The problem
Pakistan's approach to online blackmail and image based abuse, like most countries, is built around publication. A victim reports after content has already appeared. The effort then focuses on takedown and prosecution. The brief was to design something different. A national system that could do the harder, earlier thing. Protect a woman or girl from the moment she is threatened. Contain the damage if publication happens. Preserve evidence. Route the case to the right authority. And do all of this without exposing her further.
The challenge was not primarily technical. It was one of trust, timing, and restraint. Act too late and you serve only the aftermath. Collect too much and you build a catastrophe. The design had to thread both.
The shift in thinking
Reframing the harm changed everything. The damage does not begin at publication. It begins at the threat. The coercion, the fear, the extortion that happen while the image is still private. So protection had to begin there too. A credible threat, not a published image, became the trigger for the whole system.
The second insight was that the hardest seeming piece, blocking an image before it spreads, was already solved by existing on device fingerprinting services. The phone computes a hash locally and only the hash is shared. That meant the system's job was orchestration and care, not image infrastructure.
The decisions that shaped it
The most important design decision was a refusal. Panah would never hold victims' intimate images. A national archive linking identities to intimate images and abuse reports would be the most dangerous object in the ecosystem. A breach or an insider could revictimize people at scale, with lethal risk in an honour based context. So the crown jewel image is fingerprinted on the device and never uploaded. The system holds the threat evidence, messages, demands, usernames, richly, and refuses the picture. Every later decision followed from this.
Several of the most valuable integrations are gated behind institutional partnerships a solo builder may not have. Getting a fingerprint into a blocking network, platform takedowns, formal referral to the cybercrime agency, all of it needs agreements. Rather than fake them, the design made each a swappable adapter whose honest default guides the victim to the official service and clearly states that Panah did not submit on her behalf. The same codebase serves a pilot today and a fully integrated system later. Only the adapters change.
A transparent scoring model tiers cases from Low to Critical using visible factors. A deadline, repeated threats, financial demands, account access, knowledge of the victim's family, threats of violence. But the model only assists. A minor forces a safeguarding pathway. A threat of violence forces human review. High risk cases never proceed on automation alone. The engine takes no action and names no one.
Any case involving someone under eighteen routes to a specialist path and to child protection authorities. It never touches the image and never asks the child to navigate the process alone.
Deepfake detection was deliberately kept out of the core. Sending a victim's intimate image to a third party detector would break the privacy rule, and the detectors are too unreliable to justify it. AI triages and flags. It never proves a fake or accuses a person.
Walking through the system
The following is a fictional composite, not a real case, and involves an adult. It illustrates the flow, not any individual.
Consider a woman, call her R, who receives a message. A private photo, and a demand for money by tomorrow night, or it goes to her family. She is not sure whether the photo is real or made. She has told no one.
She opens Panah on her phone. There is no login, no name to give, and a leave quickly button in the corner in case someone glances over. The first screen tells her, plainly, that she is not to blame. Before any form, it gives her three things that matter most. Do not pay. Do not send more. And let it help her lock her accounts.
Her phone makes a secure fingerprint of the image locally. The picture never leaves the device. So that if it is ever uploaded to a major platform, it can be blocked. Because no partnership is assumed, Panah guides her to the official blocking service rather than pretending to submit for her. She then seals the threatening messages and the sender's username into an encrypted, timestamped record. The app refuses to let her upload the private image itself, because it never needs to be stored.
A few quiet questions, one at a time, each skippable, establish that there is a deadline and a threat to contact her family. The risk engine marks the case High and flags it for a human. She reaches a confirmation screen. A case number. Three things already done. And a clear statement of what happens next, including that she will never have to repeat her story from scratch. A structured packet, containing the evidence manifest and metadata but no image, is ready to hand to the authorities if the risk warrants it.
Every step R and, later, any reviewer takes is written to a tamper evident record that independent oversight can verify. The promise to investigate the perpetrator without exposing the victim is enforced, not merely stated.
What was actually built
The buildable core was implemented and tested. The encrypted evidence vault. The tamper evident audit ledger. The explainable risk engine. The integration seam with its guided handoff default. And the referral packet generator. The safety guardrails were proven by the tests themselves. The vault refuses image data two different ways. A minor forces the safeguarding path. A threat of violence forces human review. And the referral packet provably contains no image bytes.
What could not be built solo was equally clear. Real blocking network access, platform takedowns, and formal agency referral all require partnerships and mandates. The design does not hide this. It isolates it behind adapters and states it in the pitch as the concrete ask of a government or institutional sponsor.
What the project taught
The strongest decision in the whole effort was a refusal rather than a feature. Protecting people from image based abuse tempts you, at every turn, to gather the very thing that endangers them. The discipline that made Panah trustworthy was keeping the image out, keeping humans in, keeping the limits honest, and measuring success by harm avoided, including harm the system itself might cause. Less a clever system than a careful one.
Panah is a working name and an early stage design. The scenario is fictional. Statistics, legal provisions, and third party services referenced elsewhere in this project require verification before any official use.