The €4,000 Scam That Started Everything
Rita Barbosa didn't set out to build a fraud-detection startup. She set out to protect her grandmother.
Scammers had called her grandmother claiming the household's tap water was contaminated. They manipulated her into buying four water filters — each worth around €20 — for roughly €1,000 apiece, a total loss of nearly €4,000. But for Barbosa, the financial damage was almost secondary.
"It was such a shock — not because she was scammed, but because of the way she reacted to it. She basically said to herself, 'After this, I can't really use technology.'"
Her grandmother stopped answering the phone entirely. The scam hadn't just taken money — it had dismantled her independence. That loss of confidence, not the €4,000, is what Barbosa set out to prevent.
From Hackathon Win to National Attention
The idea gained traction after Barbosa attended a hackathon in Germany, where she won first place with a working prototype of what would become Guardião.
Guardian Labs has since grown into a formal startup, partnering with the Portuguese Public Security Police (PSP), two leading engineering universities, and one of Portugal's largest accelerators — with the backing of the President of the Republic. That trajectory — from side project to state-level endorsement in a short window — reflects both the urgency of the problem and the difficulty governments have in solving it themselves.
The Tech: AI That Acts Before You Even Pick Up
The core product, Guardião, sits as an AI layer between incoming communications and the user. What distinguishes it from conventional spam filters is where and when it intervenes.
For SMS, the AI scans for spoofing, phishing links, and manipulation patterns before a notification is even generated. For voice calls, Guardian Labs engineered interception to happen before the phone rings at all — checking known scam databases and analysing for tactics like artificial urgency, requests for banking codes, or emotional pressure. If a call or message is flagged, it never surfaces in the normal way. Instead, users receive an alert and can view a full history of intercepted contacts in-app, complete with Guardian's reasoning and a risk-level score.
"It's proactive because it's already there as the first line of defence. You don't need to protect yourself manually," says Barbosa.
Critically, all analysis runs locally on the device. No call content or message text is sent to a remote server. This matters both for privacy and for trust — especially among the older users most likely to be targeted. Barbosa notes that on-device models small enough to run on consumer hardware have only recently become viable, which is what made the product possible at all.
Scam Intelligence Is Hyper-Local
One underappreciated complexity in fraud detection is geography. A model trained on fraud patterns from one country won't reliably catch what's circulating in another — and this has direct implications for any company trying to scale a product like this across markets.
In Portugal, a dominant vector is the "Hi Mum / Hi Dad" scam, where fraudsters impersonate a victim's child, claim to have lost their phone, and pressure a parent to transfer money urgently. Another pervasive scheme mimics official communications from Portugal's national healthcare service, requesting small but suspiciously specific payments — around €46–€47 — that seem plausible to anyone who recently visited a doctor. Barbosa estimates this single campaign generated €2–3 million in fraudulent transfers last year.
The PSP has supplied Guardian Labs with data from scam reports — giving the models grounding in how fraud actually operates domestically. But the geographic dimension cuts both ways: by monitoring scam patterns across multiple countries simultaneously, Guardian Labs could also detect campaigns as they spread between markets, potentially intercepting them before they fully establish in a new territory.
Handling False Positives — and False Negatives
The obvious concern with any interception system is blocking legitimate calls. Barbosa's answer is considered: at this stage, false negatives — scams that slip through — are the more serious failure. A 1% false positive rate is acceptable, she argues, because users retain full visibility through the in-app dashboard. Missing a message and finding it in the app is a recoverable situation. Losing money to a scam, or losing confidence in technology altogether, is not.
The system continuously retrains on reported data, including from users who flag suspicious contacts directly through the app — creating a feedback loop that tightens accuracy over time.
Why This Model Matters Beyond Portugal
Guardian Labs is a useful case study in a few converging trends.
First, on-device AI as a trust mechanism. The decision to run models locally isn't just a privacy feature — it's a product decision that makes the app credible to exactly the users who need it most. Older adults who are wary of technology are not going to hand their call data to a cloud server. Keeping everything on-device removes that barrier.
Second, founder-market fit driven by lived experience. Barbosa wasn't solving an abstract problem. She watched a specific harm happen to someone she knew, and she understood intuitively what the conventional advice — "just don't pick up" — actually cost in terms of human autonomy. That framing shapes a product that prioritises invisibility and independence over user effort.
Third, the demographic math is not unique to Portugal. The population of people who struggle to distinguish a legitimate call from a fraudulent one is large and growing in most European countries. As the tools to generate convincing scam calls become cheaper — synthetic voices, AI-assisted scripts — the case for proactive, automated interception only strengthens. The question is whether solutions like Guardião can localise fast enough to stay ahead of the campaigns they're built to catch.



