NextAct

Verify before you act.

Check suspicious messages, links, job offers, payment requests and documents using evidence rather than guesswork — before you click, pay or reply.

No account needed. NextAct tells you what does not fit and what it could not check. It cannot tell you that something is safe — and it will never say so.

What a result looks like

Demonstration

What is happening

A message presenting itself as Example Bank is asking you to share a one-time security code.

They are asking you to share a one-time security code. If this turns out to be fraudulent, it cannot be undone or recovered.

What NextAct observes

High risk

Several things NextAct checked do not fit together. Do not act on this as it stands.

Before you act

Do not proceed yet

Do not do what this asks until you have checked it independently.

Evidence

Limited

Some parts could be checked, but important questions — often who is really behind this — remain open.

Confidence

Medium

The evidence supports this classification, from sources of mixed strength.

What confidence means
Confidence describes how strongly the available evidence supports this specific assessment. It is not the probability that something is fraudulent.

If this is wrong

Cannot be undone

If this turns out to be fraudulent, it cannot be undone or recovered.

Why

  • The sender presents itself as an organisation whose recorded address does not match the one actually used.
  • The message asks for a one-time security code. No organisation needs one from you, and sharing it hands over account access immediately.
  • The message sets a deadline, which reduces the time you have to check it.

What NextAct could not verify

Who actually operates this domain?

The name alone does not establish who is behind it, and names are chosen to resemble real organisations.

Safest next step

Open your banking or account app directly from your phone, the way you normally would.

If the alert in the message is real, it will also be waiting for you inside the app. If it is not there, it was not real.

A made-up example, shown with the same components a real result uses. It is not a real case and not a statistic.

What NextAct actually does

  • Reads what you were sent

    A message, a link, a screenshot, a PDF or a saved email. NextAct never opens, clicks or replies to anything.

  • Separates claims from evidence

    What the material asserts — who it is from, what is urgent — is kept apart from what can actually be checked.

  • Shows you the contradictions

    A claim that independent evidence disagrees with is the strongest signal there is. You see it, not just a score.

  • Names what it could not verify

    Silence about a gap reads as reassurance. NextAct lists what it could not check, and how to check it yourself.

What NextAct will not do

No safety guarantee

NextAct reports observed risk and what it could not check. “Safe” is not in its vocabulary, because it cannot be established.

AI does not decide

A language model may help explain a result. It can never set the risk level, and in this build no model is connected at all.

No accuracy claim

No detection rate is published, because none has been measured against real-world data.