SL2Z - Anti-phishing Google Extension
SL2Z is a browser-enabled cloud service that enhances email security and web privacy by contextually training and warning users directly in their email client. It also audits a user's current settings, with the option to automatically optimize basic Gmail settings and guidance through the adjustments that require user intervention.
Onboarding tour
A guided onboarding tour surfaces the product's most valuable features, each step paired with an animation. It opens by flagging low-security Gmail privacy settings - learn and fix each one individually, or resolve them all with a single click.

Training-email detection
When a training email arrives, SL2Z highlights the parts of the message that signal a threat - risky language, a suspicious attachment or link - and walks the user through reporting the phishing attempt to Google.

Simulation templates
Administrators manage the library of simulation emails, each tagged by threat type - phishing, sender spoofing, spelling mistakes, malicious attachments - so users train against the patterns they will actually encounter.

User management
Admins invite other administrators, set roles, and manage user access to the application from a single roster.

About the project
SL2Z is a browser-based cloud platform that helps users strengthen their email security and privacy through contextual training and alerts delivered directly inside their Gmail interface. The project was a lightweight, scalable prototype built for demos and investor showcases while simplifying cybersecurity awareness for everyday users. Despite tight timelines and limited resources, the team delivered a functional MVP ready for user testing and demo presentations.
The Challenge
Creating a demo-ready product for security-awareness training in a high-trust, high-risk environment posed several UX and technical challenges.
Key issues identified
- Users had low awareness of risky email behavior.
- Gmail settings were often misconfigured or outdated.
- Training tools were not integrated into the user's workflow.
- Timeline and resources were extremely limited.
- No integration with external platforms (NMS, CRM, ERP).
The Goals
Define and deliver a minimally viable product that could onboard and service new customers as quickly as possible.
Key resolutions
- Contextual security tips driven by user behavior.
- A guided Gmail settings audit for stronger privacy.
- An interactive product demo for investor presentations.
- A clean UI accessible to users of varying technical skill.
- A scalable framework with room for cross-platform expansion.
Product roadmap
UX that drives alignment
What made the roadmap impactful wasn't the layout - it was how it helped the team think, plan, and align around what mattered most. A Now / Next / Future board kept the product's direction legible at every stage.
-
Clarity through structure
A Now / Next / Future layout makes the product's direction legible at a glance - what's shipping, what's queued, and what's on the horizon.
-
Context built in
Every card carries its responsible team and a user-impact tag, so work is prioritized by effort against value, not opinion.
-
One source of truth
A single aligned space where every team, from Design to Dev, can see what's being worked on and what comes next.
-
Built for iteration
A modular, reusable layout, so the roadmap can be updated or expanded with minimal friction as the product grows.
Discovery
Stakeholder interviews
Before any user story went into development, conversations with stakeholders clarified and confirmed the acceptance criteria. Example Mapping kept those sessions focused on the smallest pieces of user behavior - teasing apart the rules, finding the core behavior to build, and deferring the rest until later.
Strategy
Design strategy
SL2Z is a cloud service that uses a Chrome browser extension and client-side code injection to surface potential threats inside a user's email and train them to recognize and report malicious content - simulated in the prototype. It also audits the user's settings, optimizing basic Gmail privacy automatically and guiding them through the rest.
Target audience
Product tasks
- Build the cybersecurity literacy of everyday users.
- Prevent cyber leaks and hacks for corporations.
- Simplify the management of Gmail privacy settings.
Architecture
User flows
User flows mapped the path a user takes from first touch to final interaction, shaping the strategy and an intuitive information architecture across the product's core journeys.
Handling a risky email
Review, then report it - blacklist the sender, block its links and attachments - or whitelist it to clear the warning.

Improving Gmail privacy
Surface the issue, decide, and fix it - automatically where possible, with user intervention where needed.

Getting the extension
Download from the landing page or the Chrome Web Store, then sign up.

First-run onboarding
The extension modal, personal configuration, and a first look at a risky email.

Validation
Usability testing
We ran usability testing to surface issues in the design and learn how the target users actually behave - tracking every finding to resolution before the demo build.
This whole experience has been a great journey for me, a lot of learning and excitement! I am positive that we will continue building this product together.