Open to opportunities

Jenna Webb

Trust & Safety operator who ships products.

10+ years living at the intersection of risk, data, and strategy— turning behavioral signals, regulatory frameworks, and operational KPIs into programs that actually move the numbers. Across email, messaging, fintech, and SaaS, my most recent Staff PM work used cross-functional, data-driven detection frameworks to cut abuse incidents by 71%. Off-hours, I ship full products end to end across four lanes: detection, live entertainment, operational tooling for real businesses, and quantitative trading.

96%
False-negative rate cut on recent T&S engagement
71%
Abuse incidents cut as Staff PM in a Trust & Safety org
350h
Per month of manual review automated on recent T&S engagement
10+
Years in Trust & Safety

About

Operator first,
builder always

I spent the last decade-plus running Trust & Safety and fraud programs at scale — most recently a Staff Product Manager role leading abuse-prevention strategy for a global email + messaging platform, before that a Fair Billing Compliance program at a major retail-financial-services firm, and most recently a consulting engagement designing onboarding-fraud detection for a notification platform. I’m fluent in the operational side: SQL, Snowflake, Looker, Splunk, behavioral analytics, root-cause investigation, KPI design, carrier and cross-functional escalation.

What sets me apart is that I don’t stop at the spec — I build the thing. The projects below are products I designed, built, and shipped end-to-end using modern AI tooling to move at solo-builder speed without losing the rigor I bring from the T&S side.

The combination is rare: an operator who can talk to legal, finance, and carriers, then go write the schema. That’s the role I’m looking for next.

Selected projects

Four lanes, one builder

Detection, entertainment, process improvement, and trading — different domains, same end-to-end ownership. Each project below was designed, scoped, and shipped by me.

Detection & Verification

Trust & Safety tooling

Fraud-detection APIs, domain risk scoring, OSINT verification, and GRC tooling — shaped by ten years of frontline T&S work.

  • Domain Risk API (SDAT v2)

    Shipped

    Commercial fraud-detection API

    The successor to the Config-checker prototype. Multi-tenant SaaS modeled on industry leaders like eHawk: an API-first product where customers automate fraud decisions instead of running them through a human-review console. The initial version of this engine was installed into a prominent email provider’s infrastructure during a fraud-detection consulting engagement, validating the scoring model on real submission traffic. v2 wraps that proven analyzer in a multi-tenant API with a cross-customer fingerprint reputation network and community feedback loop.

    • Initial version installed into a prominent email provider’s infrastructure for live fraud detection
    • Wraps the proven Config-checker analyzer instead of rewriting it
    • API-first: sync POST /submissions today, async-compatible response shape for tomorrow
    • Django 5
    • Postgres
    • Python
    • REST API
    • +1
    Try the live demo
  • Config Checker (SDAT v1)

    Shipped

    Streamlit prototype that scores domains for fraud risk

    The original Streamlit-based domain-risk analyzer (~400KB Python). Accepts a domain, returns a structured DomainApprovalResult with risk score, recommendation, and an investigator-friendly summary. Still in active use; the engine that the v2 API now wraps.

    • Single-domain risk scoring with a structured, queryable result object
    • Pulls DMARC, RDAP, and threat-intel signals into one report
    • Investigator-friendly summary explaining the score
    • Python
    • Streamlit
    • RDAP
    • DMARC
    • +1
    Try the live demo
  • Domain Risk Checker

    Shipped

    Domain & URL fraud analyzer that scores the registrable root AND the exact destination separately

    The evolved Config-checker engine, built on one principle: platform trust shouldn't launder a risky page. Every submission is scored twice — the registrable root and the exact submitted URL/path — so a bad tenant on a trusted host (a scam payhip.com/b/<id>, or an Amazon listing hidden behind an a.co short link) can't hide behind a clean root. It resolves URL shorteners and social/search link-wrappers (a.co, bit.ly, l.facebook.com, google.com/url) to analyze where a link actually goes, optionally renders pages in a headless browser to catch client-side-injected ads, and runs a consumer-harm pipeline that detects made-for-advertising ad-stuffing, pop/push-ad networks, fake-virus scareware, browser-lock traps, and crawler cloaking — with a plain-English summary and analyst-only evidence.

    • Dual scoring: independent verdicts for the registrable root and the exact submitted URL/path, so a trusted host can't whitewash a risky tenant
    • Unwraps URL shorteners + social/search link-wrappers (a.co, bit.ly, l.facebook.com, google.com/url) to analyze the real destination
    • Made-for-advertising / ad-density detection, with headless rendering to surface client-side-injected ads
    • Python
    • Streamlit
    • Playwright
    • Docker
    • +2
    Try the live demo
  • Social Media Verify

    Shipped

    Streamlit OSINT toolkit

    Enter a domain or email address. The tool auto-discovers social media profiles from the company's own site, verifies each one resolves and references the domain, scans reviews across Google/BBB/Trustpilot/Glassdoor/G2/Yelp/Capterra, detects developer signals (GitHub, npm, Product Hunt, app stores), and computes a 0-100 risk score with Low/Medium/High/Critical tier.

    • Social-profile auto-discovery from a company's own website first
    • Review-site coverage across 7 major platforms (Google, BBB, Trustpilot, etc.)
    • Developer/startup signal detection (GitHub, npm, Product Hunt, Crunchbase)
    • Python
    • Streamlit
    • BeautifulSoup
    • WHOIS
    • +1
    Try the live demo
  • Risk Graph

    In progress

    Risk as a linked graph, not a spreadsheet

    A working prototype for a governance, risk, and compliance system built around ten linked objects — Risk, Control, Metric/KRI, Incident, Action, Policy, Vendor/Asset, Assessment — rather than the disconnected register-plus-spreadsheet setup most teams actually live in. The engine derives residual risk from the inherent score and measured control effectiveness, halved when a control has not been tested in 180 days, then scores every risk across four impact lenses: direct monetary, regulatory, reputational, and customer churn. The churn lens is the part most GRC tools do not have — affected customers × churn probability × lifetime value, with the churn coefficient learned from incident actuals rather than guessed. Compliance and bad-actor risk share one graph: a threat-framework library (MITRE ATT&CK, fraud kill chain, messaging-abuse patterns), attack-vector objects, and detections as a control subtype carrying TPR, FPR, and MTTD — so a vectors × detections coverage matrix becomes the fraud-side gap analysis. A gap engine makes absence first-class, and reporting comes out as three audience packs — regulator, board, and customer trust — frozen as immutable snapshots for defensibility.

    • Ten linked core objects — every template is a view over the graph, never a separate table
    • Residual scoring from measured control effectiveness, with a staleness penalty for untested controls
    • Dollarized churn lens: affected customers × churn probability × LTV, calibrated on real incident outcomes
    • Next.js 16
    • React 19
    • TypeScript
    • SQLite (better-sqlite3)
    • +1

Live Entertainment

Platforms for venues, performers, and patrons

Bar-game platforms, booking marketplaces, and mobile games built for real venues under Tangled Webb Entertainment.

  • Tangled Webb Bar Platform

    Shipped

    Live bar entertainment platform plus a public marketing site

    A full multi-game platform for venues, running live bar nights every week and still in active beta testing at the venue — real crowds are the test harness. Players join by scanning a QR code, hosts run rounds from a unified console, and admins manage venues, question banks, promotions, performer profiles, and booking flows. Anti-cheat detects when players leave the app mid-question. A shared prize wheel runs across the games with per-prize stock that pulls a prize once it hits zero, a physical-deck mode for hosts who would rather deal real cards, and landing math centralized behind regression tests after it drifted between the wedge and the prize text. Bar Bingo was rebuilt phone-first this summer: server-side auto-call (the old client-side timer died whenever the host backgrounded the tab), themed square rounds, generated trash talk, and proper handling for two people calling bingo at once. Tab Out gained sabotage cards and rotating banter. The TV displays now survive a crash and hold their screen when the event stream drops. The same Next.js app serves tanglewebb.com — the public marketing site with about, services, schedule, venues, gallery, blog, and testimonials.

    • Seven game modes share one player join flow and host console, including a Queen of Hearts raffle tracker
    • Player, host, admin, and performer roles each get a tailored interface
    • Shared prize wheel: per-prize stock with auto-removal at zero, physical-deck mode, landing math under regression test
    • Next.js 16
    • React 19
    • TypeScript
    • Turso (libsql)
    • +2
    Try the live Open Mic demo
  • Louie’s Phone Games

    Shipped

    Five pick-up-and-play games on the bar’s own phones

    A games arcade for Louie’s Corner House running off the Tangled Webb platform: trivia, Shut Up & Roll, Tab Out, Triple Down, and a solo flick-to-throw Beer Pong. Play is gated behind proof you are in the bar — the geofence borrowed from the ordering app, or the table code printed on the QR — so the games stay a reason to come in rather than something to burn through at home. Leaderboards sit deliberately outside that gate: best score per person per board, across tonight, this week, and all time. Beer Pong Solo is scored on the server rather than the handset, because a flick-to-throw score computed on a phone is a claim, not an observation — the client reports throws and hits, the server does the scoring and clamps the impossible cases, and the leftover-throws bonus pays only on a cleared rack so “do not throw at all” cannot become the winning strategy. It is a leaderboard game by design and never feeds a prize wheel.

    • Five games on one join flow: trivia, Shut Up & Roll, Tab Out, Triple Down, Beer Pong Solo
    • At-bar gate uses the ordering app’s geofence or the printed table code — play stays in the building
    • Leaderboards live outside the gate: best-per-person, tonight / this week / all time
    • Next.js 16
    • React 19
    • TypeScript
    • Turso (libsql)
    • +1
    See the live leaderboards
  • GigHive

    Beta

    Mobile-first booking marketplace where bars and venues book live entertainment

    Two-sided marketplace for live entertainment. Performers publish availability and get booked; bars find acts (especially last-minute) by act type, radius, and region. Includes urgent bookings, fill-in subs, an equipment marketplace, classifieds, and a free public events feed with a follow system.

    • 10 act types, location matching by radius and region
    • $5/month subscription with beta-tester bypass; Stripe handles billing
    • Urgent / fill-in board for last-minute coverage
    • Expo (React Native)
    • Supabase
    • Stripe
    • TypeScript
    View the pitch deck
  • 2 Drink Memories

    Prototype

    Bar-friendly photo-hunt game

    First title from Fly Trapp Games (a sub-label of Tangled Webb Entertainment). Token-based plays via in-app purchase, image pairs generated through Gemini 2.5 Flash, hotspot hit-detection on tap. Designed for the bar context — short rounds, easy to pick up, hard to put down after two drinks.

    • AI-generated image-pair pipeline with hotspot coordinates
    • Token wallet (10/$1.99, 30/$4.99, 100/$12.99) wired for IAP
    • Tappable hotspot detection with miss-marker feedback
    • Expo SDK 54
    • TypeScript
    • Gemini 2.5 Flash
    • Supabase (planned)
    Play the web build

Process Improvement

Operational tooling for real businesses

Workflow and customer-facing apps for working venues — replacing phone calls, paper, and interruptions with queues, alerts, and self-service the staff run themselves.

  • Louie’s Patio & Bar Orders

    Shipped

    QR-code ordering for a real working bar

    Built for Louie’s Corner House (Buckeye Lake, OH) to replace the patio-to-bar-phone workflow that kept pulling bartenders off service. Each table's QR code bakes the seat into the link, so nobody types a table number and nobody gets it wrong. Customers browse a real menu — 300+ items with priced variants, mixers, flavours and bartender-only recipes — order in a tap, edit while they're still in line, message the bar, and get a chime-and-vibrate alert with their total. Behind it: a specials engine that runs happy hour and one-off bartender specials on a schedule and recalculates every price server-side at submit; running tabs; and a bartender queue where one tap finishes an order. The admin console runs the rest — role-based staff PINs, GPS geofencing with a gentle fallback for phones that won't share location, three service modes from open through pickup-only to closed, attributed customer blocking, a loyalty card, and an impact dashboard. The card rewards ten different days rather than ten visits or ten dollars — ordering a drink or playing a game both count, two devices on one night still count once, and it cannot be farmed by buying four rounds in a single sitting. A full card is redeemed by the customer spinning the prize wheel themselves, with no staff involved. In production at the bar today, switched on for the shifts it's being tested on.

    • Full menu with priced variants, option groups and server-authoritative pricing — the phone never decides what anything costs
    • Scheduled specials engine: happy hour by day and hour, one-off bartender specials, scoped to sections or hand-picked products
    • Live queue with per-table QR codes, two-way messaging, running tabs, and web-push lock-screen alerts for the bar device
    • Next.js 16
    • React 19
    • TypeScript
    • Supabase (Postgres)
    • +2
    Play with the working demo
  • Louie’s 50th Memory Wall

    Shipped

    Community memory wall for a bar’s 50th anniversary

    Built for Louie’s Corner House (Buckeye Lake, OH, est. 1976) to collect fifty years of customer history before it disappeared into shoeboxes. Patrons upload photos and videos, tag who is in them, add the year and the occasion, and leave comments; stories can be typed or photographed straight off the handwritten wall inside the bar. The wall groups itself by year and event, and a perceptual-hash duplicate detector catches the same photo arriving from four different phones. The team runs it from a dashboard — a review queue that clears in one tap, bulk edit and filtering, name-tag approvals, per-photo comment locks with IP and device capture plus a block list, and a visitor-analytics snapshot. A /tv mode casts the whole thing to the screens at the bar: polaroid frames with Sharpie captions, four-up montages, typed stories as story cards, event flyers and the Queen of Hearts board woven into the rotation, and a rotating ad every ninth set. In production with real patron data since June, and the bar has been playing it nightly ever since.

    • 800+ real patron memories — photo and video uploads, external video embeds, and handwritten stories
    • Perceptual-hash duplicate detection groups the same photo arriving from four different phones
    • Name tagging with approval, year and event grouping, search across names, events, years, and text
    • Next.js 16
    • React 19
    • TypeScript
    • Supabase (Postgres + Storage)
    • +1
    Visit the memory wall
  • CornerHouse

    Shipped

    The bar’s front door

    The main site for Louie’s Corner House and the hub that ties the other apps together. Everything on it is data, not code: the top nav and the homepage app tiles are driven by rows in a site_links table, so when the next app ships the team adds it themselves and it appears with no deploy. Events carry uploaded flyers, the homepage headlines the current Queen of Hearts jackpot, and a password-gated admin console runs all four surfaces — events, Queen of Hearts, menu options, and site info. The raffle section is the substantial one: a 54-envelope board, live 1-in-N odds, a jackpot trend chart, per-draw history, and admin-editable rules. Logging a draw rolls the jackpot, recomputes the odds, rejects a duplicate envelope, and records the winner automatically when the Queen turns up. Admin passwords are self-service from the dashboard — a hash in the database overrides the environment variable and signs every other device out.

    • Nav and homepage tiles are database rows — the team adds new apps without a deploy
    • Queen of Hearts: envelope board, live 1-in-N odds, jackpot trend chart, auto-recorded winner
    • Four-tab admin console covering events, the raffle, menu options, and site-wide settings
    • Next.js 16
    • React 19
    • TypeScript
    • Supabase (Postgres)
    • +1
    Visit cornerhouse.vercel.app

Algorithmic Trading

Signal-mining for markets

Same hypothesis-test-iterate discipline I bring to abuse detection, applied to equities momentum and volatility setups.

  • Gap Up + Fade Screener (v1)

    Shipped

    Pattern-mining predecessor to V9

    The first algorithmic screener I shipped. Configurable thresholds for the premarket gap (>2%) and intraday fade (<-1%), a parallel ThreadPoolExecutor scanning ~90 tickers, and a sortable result table with CSV export. The work that taught me how this signal actually behaves at scale — and what V9 needed to do better.

    • Configurable premarket-gap and intraday-fade thresholds
    • Parallel scan over ~90-ticker small-cap universe; custom watchlist supported
    • Sortable hit table with CSV export
    • Python
    • Streamlit
    • yfinance
    • pandas
    • +1
    Try the live screener
  • ML Momentum Screener

    Shipped

    Most advanced of the three screeners

    The current production model. Scrapes today's Finviz news per ticker (with a sub-20-minute 'breaking' flag), layers in pre-market and intraday flow signals, and ranks the universe by a composite score. ~1,700 lines of orchestrated screening logic — the iteration on V9 that added external catalyst awareness to the technical signals.

    • Live Finviz news scrape with 'breaking' flag for <20-minute headlines
    • Multi-timeframe momentum (premarket, intraday, 3D, 10D)
    • Composite scoring blending technicals with news catalysts
    • Python
    • Streamlit
    • yfinance
    • BeautifulSoup
    • +2
    Try the live screener
  • V9 Momentum Breakout Screener

    Shipped

    Real-time multi-signal momentum scanner

    An algorithmic equities screener I built to apply the same signal-mining discipline I used in trust & safety to financial markets. The V9 model fuses six independent technical signals into a single conviction score, ranks the universe live (alphabetical, randomized, or live-volume-ranked), and auto-refreshes every 60 seconds with audio alerts on watchlist hits. Powers the manual side of an end-to-end trading pipeline that includes backtesting, risk controls, and live execution.

    • Six-signal model: EMA10, RSI(7), 3D & 10D momentum, 10D relative volume, VWAP + order flow
    • Scans up to 2,000 tickers with a thread pool; 60-second auto-refresh
    • Three universe modes including live volume-ranked construction
    • Python
    • Streamlit
    • yfinance
    • pandas
    • +2
    Try the live screener

Experience

Career highlights

Full CV available on request.

Independent Security & Risk Consultant

Notification-platform engagement

Jan 2026 – Apr 2026

Built a domain-risk tool that closed a 68% vendor gap
  • Used signal analysis to surface that the incumbent third-party vendor was only catching ~32% of fraudsters — the other ~68% were getting through hijacked-domain attacks the vendor wasn't built to detect.
  • Built a domain-risk analyzer (SDAT — see the Domain Risk API project below) from scratch to target that exact gap, then partnered with Engineering to integrate it into the platform's vetting pipeline — turning a single-vendor pass into a full third-party-plus-supplemental vetting program.
  • Made it ops-configurable on purpose — scoring weights, rules, thresholds, and taxonomies all live in a UI so the compliance team can pivot to new fraud trends without an engineering release cycle.
  • That integration drove a 96% reduction in false-negative rate while holding false-positive rates flat — the signal-health metric I was optimizing for.
  • Same pipeline cut ~350 hours/month of manual review effort and improved enablement time by 90%, with full automation set to push both further.
  • Designed the behavioral risk scoring and identity-verification frameworks behind it — combining device intelligence, document authenticity, network reputation, and behavioral signals.

Staff Product Manager, Trusted Communications

Twilio Inc.

Jun 2022 – Apr 2025

  • Led Trust & Safety strategy for email and messaging abuse prevention protecting millions of users globally.
  • Designed detection and enforcement frameworks that reduced abuse incidents by 71% while minimizing impact to legitimate senders.
  • Built monitoring dashboards and reporting workflows in SQL, Looker, Tableau, Splunk, and Snowflake — used for executive reporting on enforcement, abuse trends, and policy effectiveness.
  • Investigated phishing, spoofing, malicious-link propagation, account compromise, and large-scale spam campaigns.
  • Collaborated cross-functionally with Security, Engineering, Legal, and carrier partners to deploy scalable anti-abuse controls.

Staff Messaging Compliance Program Manager

Twilio Inc.

Nov 2020 – Jun 2022

  • Led compliance and abuse-prevention strategy for A2P messaging ecosystems (10DLC, Short Code, Toll-Free).
  • Built automated enforcement workflows and carrier policy controls that reduced messaging violation rates by 40%.
  • Owned the weekly compliance operating rhythm — triaging carrier developments, escalating critical issues to senior leadership, and driving cross-functional remediation.
  • Defined KPIs and operational dashboards tracking violation frequency, MTTR, escalation trends, and enforcement effectiveness for executive reporting.
  • Improved compliance review throughput by 60% YoY; reduced average incident resolution time by 35%.
  • Developed training materials and internal documentation that scaled regulatory expertise across Product, Engineering, and Operations.

Compliance Specialist

Twilio Inc.

Jun 2020 – Nov 2020

  • Defined the original escalation workflows, monitoring procedures, and enforcement documentation that became the foundation of Twilio's compliance ops.
  • Designed the first-cut tooling and training materials for high-risk-account review — the patterns the team adopted as canonical for suspicious-traffic triage.
  • Served as escalation lead for compliance incidents, customer investigations, and enforcement response coordination — the operating model that informed the Staff PM role that followed.
  • Recognized with the Magic Owl Award for building the compliance department from the ground up.

Fair Billing Compliance Program Manager

Alliance Data (now Bread Financial)

Apr 2012 – Aug 2018

  • Founded and operationalized the Fair Billing compliance program: fraud identification, dispute resolution, ACH/Reg E.
  • Conducted risk assessments and root-cause analyses that reduced billing discrepancies and tightened operational controls.
  • Supported CFPB audits through reporting, operational analysis, and remediation planning.

Also worth noting

  • Quantitative Trading (Apr 2025 – present): Python data pipelines and algorithmic trading strategies across equities, futures, and options — backtesting, risk controls, and live execution.
  • Recognition: Superb Owl Award (Twilio, 10DLC compliance & carrier direct connections), Magic Owl Award (Twilio, building the compliance department from the ground up), President’s Circle nomination (Alliance Data / now Bread Financial, creating the debt-settlement function).
  • Core stack: SQL, Python, Snowflake, Looker, Tableau, Splunk, Jira, event stream analysis, behavioral analytics.

How I work

Operator’s instincts, engineer’s output

End-to-end ownership

Schema, API, mobile, web, billing — I’m comfortable owning the full stack and the product decisions that come with it.

Move fast, with rigor

AI-assisted development lets me ship at solo-builder speed without skipping the thinking — schemas, tests, and architecture still get the time they need.

Real problems

Every project here came from a real pain point — fraud teams drowning in signups, performers hunting gigs, venues looking for better bar nights.

Calm collaboration

I came up in operations. I can talk to legal, finance, and customers — not just engineers — and I write down decisions so the team can move on.

Contact

Let’s talk

I’m open to roles where I can keep building end-to-end and where my range — fraud, payments, marketplaces, live events — is an asset, not a curiosity. Happy to share deeper walkthroughs of any of the projects above.

Full resume available on request.