Regression tests
Multi-turn tracking, risk floor, and ledger recording — all passing
Loading project...
Sole Designer, Builder & Operator
Solo (AI sub-agents for research, implementation and review)
4-day sprint: v2 redesign Sep 25 → 3-mode spec Sep 26 → real-device verification → submitted Sep 28, 2026
My second submission to the 5th Agentic AI Hackathon with Google Cloud. Special fraud costs Japan over ¥70 billion a year, and most victims weren't fully fooled — they felt a thin suspicion but had no one to check it with. sagi-shield is a button you press in that moment: an AI that always introduces itself as 'your AI security secretary,' then verifies the caller's name, organization, official number, and purpose — live on a real phone call via Gemini Live API — while logging everything to an evidence ledger, notifying family over LINE on danger, and generating a police-consultation (#9110) report. Verified end-to-end on a production acoustic path; the deterministic detection layer is calibrated at 100% catch / 0% false-positive on the test corpus.
Fraud victims aren't people who believed everything — they're people who felt something was off and couldn't act on it. 'If it's suspicious, just hang up' fails because hanging up requires certainty, and certainty requires verification a layperson can't do alone mid-call. The gap is the few minutes between first doubt and reaching help — a gap where the victim faces a trained manipulator one-on-one. Existing answers didn't fit: monitoring the family's LINE or calls violates consent, and 'intercepting' the scammer (auto-responders that bait the caller) manufactures evidence neither side asked for.
A button, not a surveillance system. sagi-shield does nothing until a person presses it. Then three modes cover the real situations: (1) 'AI answers' — put the phone where it can hear a landline call, and a Gemini Live API agent introduces itself as the AI security secretary and verifies name, organization, official number, and purpose; (2) 'whisper' — during a call on the same phone, tap what the caller claimed and what they demanded, and get a danger rating plus reply text, tracked across turns; (3) 'number check' — format analysis of the incoming number (international/050/withheld), explicitly labeled as format analysis, not a reputation database. Two more doors take suspicious text: a paste-in intake form and a LINE official account that works inside the LINE app parents already use. Every exchange lands in an evidence ledger; danger triggers a LINE notification to registered family with a transcript excerpt and next action; a printable #9110 police-consultation report generates automatically.
Fraud victims aren't people who believed everything — they're people who felt something was off and couldn't act on it. 'If it's suspicious, just hang up' fails because hanging up requires certainty, and certainty requires verification a layperson can't do alone mid-call. The gap is the few minutes between first doubt and reaching help — a gap where the victim faces a trained manipulator one-on-one. Existing answers didn't fit: monitoring the family's LINE or calls violates consent, and 'intercepting' the scammer (auto-responders that bait the caller) manufactures evidence neither side asked for.
A button, not a surveillance system. sagi-shield does nothing until a person presses it. Then three modes cover the real situations: (1) 'AI answers' — put the phone where it can hear a landline call, and a Gemini Live API agent introduces itself as the AI security secretary and verifies name, organization, official number, and purpose; (2) 'whisper' — during a call on the same phone, tap what the caller claimed and what they demanded, and get a danger rating plus reply text, tracked across turns; (3) 'number check' — format analysis of the incoming number (international/050/withheld), explicitly labeled as format analysis, not a reputation database. Two more doors take suspicious text: a paste-in intake form and a LINE official account that works inside the LINE app parents already use. Every exchange lands in an evidence ledger; danger triggers a LINE notification to registered family with a transcript excerpt and next action; a printable #9110 police-consultation report generates automatically.
Honesty is the security feature. The AI always names itself — no impersonation, no entrapment. The verification protocol (identify → confirm affiliation → confirm contact → confirm purpose → save to ledger) is visualized from actual transcript turns, not inferred. The ledger separates what the AI actually sent, what it only proposed, and what the user transcribed; notifications distinguish 'LINE accepted' from 'log-only' and 'failed.' Risk scores never decrease mid-case — once danger is flagged, later turns can't quietly lower it. And the product refuses to claim deterrence: the reason a caller hangs up is undetectable, so the ledger records facts, not victories. Limitations are written on the same page as the features — the link-shared ledger model with no authentication — anyone holding a case URL can view it — the experimental speakerphone path, the 8,000-character transcript cap.
On a real call, the Gemini Live API agent opens with 'I am an AI security secretary,' then verifies the caller's name, organization, official number, and purpose in order — and refuses demands for PINs or transfers. The acoustic path (phone speaker → phone mic → Live API → spoken reply) is verified in production.
When the suspicious call is on the very phone in your hand, mic access is unreliable — so whisper mode needs only taps: report what the caller claims and demands, get a danger rating and reply text, and keep tracking the caller's moves across turns.
Every exchange is recorded with timestamps and judgment rationale; danger triggers a LINE notification to registered family with a transcript excerpt and recommended next action, and a printable report formatted for police consultation line #9110 generates automatically.
Beyond the three call modes: a paste-in intake form for suspicious texts (SMS, email, LINE messages), and a LINE official account that accepts forwarded messages — so the parent generation can use it inside the app they already open daily.
The first design died on evidence. The original concept (monitoring family LINE / intercepting scammers) was killed by a six-document Deep Research pass on consent and effectiveness grounds, then redesigned as the 'secretary button': an opt-in checkpoint, not surveillance. Business-design artifacts (premises, structural break, forces, spec) preceded implementation, with adversarial review at each gate. Real-device verification confirmed the acoustic path in production — an actual session where the AI named itself, confirmed affiliation, refused a PIN demand, and advised calling the official number, with the danger rating and LINE notification firing. The detection layer was calibrated by injecting known errors (name-stripping, urgency-stripping, request-weakening, normalization) into a synthetic corpus, and the results — including the 79% worst case — are published rather than rounded up. Submitted 2026-09-28.
Multi-turn tracking, risk floor, and ledger recording — all passing
Deterministic layer: 100% catch rate (n=24 scam corpus), 0% false positives (n=11 safe corpus); worst perturbation 79%, published as a known limit — LLM layer quality is separate
Phone speaker → phone mic → Gemini Live API → spoken AI response verified on the deployed service, with a real session logged end-to-end
v2 redesign after the evidence kill → spec → build → device verification → submission

Entry point — forward suspicious messages to the LINE official account, or verify text in the browser; the voice window is labeled as a technical demo