← All work
Company Mercado Libre
Team Security
Role UX Designer
Year Present

Trust, without the friction.

Designing re-authentication and factor flows for Mercado Libre and Mercado Pago — where every second of friction saved has to survive security review, and every security decision has to survive a user's patience. This case study documents the framework, not the pixels.

§ The question that anchors the work
How do we make it feel secure without generating more friction?
§ 01 Context

An ecosystem where trust is the product.

Mercado Libre is Latin America's largest commerce ecosystem, and Mercado Pago is its fintech arm — together, they move real money for hundreds of millions of users across the region. When someone opens the app to send money to family, pay rent, receive a salary, or check on a business, the security layer is the invisible thing that stands between their account and someone who shouldn't have it.

I joined the security team as a UX Designer. My surfaces are Reauth — the flows that verify a user is still who they say they are — and the factor flows that resolve those verifications: SMS, biometric, code, and beyond. Web and mobile. Mercado Libre and Mercado Pago.

A note on confidentiality

Due to the sensitive nature of this work, no product surfaces, feature specifics, or shipped metrics appear in this case study. What follows is the framework — how I think about the problem — not the deliverables.

§ 02 The challenge

A design problem that lives on a fault line.

Every security decision sits on a fault line between two costs. Add a step, and you protect users — but slow them down. Remove a step, and you speed them up — but you may expose them to a risk they never agreed to.

Every design I ship in this space starts from a single question:

"How do we make it feel secure without generating more friction?"

That question sounds simple. It isn't. It requires holding two counter-intuitive truths at once:

  1. More UI does not equal more security. Sometimes it equals more abandonment — and users who abandon a security flow tend to circumvent it entirely.
  2. Zero friction is not the goal. The goal is trust — and a completely invisible security layer teaches users to trust nothing.

The design lives in the narrow band between those two failures.

§ 03 My role

Designing for the moment the system says "prove it."

As UX Designer on Reauth and factor flows, I contribute to the surfaces users interact with when the system needs to re-verify who they are — from the trigger, through the challenge, to completion and re-entry into whatever they were doing. This is a domain where multiple designers rotate through the work, so the design is collaborative by nature and the ownership is shared.

The work spans Mercado Libre and Mercado Pago, and both platforms — web and mobile. But the real complexity isn't only in the interface. Every decision has to hold together across business goals, user needs, compliance requirements, and other measured concerns like fraud prevention and factor conversion. Alignment across those forces is the design problem as much as the pixels are.

And the design never finishes in a single pass. What worked last quarter may shift with a new threat pattern, a policy change, or new user data — so we're constantly reviewing metrics, adjusting, and re-testing to keep the balance right between security and usability.

I also use AI to pull real usage data and behavioral signals directly, instead of relying on assumptions or secondhand summaries — it shortens the distance between a question and an answer grounded in what users are actually doing, and reduces ambiguity before a design decision gets made.

§ 04 Approach

Two principles that hold the work together.

Every decision in this space passes through two filters. They're simple to state and much harder to hold to under pressure.

01 — Design in the user's mental model, not the technical one

System architecture has its own vocabulary — tokens, sessions, factor strength, risk scoring, session propagation. The user has none of that. They know: "I was doing something, and now the app is asking me something." Every design decision I make starts from that framing. What does the user believe is happening? Only then do we translate the technical need into a step that fits their model.

02 — Simplicity carries more security than complexity

There's a temptation, in security work, to add: another warning, another confirmation, another explanation. The evidence points the other way. Users skim, dismiss, or abandon complex flows — which leaves them less protected than they were before. The strongest security surface is one users can actually complete. Simplicity isn't the enemy of security. It's often its most under-used tool.

§ 05 Signals I measure

Two numbers tell me if the design is working.

Security work is hard to instrument without either violating privacy or drowning in noise. But there are two signals that consistently tell me the truth about whether a flow is landing.

Factor conversion
Of the users who hit a challenge, how many complete it
Drop-off
Where in the flow users fall off — and at which factor

Factor conversion is the ceiling on how well the mechanic can do its job — because a factor that no one finishes is a factor that doesn't protect anyone. Drop-off is where the design speaks: every drop-off point is either a UX gap I can close or a friction pattern I need to re-evaluate.

Both metrics are surface-agnostic. Whether the flow is SMS, biometric, or code, they tell me the same story about whether the design served the user's actual need — which is to get back to what they were trying to do.

§ 06 What this domain has taught me

Reflections from the security surface.

The user is not the adversary

In security work, it's easy to design as if every reduction in friction is a hole in the wall. But the actual adversary is the attacker — and the user completing the flow is the ally. Every point of friction the legitimate user faces is one they might route around, leaving them less safe than a small, well-designed step would have kept them.

Security is a design surface, not a warning label

The strongest security experience feels considered, not defensive. When the mechanic disappears into the flow of what the user was trying to do, they trust the system more, not less.

You don't ship security — you ship access

The metric that matters isn't "was this flow secure enough?" It's: did the user get back to what they were doing, and did we keep the wrong person out along the way? Both, together.