's ref-hash. A weekly "sign-ups from shares" report gives a clean before-and-after for the day-61 referral launch. 1 dev-day.
- Day-61 referrals: two-sided, no cash. For a free product the reward is early access to family features, a "verified protector" badge, and unlocking the family circle at N invites. The verified benchmarks are modest: referral programs convert at a 3 to 5% median (top quartile 8%+), cash rewards convert about 40% better than points, and visible mechanics add about 30% to the share rate fact (ReferralCandy; the popular "two-sided +30 to 50%, K=0.6" claims failed on review and are not used).
- Our internal K target. The reference points are informal estimate: K of 0.15 to 0.25 is "good," 0.45 is above median, 0.7+ is rare; the cycle is 7 to 14 days. Our internal bar: K at or above 0.2 by day 90. If K is under 0.1, referrals drop to a side channel and effort moves to influencers and ecosystems. The agent computes K weekly; a person makes the go or no-go call.
- The "Protect a Parent" loop. Invite a parent to get alerts without making an account, with a consent switch on any history sharing (a check history is more sensitive than location, so it stays private by default). Reference: Life360 grew revenue from $32M (2018) to $371M (2024) on a family invite vendor, though per-invite conversion is not published. MVP: 1 to 2 sprints. Claude: onboarding and consent copy; a person: the product and privacy call on defaults.
Chapter KPIShare tracking is live from week 1. The share of sign-ups from shares shows in the weekly report. The referral call is made at the day-90 gate on data, not taste.
Cases: what we keep after checking, and deck fixes
S06 to S105.1 Deck fact fixes
- S09 Scamio "7.4M reachable": remove it. No source ties 7.4M to Scamio's WhatsApp launch in Australia; the May 2024 announcement has no numbers at all. Honest replacement: "Scamio has not published usage numbers since it launched in 2023." Deck edit: 15 minutes, the agent drafts it, a person approves.
- S06 Truecaller: 429M monthly users is old. Current: 450M+ monthly users (Apr 2025), 500M+ total (Mar 2026) vendorfact. Also, the company says it stopped collecting raw address books around 2012, so the "uploads your contacts" story is history, not a current description.
- S07 HIBP: 46 governments becomes 45. The exact order: Costa Rica #42, Bangladesh #43, Bahamas #44, Bhutan #45 (May 2026) fact. The FBI batch: 630M passwords, Dec 2025, 7.4% never seen before fact.
- S08 Guardio: fix the 2021 baseline. In December 2021 Guardio had "1M extension users" (TechCrunch), not 100k paying. "Series B" is not in the source; correctly it is an "$80M institutional round" fact.
5.2 The deeper lessons
- Truecaller: a data network effect. Every verdict (with consent, anonymized) improves the base, so more checks mean sharper verdicts. Our clean version of that: aggregated signals, never contacts.
- HIBP: an API shaped for partners. Its verified price ladder runs from $4.39/mo (Core 1) to $4,599/mo (Pro 5), plus enterprise with no limit fact. So an API product can start cheap and self-serve. Design rule from day one: a verdict-only endpoint with k-anonymity (checks that reveal nothing about the input), no raw content leaving the system. That is exactly what made HIBP acceptable to Mozilla and 1Password. And a reality check: HIBP's government program has been free for 8 years, so it is a trust channel, not a revenue one.
- HIBP: infrastructure economics. The documented numbers are old (2018: 2.6 cents a day on 141M requests behind a Cloudflare cache; 2022: an egress bill of about US$8k). The lesson is not the numbers but the shape: cache verdicts hard and cap heavy objects, from the start fact.
- Guardio: what not to do on money. Hard cancel, billing after cancel, paid support: our "do not do" list (see 2.3). Their affiliate program does confirm the review-site channel works in this niche fact.
- ScamAdviser: B2B patience. About 10 years to a large B2B network fact. So we treat B2B as a 12 to 24 month track (see chapter 12), not a source of this quarter's revenue.
Organic: programmatic pages, AEO and GEO, Reddit, and a PR flywheel
S116.1 Programmatic pages: the ScamAdviser model, gated against penalties
- A page template built on real computed data. Fields: domain age (WHOIS), SSL type, hosting and IP reputation, a live OSINT verdict, a user-report counter, a "last checked" stamp that auto-updates, and 2 to 3 fact-checked summary sentences. ScamAdviser runs this model over "1M+ sites a month" and avoided penalties, because the pages carry real, unique data fact. Lookup cost: $0.01 to $0.05. 3 to 4 dev-days. Claude: the template, the summary prompt, a QA sample of 50 pages against the source data; a person: template sign-off and a spot-check of 10 pages before the batch.
- The "scaled content" risk is real: Google's March 2026 core update hits whole-site patterns fact. Discipline: batches of no more than 100 to 150 pages a week, and a gate at 50 pages (100% indexed and no drop in impressions for 2 weeks) before the road to 500+. Monitoring: a daily agent check of Search Console that flags "crawled, not indexed" pages older than 14 days; a person decides whether to pause the batch.
- Day 75: go or no-go. There is no reliable "months to 10k or 100k visits" benchmark for a new site in this niche no data. So we promise no external number and set a checkpoint instead: no indexing and no real impressions by day 75, and the budget moves to influencers and ecosystems. The agent writes a one-page memo with the data; a person decides.
- Keyword volumes: only a live Keyword Planner. Tools routinely hide the long tail of "is X a scam" practice. After the ad account opens, the agent builds a seed list and expansions; a person exports the real volumes and CPCs across 5 markets. 2 hours.
6.2 AEO and GEO: what actually gets you cited by AI
- Reddit is about 40% of citations across the big AI engines, and the top 15 domains give 68% fact (5W Index, 680M+ citations). Freshness matters most at Perplexity (content under 30 days old is cited about 3.2x more often estimate). Brand mentions track AI visibility about 3x more strongly than links estimate (Zyppy). Schema markup helps a little, about 10% estimate.
- A "help first" Reddit program. Three times a week, real answers in r/scams and r/personalfinance with genuine help and sources (FTC, IC3), and no product mention for the first 90 days in r/scams (we check each subreddit's rules by hand, since auto-fetching them is blocked practice). Mentions only where tool threads are clearly allowed, always disclosed. Claude watches threads and drafts answers; a person always posts, from a warmed-up account. 3 to 5 hours a week.
- llms.txt: a 30-minute stub, not an investment. The research agrees: AI crawlers barely read the file, and no citation lift is proven fact. We publish a minimal file and move on.
- Measurement: Otterly.ai at $29/mo (30 to 50 prompts, 5 markets, ChatGPT plus Perplexity plus AI Overviews on the plan). Step up to Profound ($99 to $399/mo, prices undisclosed and variable vendor) only once it earns it. Baseline on day 0, measure on day 90. The agent keeps a prompt set of real user questions and writes a monthly delta report; a person reviews it before the board.
- A reality check on clicks: when an AI answer sits in the results, clicks roughly halve (15% to 8% of visits, Pew) fact. So we measure organic in sign-ups and citations, not visits alone.
6.3 The PR data flywheel: a quarterly report
- Copy the Truecaller Insights format (it has worked as a press hook for 8+ years vendor), but do it every quarter: a "Scam Landscape Report" on our own aggregated, anonymous data (check volumes, top categories, a Tier-1 geo cut). One headline number, a market breakdown, a methodology footnote, an on-site interactive, and a wire release ($300 to $800). First issue: day 31 to 60. Claude: the aggregation queries, the report draft, headline options, the release draft, and a long list of journalists; a person: checking every figure (the biggest reputation risk in the whole workstream) and sending.
- Put seasonal hooks in the calendar: US tax season (Jan to Apr; IRS Dirty Dozen around 5 March; late deadline 15 October) and the annual FTC, Cifas, Scamwatch, and CAFC reports (the agent catches the release day, and we pitch the same week).
6.4 Content ops and tools
- Stack: Ahrefs Starter $29 or Lite $129/mo (enough for indexing and positions), Otterly $29/mo, Frase $49/mo to tune editorial content. Semrush ($139.95+/mo) only once we truly need competitive analysis fact (on prices).
- Staffing: one editor and fact-checker for the programmatic pages and the report. We do not assume a pages-per-week rate (no benchmark exists); we measure it on the first batches.
- One gate: no programmatic page ships without a human pass. The risk of a site-reputation penalty is far bigger than the hour saved.
Chapter KPI50 pages by day 30 (the quality gate); 500+ by day 60 only after the gate; an AEO baseline on day 0 and a measure on day 90; the first quarterly report by day 60; the Reddit program with not a single ban.
Influencers: the flagship channel, with deal mechanics we verified
S127.1 Pricing: the formula and the verified ranges
- Rate formula: (average views over 90 days divided by 1000) times the niche CPM times a format multiplier practice (OutlierKit confirms it with a worked example). Verified CPM ranges: lifestyle $15 to $25, tech reviews $25 to $45, personal finance $30 to $60, B2B SaaS and dev tools $40 to $80. The overall $15 to $80 span holds. Note: finance agencies run higher (Creators Agency: a median of about $100 CPM on their finance sample vendor), so we price offers on the low, brand-side end.
- Format multipliers: a dedicated video is 1.3 to 2x an integration (verified: OutlierKit 1.3 to 1.5x, Creators Agency about 2x; the popular "2 to 4x" has no source). Shorts 0.4 to 0.6x. A pre-roll mention 0.7 to 0.8x.
- How we negotiate: open at 60 to 70% of the computed rate (we keep the deck's "first offers 30 to 40% below budget" habit). Our counter to pushback: a rate card built on the average views of the last 10 videos, not on subscriber count.
7.2 Deal structure
- Base: a flat fee plus a trackable code or URL. The verified Guardio and ThioJoe template: a flat fee, a 20% annual discount, and a 7-day trial through a custom URL, guard.io/thiojoe fact (confirmed against the ThioJoe video itself). Attribution runs on unique codes and URLs, the niche standard.
- An affiliate benchmark for phase two: Aura pays $65 per qualified sign-up, a 60-day cookie, through Impact.com, net-30 fact. A reference for our own partner program once a paid tier exists.
- Whitelisting only after proven results: plus 20 to 50% over the base rate for 30 to 90 days of Spark Ads rights (running ads through the creator's own account) practice (aggregated sources; at Lumanu only "51% charge separately" is confirmed). No perpetual rights on a first deal. Repeat integrations beat reach: click-through rises about 10% with each new integration from the same creator vendor (Agentio).
- FTC discipline, written into the contract: disclosure in the first 30 seconds, by voice and text, plus the platform toggle (the toggle does not replace the spoken disclosure) fact. Fines run up to $51,744 per violation, and liability sits with the brand fact. Before we release payment, the agent scans the transcript for the disclosure line and a screenshot of the toggle; a person releases the payment.
7.3 Operations
- Tool: Modash Essentials $299/mo ($199 annual): discovery plus a CRM for 100 creators, 2 seats. Against Grin at about $2.5k/mo and CreatorIQ at about $35k/yr, the choice is obvious vendor (prices).
- List: 30 to 50 creators in three rings: scam-baiters and fraud-explainers (verified starters: Scambaiter about 1.3M, Scammer Revolts about 1.0M, NetworkChuck; counts from 2022, re-check before pitching), personal-finance safety, and elder-tech and family safety. The agent pulls each candidate's last 20 videos through the YouTube Data API (sponsors, average views, CPM tier); a person spot-checks 20%.
- Outreach: 15 to 20 personalized emails a week. A realistic reply rate is 3 to 5% (by analogy to cold B2B, since there is no influencer-specific benchmark estimate), 8 to 12% on deep personalization. The agent writes each email from the creator's sponsor history and recent videos; a person always sends.
- Flagships (Kitboga and the top scam-baiters) come after the micro and mid wave: first 5 to 10 micro pilots on days 0 to 30 test the message cheaply, then a dedicated video from a mid scam-baiter by days 31 to 60, with flagships reserved for the Growth and Aggressive budgets.
- Our own cost-per-sale table from day one: there is no public conversion data for security sponsorships no data. So every deal gets a unique code, a weekly cost-per-creator report, and after 5 to 10 campaigns this is our own negotiation benchmark. Day 90: decide in-house versus agency on the numbers.
Chapter KPI5 to 10 micro chats opened in week 1; first content by day 30; the cost-per-sale table fills from the first campaign; by the day-60 gate at least one dedicated video with a mid scam-baiter is signed.
Ecosystems: stores, bots, partnerships
S138.1 Browser extensions and mobile stores
- Chrome Web Store: submit in week 1, because review takes up to 3 weeks (officially "a few days to several weeks"; April 2026 saw a queue spike fact). Ask for minimal permissions (activeTab, not broad host access), no obfuscation, all code in the package (remote code is banned fact). Rejection plan: fix within 48 hours, escalate through One Stop Support if it repeats.
- The store's privacy deadline is 1 August 2026, when the new rules take effect (data for one stated purpose only, clear disclosure before consent) fact (announced 1 Jul 2026). So our submission must already meet them. Claude writes the data-handling disclosure against the checklist; a privacy owner approves.
- Listing optimization: the title and description decide which ranking "bucket" you land in, and inside the bucket it is weekly users and rating that matter; the top-performer bar is about 4.5 stars practice. Five screenshots of a real verdict, a 30 to 60 second promo video ($200 to $500). A reviews push: an in-app prompt after a confirmed verdict, a reply to 1 and 2 star reviews within 48 hours, a target of 4.5 stars and the first thousand reviews by week 4. Below 4.0, pause new features until it is fixed.
- Audience benchmarks for extensions: Malwarebytes Browser Guard about 11M Chrome users, Guardio about 1.5M vendor, Netcraft about 70k estimate. A realistic ladder for our target.
- Featured and Established Publisher: Featured is granted by a manual Chrome-team review (MV3, privacy, listing quality) and boosts ranking fact; we apply after the first weeks of metrics. Established Publisher means identity verification. The "re-nominate after 6 months" rumor is unconfirmed, so we do not plan around it.
- Platform order: Chrome Web Store, then Edge Add-ons (about 7 business days), then Firefox AMO (about 2 weeks, all dependencies in source), then Safari (an MV3 port, $99/yr Apple Developer) practicefact. Opera and Samsung Internet wait until 10k users, since queues are unpredictable and audiences small.
- iOS: week 2 after the extension launch. Apple's hard rule: you cannot claim "scans viruses or malware" (impossible in the iOS sandbox), so we frame it as a "phishing and fraud checker" fact. Review is 24 to 72 hours, the security category up to 5 to 7 days; TestFlight with 50 to 100 testers before submission; the iOS 26 SDK is required. Google Play: $25 one-time, review up to 3 to 7 days, a Data Safety form covering only user-submitted content, policy deadlines 1 and 15 August fact. Claude generates the privacy labels and Data Safety from the privacy policy; a lawyer checks the claim wording.
- Launch-week monitoring: a dashboard (impressions, installs, uninstalls, crashes). If uninstalls pass 20%, break it down by reviews and logs. The agent checks metrics 4 times a day and alerts on anomalies; the growth lead decides.
8.2 Messenger bots: WhatsApp with two hard dates, Telegram as a viral loop
- Week 1: Meta Business Verification. This is the channel's longest pole: Business Manager, plus a match between legal entity, domain, footer, and policy and your documents. 3 to 7 business days with clean documents, 2+ weeks with any flaws practice. Claude writes the exact footer and policy text and a document checklist; a person uploads and submits.
- Week 1 to 2: a written compliance answer on Meta's ban. Since 15 Jan 2026, general-purpose AI chatbots are banned on the WhatsApp Business API fact. Task-bots with a non-AI core business survive (Scamio keeps running, which we read from its ongoing marketing, not a Meta ruling estimate). Action: a written request to the provider's compliance team (360dialog or Twilio) describing the bot's single job; keep a copy of the reply on file; keep the bot's public copy strictly about "scam check," never an open "ask me anything." Context: Italy suspended Meta's policy, Brazil's CADE opened an investigation, and in Europe Meta is discussing allowing general-purpose bots at €0.049 to 0.1323 per message fact.
- Economics: the free window runs until 1 October 2026. Today: a user messages first, which opens a 24-hour service window, and verdict replies inside it are free; a click-to-WhatsApp ad (CTWA) opens a 72-hour free window fact. But on 1 Jul 2026 Meta announced that from 1 Oct 2026 in-window service messages become paid, at utility-like rates fact. Actions: (a) calendar a September recount of the bot's unit economics against the live rate card; (b) an alert at $0.01 per check; (c) keep the Telegram bot as a free alternative and web chat as a fallback. Exact rates come only from Meta's live CSV, since the blog write-ups contradict each other checked.
- Provider (BSP): 360dialog at about €49/mo per number with no markup on messages (fine for an MVP up to about 50k chats/mo) versus Twilio at about $0.005 per message with no base fee. The agent builds a cost model for 3 volume scenarios; a person signs. Meta tiering: start at 1k unique contacts a day, growing automatically to unlimited with good quality practice.
- CTWA pilot: UK first. Verified benchmarks exist only for the UK and US (UK CPM €7 to 12, cost per conversation €0.80 to 1.80; the US is pricier; no data for Australia, Canada, or Singapore vendor). $500 to $1,000 over 2 weeks, to learn the cost of an opened chat and the conversion to a first verdict; scale only on real numbers.
- Telegram: inline mode from day one. The viral move: type @tframebot then a link in any chat, and it returns a verdict card with the bot's name, without adding the bot to the chat fact. The Bot API is free, and a claimed 400M users interact with bots monthly vendor. 2 to 3 dev-days for the inline handler. Mini App Store featuring comes after traction. No precedent of a scam-checker reaching millions on inline virality was found: this is an honest experiment, not a copy of someone's win no data.
- Messenger: clone the WhatsApp bot on the same webhook (reuse the verification); re-check policy before building, since no ban like the WhatsApp AI one was found estimate. 1 to 2 dev-days. Discord: no directory, so seed by hand into 5 to 10 large scam-awareness servers by reaching out to admins, written by a person.
8.3 Partnerships: banks, GASA, government programs, grants
- UK banking context (our trump card in the pitch): banks must now repay APP scams (where the customer is tricked into paying) up to an £85k cap, split 50/50 between the sending and receiving bank, decided within 5 days fact. The PSR review (July 2026): APP losses down 21%, the repaid share up from 54% to 65%, and the cap touching under 1% of cases fact. PSR duties move to the FCA (announced Mar 2025, confirmed Apr 2026), with a consultation in December 2026 fact. Banks are already building their own: Lloyds is launching Scam Check (68% of Lloyds fraud reports are shopping scams, most starting on Meta platforms fact, wording refined), and since January 2026 Revolut catches a "call claiming to be from Revolut" in the app fact. The NatWest and Malwarebytes bundle closed in May 2024, so do not cite it as a live example fact.
- The pilot pitch is fraud ops, not innovation. The verified Featurespace path skipped accelerators and went straight to bank teams (first major bank NatWest in 2019; a Pay.UK pilot found an extra £138.7M of APP fraud fact). Our move: a free 4-week read-only pilot of a "paste before you pay" widget for a challenger bank's fraud or consumer-protection team (Monzo, Starling, Revolut), pitched on the numbers of the bank's real repayment cost center. Claude: a one-pager, an ROI model on repayments, contact search, email drafts; a person: sending and negotiating. 10 to 15 warm intros a week.
- SOC 2 is the pass into the bank pipeline: 98% of the Fortune 500 and 99% of the financial sector ask for SOC 2 Type II in due diligence, and a security review adds 2 to 3 weeks to the deal fact. Full timing and cost in chapter 13. Pilots can run alongside the process; the gate is usually "process started, Type I on the way."
- GASA and Scam.org. Pricing is undisclosed ("flexible pricing") fact. This week: a letter asking for a Supporting-tier quote, and in parallel an application to the Scam.org partners (cybersecurity tier, the same row as Malwarebytes, Netcraft, ScamAdviser). Summits for networking in 2026: San Francisco 2 to 3 September, Bangkok 10 to 11 November fact. We commit no budget until we have a quote.
- Government and NGO channels. The UK "Check a Website" slot is taken by ScamAdviser (with Cifas and Barclays as supporters fact), so we do not fight it; we copy the model in other markets. US: the Cybercrime Support Network, entered through sponsorship (Zelle did it as lead sponsor, on a $1M DHS grant fact); we offer a free API widget for FightCybercrime.org in exchange for co-branding. Australia: IDCARE Organisation Support Services, a direct request for terms. Singapore: no open partner API was found for ScamShield no data, so we promise no integration and position as a complement (see chapter 11).
- Grants. A live example: Google.org gave $2M to Singapore's SG ScamWISE to protect 100k seniors and young people from AI scams fact; the AI Opportunity Fund APAC gives 59 grants from $500k fact. Action: apply to the APAC track with the Singapore case (the agent writes the story and budget from real product data, a person signs). UK: Innovate UK Cyber Scale closed 10 Jun 2026 and Smart is paused, but Innovation Loans £100k to £5M (repayable) are open fact; a monthly agent watches for new competitions. Grant decision timelines are unconfirmed, so the plan does not lean on grant money.
- Telecom: no exclusives in year 1. The Hiya and AT&T and Truecaller and operator deals are undisclosed multi-year enterprise contracts fact. Until 100k+ users, only light co-marketing (mentions in operators' scam-awareness mailings); the full conversations come after traction.
Chapter KPIChrome submission in week 1, the extension live by the day-30 gate; Meta verification and the compliance reply on file by day 14; the Telegram bot with inline by day 30, the WhatsApp bot by day 45 (after the written compliance reply); the first bank pilot chat by day 61 to 90; the GASA quote in hand by day 30.
Paid traffic: an accelerator, under hard gates
S149.1 Policies matter more than bids
- Google Ads Misrepresentation is a minefield for anti-scam creatives. Banned: hints of government or brand backing, inflated accuracy claims, fear-based creatives around bad life events, and fake system alerts fact. Serious breaches get a ban with no warning; a lighter "misleading representation" gets a 7-day warning fact. False data at Advertiser Verification (updated 4 Nov 2025) gets an instant ban fact. Actions: a pre-flight checklist on every ad line (the agent checks each creative against the banned list and cites the rule; a person approves the batch), and Advertiser Verification with real documents in week 1.
- Warm up the accounts: the first 1 to 2 weeks, run neutral campaigns at $20 to $50 a day to build clean history before scaling any scam messaging (2026 enforcement can flag and pull ads after the fact vendor). $300 to $700 for the warm-up.
9.2 Channels and verified rates
| Channel | Verified benchmark | Our move |
|---|---|---|
| Google Search | No public CPC for our queries (the info-tail does not show up in reviews) checked | A live Keyword Planner after account verification; intent campaigns on "is this website legit" and brand defense. |
| Meta | Median CPM about $14.19 (an e-commerce proxy), US about $20 to $23; no public 45+ age split estimate. The "Advantage+ 3.14 vs 2.70 return" claim turned out to be one agency's case, not a Meta report, so we drop it checked | Our own A/B: Advantage+ versus a hand-built 45+ safety audience, $500 to $1,000 each, 2 weeks, measured on cost per active user. |
| TikTok | CPM $4 to $13 on plan; targeting 45+ "barely works" per independent notes estimate; no Smart+ data for utility apps | We do not buy 45+. We test 18 to 34 with a "check this for your parents" angle, tied to the influencer engine and Spark Ads. |
| YouTube | Skippable CPV $0.03 to $0.12, non-skip CPM $7 to $15, bumper $5 to $10, blended $5 to $20 (up to $40+ in hot niches) fact (RichAds guide; the finance CPV sub-range is unconfirmed) | Positive-placement targeting on 30 to 50 scam-baiting channels (TrueView in-stream, not Video Action, which has no positive placements fact); a $1.5k to $3k test. |
| Finance proxy cost per lead $15 to $50 practice; whether r/scams is targetable in Ads Manager is unconfirmed from outside (NSFW, quarantine, moderator opt-outs) practice | First, check by hand whether r/scams is available in the picker; fallback to r/personalfinance and r/cybersecurity; a $500 to $1,000 test. |
9.3 Measurement
- Attribution: AppsFlyer Growth gives 12,000 free attributed conversions in year one, then $0.07 each fact. The agent models when we hit the cap under different growth curves and folds the overage into the cost-per-customer math. There is no public cost-per-install benchmark for security apps checked, so we build our own.
- A $6 kill switch: a weekly dashboard of cost per active user by channel (not by campaign). Any channel above $6 for two weeks running gets auto-paused with the agent's recommendation; a person decides. Target: $2 to $4.
- Geo holdouts are not for our size: an honest test needs hundreds of thousands of conversions per arm practice. Until month 6+ we use directed pause tests instead (switch off a big channel for a week and read the change in sign-ups as a direction, not proof).
Chapter KPIA paid channel opens only after 4 weeks of organic growth; the day 31 to 60 tests bring cost per active user under $4; above $6 after optimization, the budget moves to organic and creators (the deck's rule, kept).
The agent machine: seven workstreams, one stack, real guardrails
S1510.1 The stack and verified prices
| Layer | Tool and plan | Note |
|---|---|---|
| Orchestration | n8n Cloud Starter €20/mo (2,500 runs), Pro €50 for 10k | Active-workflow limits are gone; you scale on runs fact. |
| Reasoning | Claude API: Opus 4.8 $5 in / $25 out per M tokens, Sonnet 4.6 $3 / $15, Haiku 4.5 $1 / $5 | Prices from the claude-api reference. Route: Haiku for mechanical work, Sonnet for content, Opus for synthesis and judging. |
| Outreach | Clay Launch $167/mo (the price page contradicts itself, the FAQ says $185 fact); Instantly Growth $47/mo | Real Clay bills grow on overages, so budget the actions in advance practice. |
| Content and AEO | Frase $49/mo; Otterly $29/mo; Ahrefs $29 to $129/mo | AirOps dropped, since its status and prices are unconfirmed checked; replaced by Frase plus our own Claude pipelines. |
| Creative | HeyGen pay-as-you-go (about $1.5 to $3 per 30-second video) or Runway $12 to $15/mo; ElevenLabs Creator $22/mo; Midjourney $30/mo; Canva Pro $15/mo (Grow 2.0) | Start on the minimal plans, upgrade by volume. A human gate is mandatory. |
| Platform agents | TikTok Ads MCP: works, price not stated factno data; Meta Muse Spark API $1.25 / $4.25 per M tokens fact | Keep the TikTok MCP read-only for the first 2 weeks; test Muse Spark against Haiku on cheap bulk tasks. |
| Creator discovery | Modash $199 to $299/mo | See chapter 7. |
Stack total: about $240 to $350/mo for the core (n8n plus Clay plus Instantly), about $600 to $1,000/mo by month 5 with every loop running. Against the $10k+/mo agencies we do not hire.
10.2 Governance: production lessons we take seriously
- Failures are real. 88% of organizations running AI agents reported at least one security incident, and loops that burned $47k in 11 days are on record practice. Our guardrails from week 1: (a) trace every run (prompt, model, tool calls, action) into a cost log; (b) daily spend caps of $20 to $50 per workstream; (c) a loop detector, so the same request 3+ times an hour triggers an auto-stop and alert; (d) an auto-pause if spend runs 50% over the 7-day average; (e) a weekly one-hour incident review.
- The "agent does, human approves" split across all 7 deck workstreams:
| Workstream | The agent (Claude) does | The human gate (required) |
|---|---|---|
| Content factory | Drafts, fact-checks against sources, SEO tuning | Legal and claims review, publishing |
| Programmatic SEO | Builds pages from data, QA samples, Search Console monitoring | Template sign-off, spot-check, batch launch |
| AEO and GEO | Prompt sets, measurements, delta reports, Reddit drafts | Strategy calls; on Reddit only a person posts |
| Ad creatives | Variants, policy check, rotation, weekly analytics | Offer, budget, brand safety, turning campaigns on |
| Influencer outreach | Discovery, rate math, personalized drafts, disclosure scan | Sending emails, the contract, releasing payment |
| Community monitoring | Watches threads and mentions, drafts replies | Every post; crisis PR only a person |
| Analytics | Dashboards, cohorts, K-factor, cost per customer, pacing chart, pause suggestions | Budget decisions, gates |
10.3 The automation compliance perimeter
- LinkedIn: the official API only (MDP approval), no browser scraping, since enforcement has tightened factpractice. X: $0.20 per post with a link since 20 Apr 2026, and write endpoints cut from self-serve fact. We deprioritize the channel.
- Cold email: CAN-SPAM in the US (identify yourself, offer unsubscribe); opt-in only in the EU. From 2 August 2026 the EU AI Act's transparency rules apply to AI-written outreach in the EU fact. So we geo-check the recipient in n8n before sending, and add a disclosure line for the EU.
- Platform rates and limits are wired into n8n guards (for example, 1 post an hour max per account, with buffers to the API limits).
Chapter KPINot one unauthorized public action by an agent; the cost log is complete; the monthly stack bill stays inside the scenario budget; zero "a loop burned the budget" incidents, thanks to the caps.
Geography: launch order and regulatory hooks
S1611.1 Launch order within Tier-1
- United States (the anchor, weeks 1 to 4): the strongest official numbers (FTC $15.9B, IC3 $20.9B). Main press hook: tax season (Jan to Apr, with a second wave by the 15 October late-filing deadline, around our day 90) and IRS Dirty Dozen (around 5 March) fact. Partner anchors: AARP (they have no automatic checker, only a tracking map and a helpline fact) and a CSN sponsorship.
- UK (in parallel, weeks 1 to 4): the PSR and FCA news cycle and the Online Safety Act (fines up to £18M or 10% of revenue for fraud harm fact), plus Cifas Fraudscape (444k cases; fraud is 45% of all crime in England and Wales fact). Localization: spelling, plus HMRC, TV licence, and parcel smishing examples. 1 to 2 days of copy work.
- Australia (month 2): hook: the NASC report and the SPF wave. A verification note: SPF does not create automatic reimbursement up to A$3,000 (that was refuted); SPF means civil penalties (Tier 1 up to about A$50M) and complaints through AFCA, and the full start date is not officially confirmed (sources split between Jul 2026 and Mar 2027) factchecked. We build the B2C message on 65+ losses (26.5% of losses) and aim B2B talks at the SPF milestones.
- Canada (month 2, on the US PR tail): "the worst fraud year," a national strategy in consultation, and Bill C-15 for banks fact. English content carries over from the US. Quebec and French are a separate phase, not months 1 to 6.
- Singapore (month 3, carefully): position strictly "on top of ScamShield." The SRF cascade (bank, then telecom, then consumer) has run since 16 Dec 2024 and only for phishing scams; authorized payments (investment, romance, pig-butchering) sit outside it fact. So our line is "ScamShield filters messages; T-Frame checks the investment platform and the profile, which sit outside the SRF." A separate ABS measure from 15 Oct 2025 delays transfers over 50% of a balance at S$50k+ fact. No integration claims without GovTech confirmation.
11.2 Localization: one master copy, variant lists
US English is the base. The UK, Australia, Singapore, and Canada each get a variant list: local spelling plus 5 to 10 real local scam examples from regulators, with links. About one person-week for all four markets. Claude gathers examples from the FTC, Cifas, Scamwatch, CAFC, and SPF and writes the variants; a marketing person approves (a wrong example naming a brand carries a defamation risk). Quebec French and German are a full translation, a Tier-2 phase.
11.3 Tier-2 watch (months 4 to 6, light touch)
- UAE: the central bank banned SMS one-time codes as a sole login factor (fully phased out by 31 Mar 2026) and requires real-time scoring fact. Banks need consumer anti-fraud tools, so a pilot pitch after traction.
- Germany: the BKA counts €22B of online fraud in 2025 fact. Entry needs full German and a GDPR-first message; variant lists will not cut it.
- Philippines: GSMA says 52% have met a scam vendor. A fragmented market with low ability to pay, so entry only through a telecom partner, not organically.
- Action: a quarterly watch note by the agent; a person decides the timing.
Chapter KPIUS and UK live by the day-30 gate; Australia and Canada by day 60; Singapore by day 90 with clean positioning; not one government-integration claim without written confirmation.
Monetization: B2C free, three B2B streams on a realistic clock
S1712.1 The main realism fix
The verified precedents (ScamAdviser took about 10 years to build a large B2B network; the HIBP government program has been free for 8 years fact) say the first paid B2B deals realistically close 12 to 24 months after launch, not in months 6 to 9. So the B2B tracks start on days 61 to 90 as pipeline building, and we book no B2B revenue into the 2026 plan. The agent keeps a "touch, then pilot, then deal" tracker so we have our own cycle numbers by 2027.
12.2 Stream 1: a threat-intel feed for banks and insurers
- What we sell: an anonymized real-time feed (new phishing domains, message templates, swapped bank account numbers). There are no public price benchmarks for bank contracts, since Feedzai, BioCatch, ThreatMetrix, and Featurespace only quote under NDA fact. So we do not invent a price; we go through pilots.
- How we sell: a one-page data sheet on the Web Risk Enterprise model (90 days of anonymous stats: volumes, verdict spread, false-positive rate, latency), aimed at the fraud teams of mid-size regional banks with no enterprise vendor. 10 to 15 warm intros a week through Sales Navigator ($99/mo). Claude: the data sheet, contact lists, drafts; a person: every email and any data agreement.
12.3 Stream 2: a white-label engine for telecoms, ISPs, and banks
- The F-Secure and Bitdefender model: revenue share with no prepayment, though the rates are confidential fact. Our move: a 90-day free pilot that embeds the checker into the existing security bundle of 2 to 3 regional operators in Tier-1 markets where F-Secure or Bitdefender is not already the incumbent. We discuss revenue share after the pilot data.
12.4 Stream 3: a threat-intel API (self-serve)
- Verified price anchors: Google Web Risk: 100k lookups/mo free, then $0.50 per 1,000 (Lookup) and $50 per 1,000 combined with the Update API fact; urlscan.io: a $5k/yr API plan, $12.5k to $50k/yr pro tiers fact; IPQualityScore $99 to $999/mo fact; APWG eCX: entry from $1.5k (Accredited Reporter), $2.5k to $7.5k corporate tiers, with $15k the top Premium, not the entry ticket fact (refined); VirusTotal: commercial prices undisclosed, second-hand estimates $20k to $50k/yr estimate.
- Our v1 ladder: free 5k to 10k lookups/mo for eval integrations, then metered below the VirusTotal estimates, then enterprise on request. OpenAPI docs, a status page, an SLA. Stripe metered. 3 to 4 dev-days plus a day for copy. Data leaves only as verdict-only, with k-anonymity.
- We budget the engine's own inputs up front: the free OpenPhish feeds (12-hour, non-commercial license) get swapped at commercial launch for a paid subscription (price on request fact); Web Risk lookups in our own pipeline follow the anchors above.
12.5 Grants and Verified Sender
- Grants: an application to the Google.org AI Opportunity Fund APAC (on the SG ScamWISE $2M and ASEAN Foundation $5M precedent fact) with a Singapore focus. Decision timelines are unknown, so it is not on the critical path.
- Verified Sender: only behind the deck's hard guardrails. The price anchor, Meta Verified Business at $14.99 to $349.99/mo per channel fact, shows the market will pay for verification, but our badge is not for sale. Only KYB checks (company registries, domain, DNS, SPF, DKIM), OpenCorporates API $0 to $200/mo. We reconsider paid status after our own audit framework.
- Anti-pattern confirmed: never refer victims to recovery services.
Chapter KPIThe API docs page and free tier live by day 90; the first bank pilot chat by day 90; our own deal-cycle tracker kept from the first touch; no B2B revenue promised in 2026.
Trust architecture: certifications, privacy, transparency, on real timelines
S1813.1 SOC 2: the plan's main calendar fix
- Type I is a 14 to 22 week full cycle (median 16), not "8 to 12 weeks." The check showed that 8 to 12 weeks is only the auditor's testing window after the controls are ready; the full cycle from kickoff to report is twice that fact (refined on review). Start 20 to 25 July, and a Type I report realistically lands in November 2026. So the day-30 gate holds "process started, platform live, auditor chosen," not "Type I ready."
- Type I all-in cost: $28k to $58k (median about $42k), covering the platform, the auditor, remediation, and about 320 internal hours practice. The clean platform-plus-auditor bundle, without internal hours, is $10k to $20k. Type II is an observation window after Type I, budget $15k to $35k, with full readiness for bank due diligence in mid-2027 practice (the first research's "$50k to $150k and 9 to 15 months" was corrected on review to the startup range of $25k to $80k+ and 6 to 12 months for the Type II cycle).
- Week 1: send an RFP to three auditors and pick a platform (Vanta, Drata, or Secureframe), judged on integration speed and Type I price, decided by 26 July. Claude writes the RFP, the scoring rubric, and policy drafts (access control, incident response, vendor management) and fills the platform's evidence tasks; a person runs the calls, signs, and attests the controls to the auditor.
13.2 GDPR and data residency
- EU and UK representatives (Article 27): appoint in week 2. Budget guide: $500 to $1,500/mo for both vendor (the EU-rep range is unconfirmed against primary sources, so get EDPO, VeraSafe, and DPO Consulting quotes directly). A penalty precedent for not having one: €525k (Locatefamily, Netherlands) fact. An outsourced Data Protection Officer if needed: €2k to €5k/mo fact.
- DPIA on the check flow (week 3): a data map, user input to analysis to anonymized result, with no message storage; a free CNIL or ICO template; a one-page summary on the privacy page. Claude writes the sections from a code review; a lawyer signs.
- Hosting: for the B2C launch, Hetzner (Germany, GDPR-compatible, the cheapest, about €9 to €30/mo at the start factpractice). We keep Swiss Exoscale as a premium signal for bank pilots (many times pricier estimate, figures unconfirmed against primary sources). The deck's "EU and Swiss residency" claims stay honest: EU residency from day one, Swiss on an upgrade.
13.3 Transparency and vulnerabilities
- Transparency report: a more careful format than in the first research. The review lesson: Proton's "100% refusals" applies only to the VPN, while its mail service fulfills thousands of orders a year fact. So our report is aggregated and product-honest (how many requests, how many fulfilled or declined, which data types), with no marketing absolutes. A "Transparency: H2 2026" stub page ships in week 1 (requests: 0); the first full issue is January 2027.
- Vulnerability disclosure: a security.txt file (at /.well-known/) plus a self-hosted disclosure form from week 3 (free), with a 72-hour triage promise. A managed platform (about $10k/yr, HackerOne or Bugcrowd starter) only once reports run 2+ a week practice.
- A named security advisor (weeks 2 to 3): a FAST template, 0.75 to 1.5% equity with 2-year vesting and a 3-month cliff practice. Claude prepares the pitch and a terms summary; the CEO runs the calls. Legal review about $500.
- ISO 27001: after SOC 2, planned for 2027. Year-one budget $10k to $50k (do-it-yourself versus auditor-led), with the 2026 auditor day rate about £1,500 fact (refined). Over 60% of enterprise buyers already require ISO or equivalent estimate, so it stays on the roadmap for Q2 to Q3 2027, with the agent mapping SOC 2 controls to ISO in advance.
Chapter KPIThe auditor is chosen by 26 July; the compliance tracker (board plus budget list) is live from week 1; the transparency stub and security.txt are up by day 14; the DPIA by day 21; EU and UK reps appointed by day 30.
Execution calendar: 20 July to 18 October 2026, and through year-end
S19 and S2214.1 Week by week, Foundation phase (days 0 to 30, 20 Jul to 19 Aug)
| Week | Key actions | Owner loop |
|---|---|---|
| W1: 20 to 26 Jul | SOC 2: RFP plus platform (decision 26 Jul). Transparency stub, security.txt, and company FAQ. Submit the Chrome extension (privacy declaration under the 1 Aug rules). Meta Business Verification plus the WhatsApp-bot compliance request. Google and Meta Advertiser Verification plus the start of account warm-up. Agent stack: n8n plus the governance loop (traces, caps, loop detector). First 50 programmatic pages to staging. AEO baseline (Otterly, prompt set 30 to 50). Modash plus a list of 30 to 50 creators, first 5 to 10 emails. Deck fix (2025 stats, remove 7.4M). Verdict share card: build starts. | All loops start; human gates per the chapter lists |
| W2: 27 Jul to 2 Aug | 50 pages to production after the spot-check. Search Console monitoring on. Telegram bot with inline: build. iOS and Android submissions prepared (TestFlight 50 to 100 testers). EU and UK GDPR reps: selection. Security advisor: short-list and first calls. Micro-influencers: 15 to 20 emails a week. GASA: quote request plus the Scam.org partners application. Keyword Planner: real volumes across 5 markets. | Organic, stores, trust, influencers |
| W3: 3 to 9 Aug | DPIA complete. Disclosure form live. Telegram bot to production plus iOS and Google Play submission. First micro-deals signed (target: 3 to 5 of 5 to 10 chats). Share card in production with tracking. CSN, IDCARE, NCPC: partner letters sent. Edge Add-ons submission (if Chrome approved). | Bots, stores, partnerships |
| W4: 10 to 16 Aug | First influencer content ships. Store reviews push launched. WhatsApp bot: build after the written compliance reply (or escalate the question). Programmatic pages: batch 2 (+100 to 150) on a clean gate. Ad pre-flight checklist ready; micro CTWA UK tests $500 to $1,000. US and UK landing variants live. | Influencers, paid, geo |
| Gate G1: 19 Aug (day 30) | KPI: 25,000 sign-ups. Deck thresholds: under 15k, rebuild the channels; over 40k, speed up the budget. Gate checklist: extension live in the Chrome store; 50+ pages indexed; Telegram bot live; 3 to 5 creator deals; SOC 2 in process (not a report); trust pages live. Trust questions in the first 10 creator chats? If yes, grow the trust program before scaling spend (deck rule). |
14.2 Traction phase (days 31 to 60, 20 Aug to 18 Sep)
| Week | Key actions |
|---|---|
| W5 to 6: 20 Aug to 2 Sep | WhatsApp bot to production (if compliance is fine), CTWA UK pilot on data. SEO toward 300+ pages in gated batches. First quarterly Scam Landscape Report: gather data and draft. Meta A/B: Advantage+ versus manual 45+ ($1k to $2k). Australia and Canada landings and a PR tail. GASA summit in San Francisco (2 to 3 Sep): attend if the quote is in hand. Referrals: instrumentation ready (UI by day 61). |
| W7 to 8: 3 to 18 Sep | Report published, plus wire and pitches (the agent catches regulators' report release dates). Mid scam-baiter dedicated video: signed and in production. YouTube pre-roll test on scam-channel placements ($1.5k to $3k). Recompute WhatsApp economics for 1 Oct (live rate card). Singapore landing with SRF positioning. Bank data sheet ready, first 10 to 15 intros a week. Second batch of micro and mid creators. AppsFlyer: watch the free cap. |
| Gate G2: 18 Sep (day 60) | KPI: 120,000 cumulative. Check: cost-per-active tests under $4; SEO indexing healthy (else the day-75 memo on 3 Oct decides how to redistribute); the first B2B pipeline filled; referrals ready to launch. |
14.3 Scale phase (days 61 to 90, 19 Sep to 18 Oct)
| Week | Key actions |
|---|---|
| W9 to 10: 19 Sep to 2 Oct | Referrals live (two-sided, no cash). Double down on the winning channels from the G2 data. First bank pilot chat (target: a verbal OK on a 4-week read-only pilot). On 1 Oct WhatsApp pricing takes effect: the recomputed economics apply, and on bad math traffic moves to Telegram and web. Google.org APAC application submitted. |
| W11 to 13: 3 to 18 Oct | Day-75 SEO memo (3 Oct): go or no-go on scaling more pages. AEO day-90 measure against the baseline. US tax late-deadline (15 Oct) PR wave. API docs page plus free tier live. Tier-2 watch note. Prep the G3 report. |
| Gate G3: 19 Oct (day 90, Monday) | KPI: 250,000+, on track to 500k by month 6 to 9. Decisions: the Q4 scale mix; the budget scenario for next quarter; the fate of referrals by K-factor (0.2 or above, expand; under 0.1, fold into the background); the B2B pipeline, how many pilots are in flight. |
14.4 November and December 2026 (month by month)
- November: the SOC 2 Type I report (at the median 16 weeks from start); the GASA summit in Bangkok (10 to 11 Nov) if a member; the second quarterly Report (holiday-scam angle, Black Friday); a Tier-2 decision on the UAE (after the OTP phase-out) on data; the Type II observation window begins.
- December: year-end results against the pacing chart; the PSR consultation (December) as a UK PR hook; the 2027 budget and the ISO 27001 plan (Q2 to Q3 2027); a call on a flagship influencer contract (Kitboga tier) on cost-per-sale data; prep for the January tax-season wave (the category's peak).
Budgets: three scenarios with verified line items
S20The deck's frames stay; the line items are rebuilt from verified prices. All figures are over 3 months.
| Line item | Lean, about $150k | Growth, about $500k | Aggressive, $1M+ |
|---|---|---|---|
| Paid tests and campaigns | $40k (micro-tests of every channel under the $6 kill switch) | $240k (plus Meta, Google, TikTok scaling of the winners) | $500k+ (broad YouTube, all markets) |
| Creators | $30k (5 to 10 micro plus 1 mid-dedicated; rates by the chapter-7 formula) | $120k (plus a macro scam-baiter dedicated, whitelisting the top ones) | $300k+ (Kitboga-tier flagships, repeat-integration packages) |
| Agent stack and tools | $3k to $4.5k ($0.6k to $1k/mo core plus AEO plus Modash plus attribution overage) | $9k to $12k (full stack, Semrush or Profound if needed) | $15k to $20k (multi-account, enterprise tiers as needed) |
| Trust: SOC 2 tranche, GDPR reps, hosting | $15k to $25k (platform plus Type I auditor, reps, Hetzner) | $30k to $45k (plus Type II start, legal review, disclosure platform at volume) | $45k to $60k (plus Swiss hosting for bank pilots, pen-test) |
| Content ops (editor and fact-checker, design, PR wires) | $20k to $25k | $45k to $60k (2 editors, video production) | $80k to $100k |
| Channel engineering (extension, bots, cards, API) | $25k to $35k (in-team) | $50k to $70k | $90k to $120k |
| Reserve, contingency (10%) | $14k | $47k | $95k+ |
| User expectation (deck frame) | about 150k to 200k | about 350k to 450k | 500k+ by month 3 to 4 |
Notes. (1) The cost-per-customer math across scenarios keeps the deck rule: $2 to $4 target, $6 kill switch; paid lines only fund channels that passed the micro-tests. (2) User expectations are the deck's modelled frames estimate, not a public promise: the verified reference curves (see 4.2) show 500k in 3 to 4 months is the upper edge of the possible, even with budget. (3) Attribution overage: at 500k installs with paid attribution the AppsFlyer line can reach $30k+, budgeted into the Growth and Aggressive paid lines.
Risks and honest caveats
S21, expanded| # | Risk | What we do about it |
|---|---|---|
| 1 | Built-in defense (Chrome, Android, Samsung) shrinks the felt need faster than our awareness grows | "On top of the baseline" positioning (see chapter 2), monthly feature monitoring, and a bet on formats the platforms lack (documents, people, a continuous session) |
| 2 | WhatsApp: how the bot is classified for compliance, plus paid service messages from 1 Oct 2026 | A written reply before investing; Telegram and web as free alternatives; the September economics recompute in the calendar |
| 3 | Google penalties for scaled content on the programmatic pages | Unique computed data, batch caps, a 50-page gate, the day-75 memo, and a human gate on publishing |
| 4 | Ad policies: a ban for "fear creatives" and accuracy claims | A pre-flight checklist by policy clause, account warm-up, and verification with real documents |
| 5 | Vendor figures (Guardio revenue, Meta lifts, TikTok Spark) are unaudited | A vendor mark across all materials; decisions only on our own A/B |
| 6 | SOC 2 timing: Type I by November, but banks want Type II (mid-2027) | Pilots run alongside the process, with "process started" a sufficient gate for read-only pilots |
| 7 | Fraud detection is regulated ground; a false negative is a reputation blowup | An "AI-assisted, informational only" product, legal review of every claim, and no detection guarantees, ever (deck rule) |
| 8 | A new site's organic ramp is unpredictable (no niche benchmark) | Internal checkpoints instead of external promises, and redistribution at the gates |
| 9 | The referral K-factor may not catch (niche examples undocumented) | Non-cash rewards, measurement from week 1, and a K under 0.1 kill threshold on day 90 |
| 10 | Agent incidents (loops, spend, unauthorized posts) | The governance loop of chapter 10: caps, traces, a loop detector, and human gates on everything public |
Source registry (by chapter)
The full research JSON packages (14 workstreams: findings, steps, prices, caveats) and the verification verdicts live in the project's working archive. Below are the key primary sources.
Market (chapter 1)
- FTC 2025 (imposters $3.5B, $15.9B): ftc.gov/news-events/news/press-releases/2026/06 plus cnbc.com/2026/06/26/imposter-scams-led-fraud-reports-to-ftc-in-2025
- FBI IC3 2025 ($20.9B, AI category): ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf (direct fetch 403; figures via spycloud.com/blog/fbi-internet-crime-report-2025)
- UK Finance Annual Fraud Report 2026: ukfinance.org.uk (report PDF); PSR reimbursement dashboard (89%, £243M)
- NASC Targeting Scams 2025 (March 2026): nasc.gov.au/publications/targeting-scams-2025 (full text read by the verifier)
- Singapore Police Annual Scam and Cybercrime Brief 2025: police.gov.sg (full PDF read by the verifier)
- CAFC Top-10 frauds 2025: antifraudcentre.ca/features-vedette/2026/02
- GASA research hub (regional 2026): gasa.org/research; Hoxhunt Phishing Trends: hoxhunt.com/guide/phishing-trends-report vendor
Competitors (chapters 2 to 3, 5)
- Guardio: techcrunch.com/2025/11/19 ($80M, ION, about $100M revenue); techcrunch.com/2021/12/14 (1M users 2021); guardio.pissedconsumer.com (1.5/5, 235); trustpilot.com/review/guard.io (4.4/5, via aggregators)
- Chrome Gemini Nano: androidheadlines.com/2026/05 plus ppc.land (May 2026); Android Scam Detection (12 countries, opt-in): blog.google/security
- Norton Genie: justuseapp.com/en/app/6448706515 (0/100 language score); norton.com Scam Protection
- Malwarebytes Scam Guard: malwarebytes.com/press/2026/02/17; McAfee: techradar.com "not truly free"
- Scam.org: gasa.org/knowledge-base/blog (12.03.2026, partners)
- Truecaller: techcrunch.com/2025/04/03 (450M+), techcrunch.com/2026/04/26; restofworld.org/2022 (contact history)
- ScamAdviser: similarweb.com and semrush.com website reports (4.5M and 7.3M visits), scamadviser.com/articles/scamadviser-algorithm-explainer, scamadviser.com/become-a-partner (400+ partners)
Organic (chapter 6)
- Google scaled content and site reputation: digitalapplied.com (March 2026 core), seroundtable.com (manual actions on CNN, USA Today, German publishers)
- llms.txt: ahrefs.com/blog/llmstxt-study (137k domains), Originality.ai tracker, ALLMO.ai (94k citations)
- AI citations: prnewswire.com 5W AI Platform Citation Source Index 2026 (Reddit about 40%, top 15 is 68%); Pew via almcorp.com (clicks 15% to 8%)
- Prices: ahrefs.com/pricing, ampifire.com (Semrush), solcrys.com/aeo-platform-pricing-2026 (Otterly, Profound), frase.io/pricing
- PR flywheel: prnewswire.com Truecaller Insights series
Influencers (chapter 7)
- outlierkit.com (formula, CPM tiers, 1.3 to 1.5x); creatorsagency.co (about 2x, median $100 CPM on a finance sample)
- aura.com/affiliate-program ($65 per sale, 60-day cookie); youtube.com ThioJoe (Guardio deal structure, confirmed against the video)
- lumanu.com (51% charge for whitelisting); influencerfee.com (uplifts, aggregation)
- FTC endorsement: ftc.gov/business-guidance plus thesocialmedialawfirm.com ($51,744)
- modash.io/pricing; instantly.ai cold-email benchmark report 2026 (reply benchmarks); emarketer.com Agentio (plus 10% click-through on repeats)
Stores and bots (chapters 8.1 to 8.2)
- developer.chrome.com/docs/webstore (review process, discovery, code readability); developer.chrome.com/blog/cws-policy-updates-2026 (enforcement 01.08.2026)
- extensionranker.com, extensionfast.com (ranking, 4.5 stars) (low-ranked, flagged); lowcode.agency (iOS and Play review timings); developer.apple.com/app-store/review/guidelines (2.3.1a); learn.microsoft.com (Edge about 7 days)
- developers.facebook.com WhatsApp pricing (the window model; the live rate-card CSV is the required source for rates); hello-charles.com (paid service messages from 01.10.2026); dig.watch plus techcrunch.com/2026/03/05 (AI ban, €0.049 to 0.1323)
- core.telegram.org/bots/inline, webapps, payments-stars; getkanal.com (CTWA benchmarks UK and US); ezcontact.ai (BSP comparison); zaple.ai (Business Verification)
Partnerships, banks, grants (chapters 8.3, 12)
- psr.org.uk PS24-7 and PS25-5 (£85k, 50/50, 5 days); bratby.law (July 2026 assessment: down 21%, 54 to 65%); klgates.com (Fraud Strategy 2026 to 2029, £31M Online Crime Centre)
- lloydsbankinggroup.com plus fintech.global (Scam Check); Revolut newsroom (call ID)
- fraxtional.co (SOC 2 in bank due diligence: 98% and 99%, 2 to 3 weeks to the cycle); natwest.com (Malwarebytes bundle closed)
- gasa.org/members (tiers, "flexible pricing," summits); getsafeonline.org/checkawebsite (ScamAdviser engine; Ask Silver)
- earlywarning.com (CSN and Zelle), idcare.org; apply-for-innovation-funding.service.gov.uk (Cyber Scale closed, Loans open)
- cloud.google.com/web-risk/pricing; urlscan.io/pricing; ipqualityscore.com/plans; apwg.org/membership (tiers $1.5k to $15k); haveibeenpwned.com/Subscription; troyhunt.com (FBI 630M, government program #45, k-anonymity)
- aiopportunityfund.withgoogle.com/apac (SG ScamWISE $2M, ASEAN $5M); feedzai.com/fraud (clients, quote-only prices)
Paid traffic and measurement (chapter 9)
- support.google.com/adspolicy (Misrepresentation 6020955, 7-day 15936666, Circumventing 15938075 dated 04.11.2025); thehackernews.com/2026/04 (Ads Safety Report)
- adamigo.ai (Meta CPM), adliftr.com (TikTok), richads.com/blog/pre-roll-ad-cost (YouTube), stackmatix.com (Reddit cost per lead)
- appsflyer.com/pricing (12k free, $0.07); amsive.com (geo holdouts)
Agent stack (chapter 10)
- n8n.io/pricing; clay.com/pricing ($167, inconsistencies logged); instantly.ai/pricing; ads.tiktok.com/help (MCP server); ai.meta.com (Muse Spark $1.25 and $4.25); canva.com/pricing; elevenlabs.io/pricing; developers.heygen.com; runwayml.com/pricing
- sprinto.com/blog/ai-incidents-lessons (88%), github.com/vectara/awesome-agent-failures, arxiv.org/pdf/2509.14647 (AgentCompass)
- linkedin.com/legal/professional-community-policies; datamatters.sidley.com (EU AI Act, 02.08.2026); X post pricing (20.04.2026)
Geography (chapter 11)
- corrs.com.au (SPF: no auto-compensation, penalty tiers); mas.gov.sg SRF guidelines (cascade, 16.12.2024, phishing only); ABS safeguard 15.10.2025
- irs.gov/newsroom Dirty Dozen 2026 (05.03); biometricupdate.com Cifas Fraudscape 2026 (444k); canada.ca (Anti-Fraud Strategy, March 2026)
- onespan.com (CBUAE OTP phase-out 31.03.2026); verbraucherzentrale.de Phishing-Radar; BKA €22B via ThreatMark; gsma.com (Philippines 52%)
Trust (chapter 13)
- atlantsecurity.com ($28k to $58k; 14 to 22 weeks, the verifier's refinement on the same source); cavanex.com
- elevateconsult.com (ISO 27001 $10k to $50k; £1,500 a day); engagecompliance.co (DPO €2k to €5k/mo); complyjet.com (€525k Locatefamily)
- proton.me/legal/transparency (report structure; the VPN versus Mail nuance); cipherssecurity.com (disclosure and bug-bounty tiers); fi.co/fast (FAST agreement)
Viral loops (chapter 4)
- vercel.com/docs/og-image-generation; developers.facebook.com WhatsApp link previews (up to 600KB); instantview.telegram.org
- referralcandy.com (3 to 5% median, cash beats points by about 40%, visibility plus 30%); saxifrage.xyz/post/k-factor-benchmarks (informal); slate.com (Wordle "link feels spammy"); ainvest.com (Life360)
- redship.io (Reddit 90/10 informal); help.nextdoor.com (promo rules)
Summary of agent loops on the Claude infrastructure
The recurring automations we run on n8n plus Claude (on a cron or triggers), all with a human gate on any public action:
- Weekly (Friday): a check for the GASA Global 2026 release and new regulator reports (FTC, Cifas, Scamwatch, CAFC, SPF), returning a short summary and a proposed PR pitch on release day.
- Monthly: the competitor matrix (a diff report), monitoring of blog.google/security and platform features, the Tier-2 watch note (quarterly), and SPF milestones.
- Daily: Search Console indexing of the programmatic pages (flag "not indexed over 14 days"), store metrics 4 times a day in launch week, and agent-stack incidents.
- Weekly: cost per active user by channel plus a pause recommendation ($6 kill switch); K-factor; cost per sale per creator; the pacing chart against the reference curves (monthly).
- Event-driven: a transcript scan of influencer videos for the FTC disclosure before payment; a policy check of every ad creative; a smoke-test of the card link previews before release.
- September (a hard date): a recompute of WhatsApp economics against the live rate card before 1 Oct 2026.
Verification log: what was fixed and what could not be checked
B.1 Refuted (kept out of the plan)
- "SPF (Australia) brings automatic reimbursement up to A$3,000": the law has no mandatory compensation, only penalties and AFCA. The full start date is not officially fixed.
- "ScamShield blocked $913.1M": that is Singapore's total national loss in SGD (down 17.9%), not a ScamShield number (its own: 1.53M downloads).
- "Two-sided referrals plus 30 to 50%, 4 invites, 15% of installs, K=0.6 (ReferralCandy)": these figures are not on the source page. The real numbers: 3 to 5% median conversion, cash beats points by about 40%, visibility adds 30% to sharing.
- "SOC 2 Type I in 8 to 12 weeks": the full cycle is 14 to 22 weeks (median 16); 8 to 12 weeks is only the auditor's testing window.
B.2 Key fixes (folded into the text)
- Android Scam Detection: 12 countries and off by default (not "on by default in 6 countries"). Chrome Gemini Nano: confirmed via Android Headlines and ppc.land, with the primary source weaker than hoped.
- UK 89% versus 61%: different perimeters (the PSR dashboard's 15 months versus UK Finance's full 2025); both figures stand.
- Guardio 2021: 1M users (not 100k paying); "Series B" is not in the source; PissedConsumer 235 reviews; Trustpilot reviews in the thousands, not "500+".
- Lloyds: 68% refers to shopping scams in Lloyds fraud reports (most of which come from Meta platforms), not "68% of all reports from Meta."
- APWG: $15k is the top tier, entry from $1.5k. HIBP governments: 45. Scamio "7.4M": exists nowhere, purged from the deck.
- YouTube "finance CPV $0.08 to $0.25" unconfirmed; Advantage+ "3.14 versus 2.70" is not a Meta report but one agency's case; TikTok MCP "free": features confirmed, price not.
- llms.txt figures refined (28% of the sample's domains publish; 97% get zero traffic at all); the "do not invest" conclusion held. The 5W stat "11% domain overlap" is absent from the release, purged.
- SOC 2 Type II: startup range $25k to $80k+ and 6 to 12 months; ISO day rate £1,500; Proton transparency: "100% refusals" only for the VPN.
B.3 Could not verify (used with care or not used)
- Exact WhatsApp rates by market (only Meta's live CSV; the blogs contradict each other).
- The absence of CPC data for scam queries: a negative claim, closed by a live Keyword Planner.
- Vercel OG: the 4MB limit and the exact Cache-Control are not on the docs page (re-check at build).
- Hosting details (Exoscale plus 74%, Hetzner 20TB egress): unconfirmed against primary sources. The Hetzner choice rests on the general price level; when in doubt, recompute on live prices.
- No-analogue claims (referral cases for free security products, Telegram scam-bots with millions): searched, not found, so treated as "no precedent," not "impossible."
What makes this plan "two levels deeper" than the deck
The deck level says "ship 50 SEO pages by day 30." Level 2 of this plan says which fields go in the page template, which APIs and at what price, and which quality gate to pass before scaling. Level 3 says who exactly does it (the agent prepares the change, draft, or calculation; a person approves and presses the button), which tool and plan, which date on the calendar, and which kill threshold. Every chapter closes all three levels. Anything one level deeper that depends on live data (the Keyword Planner, the Meta rate card, the GASA quote) is marked as a first-week action, not an invented number.