IMPOSTR: Digital Risk Protection for Social & App Monitoring
IMPOSTR finds fake social-media profiles, fake brand pages, scam accounts and look-alike mobile apps that impersonate a brand. It scores each one from 0 to 100, explains every flag in plain words, and never flags the brand's own accounts and apps. The app runs in the browser and needs no login: open https://impostr.live. Each browser gets a private workspace with two demo brands, ZentraPay (fictional) and PhonePe (real).
Start here
How each requirement is met
- Brand Profile: a three-step setup records the legitimate assets: brand name, aliases, official logo, description, keywords, official social accounts, official apps, publisher and domains. Each official app is validated on Google Play or the App Store (developer ID, store title, icon), and the profile drives every check.
- Official assets are excluded first: every candidate is checked against the profile before any scoring (official app ID or handle, official link, verified developer account, publisher name with supporting details, the same app on the other store). Official and likely official items get risk 0 and are never stored as threats; the allowlist is checked again just before a detection is saved.
- Social Media Monitoring: impersonation accounts, fake brand pages and scam profiles on 16 social and messaging platforms, found by look-alike name, copied logo (perceptual hash, including mirrored and recoloured copies), copied bio, "official/helpline" claims and scam behaviour (requests for OTP or fees, lures, moving to WhatsApp, brand-new accounts).
- App Store Monitoring: Google Play and the Apple App Store are searched live. Suspicious apps are found by similar name, copied icon, a different developer or publisher (including fakes that copy the company name under another developer account) and a resembling description. The brand's official apps and their sibling apps are recognised and not flagged.
- Look-alike names (bonus): character swaps, missing or doubled letters, look-alike characters (0 for o, 3 for e, Cyrillic letters), added words and spacing changes, while ordinary words, other companies' names and openly labelled fan, news or third-party pages stay Low.
- User experience: setup in three steps or straight from a search; each detection shows its reasons, a score breakdown and evidence checks, with actions to confirm, request a takedown, mark a false positive or mark official. Each source has its own timeout and retries and falls back to cached results, so an unavailable source never stops a scan.
Evidence you can open directly (JSON)
- https://impostr.live/api/accuracy: the labelled test set run live through the engine: 82 of 82 cases correct, precision 1.0, recall 1.0, 0 of 19 official assets flagged.
- https://impostr.live/api/search?query=PhonePe&platforms=google_play,app_store: a live search of both app stores; PhonePe's official apps are listed under "official" with risk 0, look-alikes under "results" with reasons, signals and evidence checks.
- https://impostr.live/api/search?query=zentrapay&platforms=instagram,facebook,whatsapp,telegram,x: social impersonation and scam accounts scored, with the brand's official accounts excluded.
- https://impostr.live/api/search?query=z3ntra.pay_official: look-alike name analysis step by step (field "nameAnalysis").
- https://impostr.live/api/sources: all 20 sources with their mode (live or sample data) and health.
Data disclosure: Instagram, Facebook, WhatsApp and the other social platforms offer no open search API, so their results come from a curated sample set and are tagged SAMPLE in the app. Google Play and the App Store are searched live.