Archive position — measured, not model output
5 likes on Devpost
54 of the 7,856 archived projects have more likes, and 35 share exactly 5 — so this project's #55 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
Astartis x Codex is a self-reported developer security control plane built around deterministic policy enforcement and integration with AI tools like Codex/GPT-5.6. It claims to offer a hyper-scalable, low-cost system designed for regions where enterprise-grade cybersecurity infrastructure is unaffordable, such as Botswana.
What changed
The project description indicates that the author built this system using C++ and integrated it with Codex/GPT-5.6 for debugging and development workflow enhancement. It includes a dashboard and plugin architecture allowing Codex to interact with security controls in limited ways.
The single most important open question
Is there any evidence of actual deployment, usage or traction beyond the author's own development environment?
Note: This analysis is based entirely on self-reported information from the project description provided. No independent verification or external data has been used. All claims are stated by the author and not independently confirmed.
What The Product Actually Is
The description states that Astartis x Codex is a developer security control plane built around deterministic policy enforcement, using a combination of:
- A rule engine with entropy/chaos analysis for threat signals
- WORM-style protected evidence and hash-linked audit chain
- NAC admission and Zero Trust access evaluation
- Recovery, decoy, sandbox, attribution, and rule evidence surfaces
- Opt-in local Npcap metadata capture
- A safe, allowlisted diagnostic terminal
- A routed catalogue of 77 security-agent definitions (65 JSON personas and 12 ECC agent definitions)
It also includes a dashboard and a local plugin that integrates Codex with seven narrow MCP tools for investigation, explanation, remediation, and verification purposes.
Inference: The system appears to be a hybrid of deterministic security enforcement and AI-assisted workflow integration, intended for use in developer environments or small-scale deployments.
Positioning & Claim Evolution
The author positions Astartis x Codex as:
- A hyper-scalable, low-cost solution for regions like Botswana where enterprise-grade cybersecurity is unaffordable.
- A system built with compliance in mind (e.g., Zero Trust, NIST CSF, Botswana Data Protection Act).
- An alternative to opaque automation, emphasizing evidence-based control and deterministic enforcement.
It claims to be:
- Designed to run on ordinary hardware (laptop or server) via configuration changes.
- Built using C++ and integrated with Codex/GPT-5.6 for debugging and development workflow support.
- A deterministic policy authority that allows Codex to investigate, simulate, and verify actions without making destructive changes.
Claim vs Fact: These are claims made by the author; no evidence of actual deployment or adoption is provided.
Target Customer & ICP
The description states:
- The system targets small companies and solo developers who cannot afford enterprise-grade cybersecurity systems.
- It is designed for use in regions like Botswana where cloud hosting is expensive and infrastructure unreliable.
- The target includes developers working on security tools or environments that require compliance with frameworks like NIST CSF, SOC 2, ISO 27001, etc.
Inference: The ICP appears to be individual developers or small teams in low-resource environments who need affordable, scalable, and compliant security solutions.
Business Model & Pricing Evidence
Not evidenced.
Note: No information is provided about pricing models, monetization strategies, or business model assumptions. The description does not mention any revenue streams or customer acquisition plans.
Technical & Delivery Signals
The author reports:
- Built using C++, Phoenix, Node.js
- Uses Codex/GPT-5.6 for debugging and development workflow enhancement
- Implements a local MCP control plane plugin
- Integrates with NAC, Zero Trust, WORM locks, Veeam backup locking, and other security components
- Includes opt-in permissions for destructive capabilities
- Supports configuration changes via GitHub repo
Inference: The system is built on a hybrid architecture combining deterministic C++ components with AI-assisted development workflows. It emphasizes safety through opt-in permissions and simulation-based access.
Traction & Maturity Signals
Not evidenced.
Note: There is no mention of actual users, customers, revenue, or adoption metrics. The project is described as a hackathon submission and a personal development effort.
Competitive Context
The description does not provide any information about competitors or market positioning beyond self-reported claims.
Inference: Based on the author's framing, this appears to be positioned against opaque automation tools in cybersecurity, possibly competing with enterprise-grade platforms that are too expensive for small developers or regions like Botswana.
Key Risks & Red Flags
- Unverified Claims: All technical and compliance features are self-reported without third-party validation.
- No Traction Evidence: No data on users, customers, or revenue is provided.
- Single Developer Team: The team size is listed as one person (kgosi blanda), raising questions about scalability and support.
- Limited Scope of Use: The system is described as a developer tool with limited production-grade functionality.
- Unclear Commercial Viability: No indication of how the product will be monetized or scaled beyond personal development.
Inference: There is a high risk that this remains a prototype or proof-of-concept rather than a viable commercial offering.
Diligence Questions To Ask The Founders
- What specific compliance frameworks have been implemented, and how are they validated?
- Is there any real-world testing or deployment of the system outside of development environments?
- How does the integration with Codex/GPT-5.6 work in practice? Are there performance or accuracy limitations?
- What is the roadmap for converting simulated features into production-grade functionality?
- Has the author considered how to scale beyond a single developer team?
- Are there any plans for monetization or commercial partnerships?
Investment/Partnership Verdict
Not evidenced.
Note: No evidence of financials, traction, or strategic fit is available to assess investment or partnership potential. The project appears to be in early development stage and lacks key signals that would indicate readiness for investment or partnership.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
