Flipkart Marketplace Platform  ·  View 25 of 25  ·  7 · Assurance

Trust and Marketplace Governance

How the marketplace polices itself, from a signal to an enforcement anyone can appeal.

Editable source SVG draw.io All views
Signal Detect Decide Act Appeal Seller risk KYC, GSTIN, bank Cancel and SLA rate Risk band model KServe Auto or analyst band threshold Payout hold, delist Evidence upload SLA 72 h Buyer abuse Return and RTO rate Abuse score graph features Instant refund gate Inspect before refund Care override Payment fraud Device, velocity, BIN Real-time scoring Flink · 40 ms Allow, step-up, block 3DS or decline Chargeback defence Counterfeit and content Listing text and image Brand complaint Classifier + brand match Azure OpenAI Moderation queue Take down listing Seller counter-notice Review integrity Review burst pattern Ring detection graph clustering Confidence threshold Suppress and reweight Trust and Marketplace Governance — Signal to Enforcement External / third party Queue / topic Security / platform Decision point Application we own Person or role Every enforcement writes an immutable decision record with the model version and the features that fired, because an appeal that cannot be reconstructed is an appeal that will be lost. Review integrity has no appeal path by design: suppression is silent. v 1.0 · owner Trust and Safety Architecture · date 2026-09

Why this is architecture, not a policy document

  • Seller vetting and real-time marketplace monitoring are first-class components with their own stores, models and SLAs
  • Enforcement writes an immutable decision record naming the model version and the features that fired — an appeal that cannot be reconstructed will be lost
  • Risk band is an input to payout timing, Buy Box eligibility and listing limits, so trust has commercial consequences by design

Decisions

  • Real-time scoring in Flink with a 40 ms budget for payment fraud; asynchronous scoring for everything that can wait
  • Human review is the default above the automation threshold, and the threshold is a tunable, not a constant
  • Counterfeit detection combines a classifier with brand-registry matching, because neither alone survives an appeal

Deliberate gaps

  • Review integrity has no appeal path: suppression is silent by design, which is a stated policy choice
  • Collusion between a buyer and a seller is detectable only in aggregate, so it is a batch graph job, not a real-time score
  • Model bias review is a quarterly process outside this architecture and needs an owner