# Mockup Safety Guidelines — Digital Red Flags

TrueTraceShorts scam screens must be controlled, fictional, and safe.

## Default

For scam-screen content, prefer deterministic renderer-owned mockups over free-form AI images.

Use deterministic mockups for:

- SMS screens
- email screens
- invoices
- login pages
- payment routes
- QR/payment situations
- marketplace chats
- popup warnings
- screenshot checklist cards

## Forbidden in Mockups

No real:

- brand names or logos
- bank names or bank details
- IBANs, account numbers, routing numbers
- phone numbers
- QR codes or barcodes
- real domains
- real addresses
- real people, firms, or copied scam examples

Use reserved fictional domains only when needed, e.g.:

- `example.com`
- `example-login.com`
- `example-delivery.com`

Do not create realistic malicious paths or reusable phishing templates.

## Safe Copy Rules

Use plain, fictional text that shows the red flag without teaching the scam.

Good:

```text
Your package is on hold
Pay CHF 1.95
Delivery expires today
track.example-delivery.com
```

Bad:

- real courier names
- real bank names
- live-looking QR codes
- real phone numbers
- complete step-by-step fraud flow

## Claim Safety

Do not say:

- “This catches every scam.”
- “You are safe if you do this.”
- “All scammers do X.”

Say:

- “A common red flag is…”
- “Before you pay, check another way.”
- “This does not catch everything, but it gives you a safer next step.”

## AI Image Boundary

AI images may provide atmosphere: desk, phone in hand-free setup, room, lighting, premium texture.

AI images should not invent the actual scam screen when exact text/data/legibility matters. The scam screen should be deterministic whenever possible.
