After vetting a large volume of creator profiles in production, one thing becomes clear: the creators who present the most risk to a platform's processor relationships rarely look risky. They look ordinary. The interesting question is not what prohibited activity looks like — everyone can picture that — but what it looks like when someone is actively trying to make it look like something else.
This article describes, at the level of pattern rather than instruction, the recurring shapes we see when a compliant-looking storefront is a front for non-compliant activity. The point is not to catalogue techniques for anyone to copy; it is to help platform risk teams recognize the structure of the problem they are actually facing.
The mismatch is the signal
The single most reliable characteristic across these patterns is a mismatch between what a creator appears to sell and what they actually transact. The visible storefront is chosen precisely because it is unremarkable — a generic digital product, a small physical item, a nominal service. The price is often low and round, functioning less as a real product and more as a payment placeholder.
What makes this hard to catch is that the visible side is genuinely clean. There is nothing wrong with the listing. A reviewer looking only at the storefront finds a compliant page because it is a compliant page. The violation is not in what is shown; it is in the gap between what is shown and what is happening. Recognizing that the mismatch itself — not any single visible element — is the thing to look for is the first shift a risk team has to make.
Where the real business is visible
If the prohibited business is not on the storefront, it has to be somewhere, because the creator still needs buyers to find it. That somewhere is off-platform, and it is where the actual pattern becomes legible.
The recurring shape is that the audience is acquired in one place and the payment is collected in another. A creator builds demand in a community organized around the prohibited activity — wherever its buyers gather — and then routes those buyers to the innocuous on-platform storefront to pay. The two halves of the business live in different places on purpose, because keeping them separate is what lets the payment side look clean.
This is why inbound traffic sources are so revealing. A storefront selling a generic digital item that draws a large share of its visitors from a community organized around prohibited activity is describing its real business through its traffic, even as its listing describes a fictional one. The audience does not match the ostensible product. That mismatch, again, is the signal.
The role of outbound links
The mirror image of inbound traffic is outbound linking. Some patterns run the other direction: the on-platform presence is the storefront of record, but the creator's own outbound links — from their profile, their posts, their linked accounts — point toward the channel where the prohibited transaction is actually arranged.
Following where a creator sends people is often more informative than reading what they say. A profile can describe anything. The destinations it links to are harder to dress up, because they have to actually work for the real business to function. A link graph that terminates in prohibited channels tells a story the profile copy is written to obscure.
Why these patterns defeat single-signal review
The common thread across all of these is that no single on-platform signal is sufficient to catch them. The storefront is clean. The listing text passes. The price is unremarkable. Each individual element, examined alone, looks fine, which is exactly the point — the pattern is engineered so that every isolated check passes.
What catches them is assembling the signals into a relationship: this clean storefront, plus this inbound traffic from a prohibited community, plus these outbound links to a prohibited channel, add up to a picture that none of the pieces convey alone. This is what an evidence graph is for. The individual facts are ambiguous; the connections between them are not.
What this means for platform risk teams
The practical implication is that a review process built around checking storefronts one at a time will systematically miss the highest-intent bad actors, because those actors have specifically arranged for their storefronts to survive that kind of check. The creators easiest to catch — the ones who put the prohibited activity right on the listing — are also the least sophisticated and often the least damaging.
The ones that generate real processor exposure are the ones who understood the review process and built around it. Catching them requires looking at the relationships between on-platform and off-platform signals, before the payout, rather than examining the storefront in isolation after the fact. The pattern is consistent enough that it can be looked for deliberately — which is the whole basis for treating payout compliance as a distinct, signal-driven discipline rather than an extension of storefront review.
This article describes risk patterns at a general level for the purpose of helping platforms recognize and defend against them. It is provided for educational purposes and is not legal or compliance advice. Details are deliberately kept at the level of pattern rather than method. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.
Pattern Intelligence
8 min read
How Creators Hide Prohibited Sales Behind Innocuous Storefronts: Patterns From Production
Creators who want to get paid for prohibited activity have a small number of recurring tactics for looking compliant. Drawn from patterns seen in production, here is the shape of how a clean storefront hides a non-compliant business.
Mahesh Premachandran
Founder, Tumban
After vetting a large volume of creator profiles in production, one thing becomes clear: the creators who present the most risk to a platform's processor relationships rarely look risky. They look ordinary. The interesting question is not what prohibited activity looks like — everyone can picture that — but what it looks like when someone is actively trying to make it look like something else.
This article describes, at the level of pattern rather than instruction, the recurring shapes we see when a compliant-looking storefront is a front for non-compliant activity. The point is not to catalogue techniques for anyone to copy; it is to help platform risk teams recognize the structure of the problem they are actually facing.
The mismatch is the signal
The single most reliable characteristic across these patterns is a mismatch between what a creator appears to sell and what they actually transact. The visible storefront is chosen precisely because it is unremarkable — a generic digital product, a small physical item, a nominal service. The price is often low and round, functioning less as a real product and more as a payment placeholder.
What makes this hard to catch is that the visible side is genuinely clean. There is nothing wrong with the listing. A reviewer looking only at the storefront finds a compliant page because it is a compliant page. The violation is not in what is shown; it is in the gap between what is shown and what is happening. Recognizing that the mismatch itself — not any single visible element — is the thing to look for is the first shift a risk team has to make.
Where the real business is visible
If the prohibited business is not on the storefront, it has to be somewhere, because the creator still needs buyers to find it. That somewhere is off-platform, and it is where the actual pattern becomes legible.
The recurring shape is that the audience is acquired in one place and the payment is collected in another. A creator builds demand in a community organized around the prohibited activity — wherever its buyers gather — and then routes those buyers to the innocuous on-platform storefront to pay. The two halves of the business live in different places on purpose, because keeping them separate is what lets the payment side look clean.
This is why inbound traffic sources are so revealing. A storefront selling a generic digital item that draws a large share of its visitors from a community organized around prohibited activity is describing its real business through its traffic, even as its listing describes a fictional one. The audience does not match the ostensible product. That mismatch, again, is the signal.
The role of outbound links
The mirror image of inbound traffic is outbound linking. Some patterns run the other direction: the on-platform presence is the storefront of record, but the creator's own outbound links — from their profile, their posts, their linked accounts — point toward the channel where the prohibited transaction is actually arranged.
Following where a creator sends people is often more informative than reading what they say. A profile can describe anything. The destinations it links to are harder to dress up, because they have to actually work for the real business to function. A link graph that terminates in prohibited channels tells a story the profile copy is written to obscure.
Why these patterns defeat single-signal review
The common thread across all of these is that no single on-platform signal is sufficient to catch them. The storefront is clean. The listing text passes. The price is unremarkable. Each individual element, examined alone, looks fine, which is exactly the point — the pattern is engineered so that every isolated check passes.
What catches them is assembling the signals into a relationship: this clean storefront, plus this inbound traffic from a prohibited community, plus these outbound links to a prohibited channel, add up to a picture that none of the pieces convey alone. This is what an evidence graph is for. The individual facts are ambiguous; the connections between them are not.
What this means for platform risk teams
The practical implication is that a review process built around checking storefronts one at a time will systematically miss the highest-intent bad actors, because those actors have specifically arranged for their storefronts to survive that kind of check. The creators easiest to catch — the ones who put the prohibited activity right on the listing — are also the least sophisticated and often the least damaging.
The ones that generate real processor exposure are the ones who understood the review process and built around it. Catching them requires looking at the relationships between on-platform and off-platform signals, before the payout, rather than examining the storefront in isolation after the fact. The pattern is consistent enough that it can be looked for deliberately — which is the whole basis for treating payout compliance as a distinct, signal-driven discipline rather than an extension of storefront review.
This article describes risk patterns at a general level for the purpose of helping platforms recognize and defend against them. It is provided for educational purposes and is not legal or compliance advice. Details are deliberately kept at the level of pattern rather than method. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.