OpenAI 2026 hackathon

Astartis x Codex

I built a developer security control plane around evidence, not opaque automation and its called astartis x codex

Solo project by kgosi blanda · 5 likes · 0 comments

Archive position — measured, not model output

5 likes on Devpost

54 of the 7,856 archived projects have more likes, and 35 share exactly 5 — so this project's #55 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Astartis x Codex is a self-reported developer security control plane built around deterministic policy enforcement and integration with AI tools like Codex/GPT-5.6. It claims to offer a hyper-scalable, low-cost system designed for regions where enterprise-grade cybersecurity infrastructure is unaffordable, such as Botswana.

What changed

The project description indicates that the author built this system using C++ and integrated it with Codex/GPT-5.6 for debugging and development workflow enhancement. It includes a dashboard and plugin architecture allowing Codex to interact with security controls in limited ways.

The single most important open question

Is there any evidence of actual deployment, usage or traction beyond the author's own development environment?

Note: This analysis is based entirely on self-reported information from the project description provided. No independent verification or external data has been used. All claims are stated by the author and not independently confirmed.

Back to contents

What The Product Actually Is

The description states that Astartis x Codex is a developer security control plane built around deterministic policy enforcement, using a combination of:

  • A rule engine with entropy/chaos analysis for threat signals
  • WORM-style protected evidence and hash-linked audit chain
  • NAC admission and Zero Trust access evaluation
  • Recovery, decoy, sandbox, attribution, and rule evidence surfaces
  • Opt-in local Npcap metadata capture
  • A safe, allowlisted diagnostic terminal
  • A routed catalogue of 77 security-agent definitions (65 JSON personas and 12 ECC agent definitions)

It also includes a dashboard and a local plugin that integrates Codex with seven narrow MCP tools for investigation, explanation, remediation, and verification purposes.

Inference: The system appears to be a hybrid of deterministic security enforcement and AI-assisted workflow integration, intended for use in developer environments or small-scale deployments.

Back to contents

Positioning & Claim Evolution

The author positions Astartis x Codex as:

  • A hyper-scalable, low-cost solution for regions like Botswana where enterprise-grade cybersecurity is unaffordable.
  • A system built with compliance in mind (e.g., Zero Trust, NIST CSF, Botswana Data Protection Act).
  • An alternative to opaque automation, emphasizing evidence-based control and deterministic enforcement.

It claims to be:

  • Designed to run on ordinary hardware (laptop or server) via configuration changes.
  • Built using C++ and integrated with Codex/GPT-5.6 for debugging and development workflow support.
  • A deterministic policy authority that allows Codex to investigate, simulate, and verify actions without making destructive changes.

Claim vs Fact: These are claims made by the author; no evidence of actual deployment or adoption is provided.

Back to contents

Target Customer & ICP

The description states:

  • The system targets small companies and solo developers who cannot afford enterprise-grade cybersecurity systems.
  • It is designed for use in regions like Botswana where cloud hosting is expensive and infrastructure unreliable.
  • The target includes developers working on security tools or environments that require compliance with frameworks like NIST CSF, SOC 2, ISO 27001, etc.

Inference: The ICP appears to be individual developers or small teams in low-resource environments who need affordable, scalable, and compliant security solutions.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

Note: No information is provided about pricing models, monetization strategies, or business model assumptions. The description does not mention any revenue streams or customer acquisition plans.

Back to contents

Technical & Delivery Signals

The author reports:

  • Built using C++, Phoenix, Node.js
  • Uses Codex/GPT-5.6 for debugging and development workflow enhancement
  • Implements a local MCP control plane plugin
  • Integrates with NAC, Zero Trust, WORM locks, Veeam backup locking, and other security components
  • Includes opt-in permissions for destructive capabilities
  • Supports configuration changes via GitHub repo

Inference: The system is built on a hybrid architecture combining deterministic C++ components with AI-assisted development workflows. It emphasizes safety through opt-in permissions and simulation-based access.

Back to contents

Traction & Maturity Signals

Not evidenced.

Note: There is no mention of actual users, customers, revenue, or adoption metrics. The project is described as a hackathon submission and a personal development effort.

Back to contents

Competitive Context

The description does not provide any information about competitors or market positioning beyond self-reported claims.

Inference: Based on the author's framing, this appears to be positioned against opaque automation tools in cybersecurity, possibly competing with enterprise-grade platforms that are too expensive for small developers or regions like Botswana.

Back to contents

Key Risks & Red Flags

  • Unverified Claims: All technical and compliance features are self-reported without third-party validation.
  • No Traction Evidence: No data on users, customers, or revenue is provided.
  • Single Developer Team: The team size is listed as one person (kgosi blanda), raising questions about scalability and support.
  • Limited Scope of Use: The system is described as a developer tool with limited production-grade functionality.
  • Unclear Commercial Viability: No indication of how the product will be monetized or scaled beyond personal development.

Inference: There is a high risk that this remains a prototype or proof-of-concept rather than a viable commercial offering.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific compliance frameworks have been implemented, and how are they validated?
  2. Is there any real-world testing or deployment of the system outside of development environments?
  3. How does the integration with Codex/GPT-5.6 work in practice? Are there performance or accuracy limitations?
  4. What is the roadmap for converting simulated features into production-grade functionality?
  5. Has the author considered how to scale beyond a single developer team?
  6. Are there any plans for monetization or commercial partnerships?

Back to contents

Investment/Partnership Verdict

Not evidenced.

Note: No evidence of financials, traction, or strategic fit is available to assess investment or partnership potential. The project appears to be in early development stage and lacks key signals that would indicate readiness for investment or partnership.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.