OpenAI 2026 hackathon

Atreides: Agent Security Gateway

A proof-carrying MCP security gateway. Stop agent runaway with deterministic, provenance-based policy and auditable trust receipts—not LLM confidence scores. x

Solo project by Parth Bhatt · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #646 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Atreides: Agent Security Gateway is a developer-focused security tool that evaluates and enforces deterministic policy for Model Context Protocol (MCP) actions. It operates as a pre-execution gateway, analyzing provenance and context to authorize or block specific tool calls, and generates auditable trust receipts.

What changed

The project shifts from heuristic-based prompt-injection defenses (e.g., LLM confidence scores) to deterministic, policy-as-code enforcement with cryptographic proof-carrying receipts. It positions itself as a solution for securing autonomous agents by enforcing strict action boundaries rather than relying on text analysis.

Single most important open question

Is there evidence of real-world usage or integration with existing MCP-based systems, or is this a prototype that has not yet reached production readiness?

Back to contents

What The Product Actually Is

The description states that Atreides is a developer-focused security gateway. It tracks the path from untrusted context to a requested MCP action and enforces deterministic policy before an allowed tool call is forwarded to execution.

It includes:

  • An upstream MCP Broker that discovers configured stdio tools.
  • A Trust Receipts system that produces signed, hash-chained receipts for every action.
  • Provenance-aware decisions, based on trust level, data sensitivity, destination, and write impact.
  • A Safe Red-Team Replay feature via an interactive operator console.

The product is architected as a TypeScript monorepo, with:

  • A Node.js backend using Zod for validation and the @modelcontextprotocol/server SDK.
  • A Next.js/React frontend for visualizing policy evaluation and receipt chains.

It was built using Codex / GPT-5.6 assistance for architecture, scaffolding, and UI iteration.

Claim: Atreides is a security gateway that enforces deterministic policy for MCP actions.

Evidence: The author's own write-up.

Back to contents

Positioning & Claim Evolution

The project claims to shift from traditional prompt-injection defenses (which rely on detecting suspicious wording or LLM confidence scores) to a deterministic, provenance-based approach. It frames its value as:

  • Replacing heuristic model confidence with policy-as-code.
  • Providing auditable trust receipts instead of warnings.
  • Enabling pre-execution authorization rather than post-hoc detection.

It positions itself as a solution for securing autonomous agents by enforcing strict boundaries, not by analyzing text.

Claim: Atreides replaces LLM confidence-based defenses with deterministic policy enforcement.

Evidence: The author's own write-up.

Back to contents

Target Customer & ICP

The description states that Atreides is a developer-focused security gateway. It targets users who are building or operating autonomous agents using the Model Context Protocol (MCP).

It is designed for:

  • Developers working with MCP-based systems.
  • Teams looking to secure agent tool calls and prevent unauthorized actions like secret exfiltration.

Claim: Atreides targets developers working with MCP-based agents.

Evidence: The author's own write-up.

Back to contents

Business Model & Pricing Evidence

No information is provided about pricing, monetization, or business model. The description does not mention any revenue streams, customer acquisition plans, or commercial arrangements.

Claim: Not evidenced.

Back to contents

Technical & Delivery Signals

The project is built as a TypeScript monorepo with:

  • A Node.js backend using Zod and the @modelcontextprotocol/server SDK.
  • A Next.js/React frontend for operator console and visualization.
  • Use of Codex / GPT-5.6 for development assistance.

It includes:

  • Transparent stdio MCP broker functionality.
  • Hash-chained trust receipts with SHA-256 integrity.
  • HMAC signing and optional JSONL persistence.

Claim: Atreides is a technical security gateway built on MCP, with cryptographic receipt chains.

Evidence: The author's own write-up.

Back to contents

Traction & Maturity Signals

The project is described as a prototype submitted to the OpenAI 2026 hackathon. It has no evidence of:

  • Revenue
  • Customers
  • Product adoption
  • Production deployments
  • Market traction

It is explicitly stated that this is a pre-execution evaluator and stdio MCP broker, with next steps including:

  • Expanding to other MCP transports.
  • Adding identity-aware authorization and mTLS.
  • Integrating durable, encrypted receipt storage.

Claim: Atreides is a prototype submitted to a hackathon.

Evidence: The author's own write-up.

Back to contents

Competitive Context

The description does not mention any competitors or competitive positioning. It does not reference existing tools in the agent security or MCP space.

Claim: Not evidenced.

Back to contents

Key Risks & Red Flags

  • Prototype-only status: No evidence of production use or integration.
  • No commercial traction: No customers, revenue, or adoption data.
  • Limited scope: Currently only supports stdio-based MCP transport.
  • Unproven scalability: Hash-chain integrity and throughput are mentioned as challenges, but no performance data is provided.
  • Self-reported maturity: The project is described as a prototype with future steps, not a finished product.

Inference: Atreides is not yet ready for production use or commercial deployment.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current status of integration with non-stdio MCP transports?
  2. Has this been tested in any real-world agent environments?
  3. Are there any existing partnerships or early adopters?
  4. How does Atreides plan to scale trust receipt generation without impacting performance?
  5. What are the specific use cases or industries where this is being considered for deployment?

Back to contents

Investment/Partnership Verdict

Atreides is a prototype submitted as part of a hackathon, with no evidence of commercial traction, revenue, or customer adoption.

It represents a technical approach to agent security that shifts from LLM confidence-based defenses to deterministic policy enforcement. However, the project is in an early stage and has not yet demonstrated real-world usage or scalability.

Verdict: Not ready for investment or partnership at this time. Requires further development, testing, and evidence of traction before commercial viability can be assessed.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.