Trust and Safety Infrastructure for Horizontal Marketplaces
Horizontal marketplaces need layered defenses because fraud costs compound on both sides.

Horizontal marketplaces sell everything to everyone, and that's exactly the problem. A platform running gig bookings next to used furniture next to digital downloads has to protect two different people on every transaction: a buyer and a seller, each with a different risk profile and a different way of getting burned. This piece walks through what that protection actually looks like when you build it in layers, identity, fraud detection, content moderation, payments, and disputes, and why a weak link in any one of them wrecks the rest.
Vertical marketplaces get to cheat, a little. A platform selling only vintage watches or only freelance coding gigs knows its users cold, writes fraud rules for one category, and tunes everything around a narrow set of behaviors. Horizontal platforms carry a heavier burden: the same trust and safety stack has to catch a fake antique dealer, a rideshare driver using someone else's ID, and a scammer selling concert tickets that don't exist, all at the same time, on the same rails. In practice, a single fraud model stretched across all three has rarely held up.
The fraud losses that make building this infrastructure non-optional
The dollar figures settle the argument for anyone still on the fence. Online payment fraud cost businesses an estimated $44 billion in 2024, and the number is headed past $100 billion by 2029. Merchants are on track to lose $52.84 billion to online payment fraud in 2025 alone, which is not a rounding error on anybody's balance sheet.
The multiplier is where it gets ugly. Retailers lose $4.61 for every $1 of actual fraud once you count the fees, the shipping, and the chargebacks; add it all up and the true cost runs to $207 per $100 of fraud. This is a routine cost of doing business, not some rare event happening to a few unlucky merchants. Eighty-four percent of e-commerce merchants reported fraud attacks in the past year, so that's the baseline, not the exception. Twelve percent of online retailers lost more than $30 million each to fraud in 2024, and merchants overall spend an average of 11% of yearly revenue just managing the problem. Call it a tax, because functionally, that's what it is.
Horizontal marketplaces feel this differently than a single retailer does, because the platform absorbs damage from both directions. A scammed buyer doesn't just distrust one seller; they distrust the platform that let the seller list in the first place. A defrauded seller doesn't blame the buyer alone; they blame the marketplace that failed to catch it. No surprise, then, that the fraud detection market itself hit $57.51 billion in 2024, with projections putting it at $186.82 billion by 2030. Everyone's racing to build the same wall, and the wall keeps needing to be taller.
How the threat landscape has shifted as AI lowers the cost of sophisticated fraud
Here's the part nobody asked for: the same AI tools making product teams faster are making fraud rings faster too. Attack volumes across account takeover, synthetic identity fraud, payment fraud, and new account creation grew roughly 34% year over year across 2024 and 2025. AI-assisted fraud tooling has become increasingly accessible on dark web marketplaces, lowering the skill bar for running a sophisticated scam. You just need to know where to shop, which, unfortunately, is not hard.
Synthetic identity fraud, where someone stitches together a fake person from real and fabricated data, grew 311% in the U.S. from Q1 2024 to Q1 2025, and now accounts for 29% of e-commerce fraud loss at the point of transaction. Deepfake scams rose 28%. Both ride the same generative AI wave that legitimate platforms are trying to adopt for their own product features at the same time, which raises a question worth sitting with: are we building the tools that get used against us next quarter? More than 80,000 fraudulent online stores were flagged during the 2024 holiday season alone, and fake e-shop scams kept climbing into Q1 2025. AI-generated photos, videos, and reviews mean a counterfeit product can now ship with a product video that looks slicker than what the real manufacturer put out. There's something almost insulting about that, if you think about it too long.
Task scams deserve their own mention because the growth curve is steep enough to look like a typo. The FTC reported more than $220 million stolen and 20,000 reports in just the first half of 2024. Compare that to roughly 5,000 total reports across all of 2020 through 2023, and you start to wonder if the FTC's counters are even calibrated for this. Static, rule-based fraud defenses, the kind that flag a transaction because it matches a pattern from last year, can't keep pace with an adversary rewriting its own patterns every quarter. Layers that learn and adapt aren't a nice-to-have anymore. They're the entry fee.
Why consumer trust is eroding faster than most marketplace operators realize
Trust in the review system, maybe the oldest and simplest trust mechanism the internet ever built, is falling apart in real time. Consumer trust in online reviews as a substitute for a personal recommendation has been declining steadily, and the trend shows no sign of reversing. Twenty-one percent of U.S. consumers say they distrust online reviews outright, and 44% report seeing fake reviews on Amazon in 2025. However you slice that trend line, it's going one direction.
Research on Mercado Libre buyers found that the mere perception of fake reviews damages trust in the rating system as a whole, independent of whether any individual review was actually fake. A systematic review across 68 articles found negative reviews carry more weight on trust than positive ones do; bad signals travel farther and stick around longer. People also want detail over decoration: Research consistently finds that written text reviews feel more trustworthy than a star rating alone, and opposition to AI-generated reviews is a backlash already underway, not a hypothetical one.
The payment side shows the same anxiety. A substantial share of global e-commerce users prefer payment methods that don't share their data with merchants, and concern about payment fraud has been rising year over year. When something does go wrong, though, people want a human on the other end. Consumers consistently say they trust companies that make it easy to reach the people behind them, and good customer support ranks as a top driver of loyalty. Put those numbers side by side and you get a business problem: eroding review credibility plus payment anxiety doesn't just cost individual sales, it speeds up the exit of both buyers and sellers from the platform entirely.
Identity verification as the foundation layer, and why it must cover both sides of the transaction
Identity verification is the foundation layer of marketplace trust: it must cover both buyers and sellers, and the bar for what counts as "verified" has moved well past checking a driver's license photo. Biometrics and liveness detection, confirming a real person is actually present and not a photo or a mask, are now the baseline expectation. Behavioral and device signals, IP analysis, device fingerprinting, email and phone reputation, now supplement document checks, because deepfakes and account takeovers are built specifically to sail through document verification alone.
Gig-economy platforms carry a heavier burden here than pure e-commerce does. When a worker meets a stranger in a physical space, a failed identity check isn't just a fraud event, it's a safety incident, full stop. Gig workers aren't employees either, so the traditional HR verification workflow doesn't apply cleanly. That gap is exactly why purpose-built marketplace identity platforms exist as their own category, rather than being an afterthought bolted onto HR software.
Seller-side checks matter as much as buyer-side ones. Amazon's seller onboarding process includes verification steps before a new seller can list a single product, which catches fraud before it enters the marketplace instead of after a buyer complains. Purpose-built identity platforms for two-sided marketplaces now cover consumer onboarding, gig worker and seller verification, and ongoing account protection in a single stack. Other vendors are targeting the same full-lifecycle problem. Verification speed matters more than it sounds like it should, because verification that adds noticeable friction defeats the point of building a smooth marketplace at all. Nobody wants to sit through a loading spinner just to sell their old couch.
Here's the catch, though: identity verification alone can't finish the job. It confirms who someone is the moment they sign up, but it doesn't watch what they do six months later. That's a different layer's problem entirely.
Fraud detection across listings, reviews, and account behavior — where signals compound
Fake listings scale the way weeds do: quiet for a while, then everywhere at once. Amazon removed more than 7 million counterfeit listings in 2023, then seized over 15 million fake products in 2024, roughly doubling in a single year. What changed the math was proactive detection. Amazon's AI systems blocked over 99% of suspicious listings in 2024 before brand owners even reported them, which is the real shift: going from cleaning up a mess after the complaint to stopping the mess from forming at all.
Reviews got the same treatment. Amazon blocked more than 275 million suspected fake reviews in 2024 before they ever reached a live product page. Meanwhile, refund and policy abuse became the single most common e-commerce fraud type in 2024, hitting 48% of global merchants, and it barely looks like fraud on paper, because it exploits normal-seeming behavior rather than obviously stolen credentials. Chargebacks are projected to cost merchants more than $100 billion in 2025, and 61% of those disputes trace back to friendly fraud. So the real detection challenge, increasingly, is telling a legitimate complaint apart from someone gaming the system.
Task scams show the underlying principle clearly: any incentive a platform offers, account creation bonuses, rating boosts, referral rewards, booking credits, gets manufactured at scale by someone willing to try. The fix is verifying the seller, the device, and the location before that listing ever goes live, rather than reviewing it only after a buyer complains. The signals have to compound instead of sitting in separate silos. Given that counterfeiting and piracy are projected to cost global businesses $4.2 trillion by 2025 according to the International Chamber of Commerce, spending real money on platform-level detection stops looking like overhead and starts looking like the only rational move on the table.
Content moderation as a distinct layer — what AI handles, what humans must decide, and where hybrid models operate
Content moderation operates as a distinct layer where AI handles volume efficiently but human judgment remains essential for gray-area decisions. Moderation APIs from OpenAI, AWS, and Hive now catch a large share of obvious abuse cheaply and fast, which makes them a decent first triage layer. Their limits show up quickly, though: AI handles scale well, sorting millions of posts, images, and listings for obvious violations, the stuff that doesn't require a second thought.
What AI still struggles with is the gray area: category-specific risk, fraud engineered specifically to slip past an automated filter, situations that need context or empathy rather than pattern matching. All of that still needs a person behind the decision. Vendor studies report accuracy in the mid-to-high 90s for leading systems, though that number swings a lot depending on the platform, the training data, and the specific test case someone picked to run. Nobody should treat a vendor benchmark as gospel across every context, and that lesson tends to arrive after the fact.
The dominant setup in production right now is hybrid: automated systems handle initial triage, human reviewers step in on escalations, distributed teams cover the globe across time zones. That structure isn't going away soon, especially since moderation is caught in the same arms race as fraud detection. Analysis of phishing activity has found that AI-generated content is increasingly common in fake sites, meaning the fakes moderators hunt for keep getting more convincing. Horizontal scope adds its own wrinkle too: training data and rules built for electronics listings don't transfer cleanly to service bookings, so moderation policy needs to be modular and category-aware instead of one-size-fits-all. There's a real cost to overcorrecting as well. False positives suppress legitimate seller listings and frustrate honest buyers, so calibrating the system matters just as much as catching bad actors in the first place.
Payment security and dispute resolution as the last line of defense and the primary trust signal for users
Payment security operates as its own layer, separate from identity, covering AML compliance automation, transaction-level fraud engines, and chargeback management. It's also, oddly enough, a trust signal before fraud even happens. Recall that seven in ten global e-commerce users prefer payment methods that don't share their data with merchants; people are making judgments about a platform's safety before a single transaction goes wrong.
Escrow and staged release lower the temperature structurally. Holding funds until a milestone is met protects the buyer and gives both sides a built-in resolution path without a formal dispute process kicking in every time. When disputes do happen, though, how fast and how fairly they get resolved shapes confidence on both sides of the transaction, not just the side that filed the complaint.
Friendly fraud complicates this further. With 61% of chargeback disputes tied to friendly fraud, the resolution system has to sort legitimate claims from policy abuse, which is a categorization problem as much as a processing one. That link between accessible customer support and loyalty applies directly here: dispute resolution is the moment that either proves everything the earlier layers promised, or quietly undoes it. A buyer who loses a dispute unfairly leaves the platform. A seller hit with repeated fraudulent chargebacks leaves too, just through a different door.
How the layers interact — and why failure in one undermines all the others
None of these layers work in isolation, and treating them like they do might be the single biggest mistake an operator can make. Identity verification catches fraud at the door, sure, but it creates a false sense of security if nobody's watching behavior after that door closes. Content moderation flagging a suspicious listing only means something if seller verification already confirmed whether that seller is even real. The layers have to share signals rather than operate as separate departments checking separate boxes.
A strong payment fraud engine that catches every transaction anomaly still won't save you if it feeds into a slow, opaque dispute process on the back end. Speed and fairness in resolution matter as much as detection accuracy, because a user's actual experience is "it took three weeks to get my money back," which, from where they're sitting, is the whole story regardless of how the fraud got caught.
Synthetic identity fraud is the clearest example of an attack that targets the seams between layers specifically. That 311% growth figure from earlier isn't fraud that beats identity verification outright; it's fraud that passes verification cleanly and only reveals itself later in behavioral patterns nobody was watching for. Review integrity works the same way as connective tissue. Once users know reviews can be faked, they discount seller reputation signals across the board, which undermines the verification layer even though verification itself never actually failed.
This is the compounding failure mode worth sitting with for a second. One weak layer puts pressure on the layers next to it, which pushes teams toward more restrictive policies, which adds friction for legitimate users, which drives them away. Defense in depth, here, means complementarity rather than redundancy for its own sake: each layer built to catch specifically what its neighbors miss.
Organizational and operational decisions that determine whether the infrastructure actually works
Every marketplace eventually faces the build versus buy versus partner question, and there's no universally correct answer to it. Purpose-built platforms like Socure or Veriff offer speed to market. Assembling point solutions offers customization. Building everything internally offers control, at the cost of maintenance that never really ends. Each path trades speed for customization for cost in a slightly different ratio, and picking one is less about finding the "right" answer than picking which tradeoff you can live with.
One thing you shouldn't outsource, regardless of which path you pick, is the strategy itself. You have to own the policy calls, the definitions of what counts as an edge case, and the calibration of how much friction is acceptable for legitimate users. A vendor can supply the engine. Only you get to decide what your platform is willing to tolerate.
Underinvesting here is a false economy, and the 11% of revenue merchants already spend managing fraud makes that case on its own. Treat trust and safety like a cost center and you end up spending more later, reactively, cleaning up damage instead of preventing it. Calibration isn't a one-time setup either; thresholds you tune for one GMV level or one fraud environment will generally need adjusting as your platform grows and as threat actors adapt around whatever defense just got deployed. Every tightening of fraud controls has to get tested against conversion impact, which means the people running trust and safety need access to actual user experience data, not just fraud metrics sitting in a separate dashboard somewhere.
Ultimately this work spans engineering building the detection systems, operations running the moderation queues and dispute handling, legal covering compliance and AML, and product managing the UX friction all of it creates. No single department owns trust and safety cleanly, and that's probably the point. A marketplace spanning this many categories and this many kinds of risk was never going to get solved by one team working alone in a room.


