Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #3,607 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
The company appears to be a solo project, CustodIA, self-described as an "Enterprise AI Gateway" designed to govern access to external AI models by evaluating requests before sending them out. The author states that the system evaluates each request and routes it through one of five possible paths: direct external model, protected external model (with local sanitization), local-only processing, human review, or blocked.
The project is described as a demonstration built during a hackathon using synthetic data and limited scenarios. It uses GPT-5.6 Luna via the OpenAI Responses API, with Codex for development assistance. The system claims to protect sensitive data by replacing values locally before sending requests externally, and reconstructing responses locally after validation.
The single most important open question is: what is the actual commercial viability of this governance layer, and how does it scale beyond a controlled hackathon demonstration?
The description provides no evidence of revenue, customers, or traction. It is entirely self-reported and unverified. The author explicitly states that the submission proves only the governed flow with controlled synthetic scenarios, not production readiness.
What The Product Actually Is
- The description states that CustodIA is a "governed enterprise AI gateway" that evaluates requests before routing them to external models.
- It selects one of five routes for each request:
- Direct external model for approved public content.
- Protected external model when sensitive values must be removed locally first.
- Local-only processing when information must remain inside the trusted environment.
- Human review when policy requires an explicit decision.
- Blocked when the request is prohibited.
- The system uses GPT-5.6 Luna through the OpenAI Responses API.
- It implements local sanitization of sensitive values before sending requests externally.
- It reconstructs responses locally after validation.
- The demonstration focuses on three controlled scenarios using synthetic data.
- The author states that it was built during a Build Week hackathon and is not authorized for production use.
Positioning & Claim Evolution
- The description states that the company wants to provide "governed AI access that protects sensitive data locally before using external models."
- The author claims that companies want to use advanced AI but cannot send every request directly to an external model due to privacy, security, and compliance risks.
- The positioning is described as a "practical middle layer" between unrestricted access and complete blocking.
- The project is positioned as solving the problem of balancing useful AI capabilities with data protection requirements.
- The author states that governance must be part of the execution path, not added after model calls.
- The claim evolution shows a progression from a simple demonstration to a vision for a full client-server system with advanced features like multimodal requests, central administration, and configurable organizational policies.
Target Customer & ICP
- Not evidenced. The description does not identify specific customer segments or personas.
- The author states that the project is designed for enterprise use cases where companies want to use AI but need to protect sensitive data.
- No evidence of target industries, company sizes, or decision-makers mentioned.
- The system is described as an "enterprise AI gateway," suggesting it targets large organizations with compliance requirements.
Business Model & Pricing Evidence
- Not evidenced. There is no mention of pricing models, revenue streams, or monetization strategies in the description.
- The author states that the project is not authorized for production use and is only ready for a controlled judge demonstration.
- No evidence of customer acquisition costs, lifetime value, or business model details provided.
Technical & Delivery Signals
- The system uses GPT-5.6 Luna through the OpenAI Responses API.
- It implements local sanitization of sensitive values before sending requests externally.
- It reconstructs responses locally after validation.
- The demonstration was built using Codex as the main development agent.
- Railway deployment package was implemented.
- Three-scenario interface was created.
- Tests were written and run.
- Privacy and security boundaries were audited.
- Deployment and Responses API issues were diagnosed.
- Placeholder protection and local reconstruction were validated.
- The system uses store=false for OpenAI requests, with no retries, streaming, tools, background execution, conversations, or fallback models.
- HTTPS ingress, Host and Origin validation, health checks, authorization controls, rate limits, and a kill switch were implemented for Railway deployment.
- Realistic Responses API payload parsing was corrected through testing.
Traction & Maturity Signals
- Not evidenced. The description provides no evidence of revenue, customers, or adoption.
- The author explicitly states that the submission proves only the governed flow with controlled synthetic scenarios, not production readiness.
- The project is described as a demonstration built during a hackathon.
- No evidence of user engagement, usage metrics, or product maturity beyond the demo phase.
Competitive Context
- Not evidenced. The description does not mention competitors or competitive positioning.
- No evidence of existing solutions in the market for governed AI access or enterprise AI gateways.
- The author does not reference other companies or products that address similar problems.
Key Risks & Red Flags
- Production readiness: The system is explicitly stated as not authorized for production use and only ready for a controlled judge demonstration.
- Scalability concerns: The project is described as a hackathon demo with synthetic data, raising questions about scalability to real-world enterprise environments.
- Single-person development: The team size is listed as 1, which may limit the ability to scale or maintain the product.
- Limited scope: The demonstration focuses on only three controlled scenarios using synthetic data, not real-world use cases.
- Dependency on specific providers: The system uses GPT-5.6 Luna through OpenAI Responses API, limiting flexibility if those providers change.
- Unverified claims: All claims are self-reported and unverified; no independent validation of the technical implementation or effectiveness.
Diligence Questions To Ask The Founders
- What specific enterprise compliance requirements does CustodIA address that existing solutions don't?
- How does the system handle edge cases beyond the three controlled scenarios demonstrated?
- What are the actual technical limitations of scaling this solution beyond a single developer's hackathon project?
- How would you implement multi-provider support in a production environment?
- What is your plan for addressing the human review workflow at scale?
- How do you intend to handle the complexity of enterprise policy configuration and enforcement?
- What are the specific security vulnerabilities that this system protects against, and how are they validated?
- How would you measure success or effectiveness of the governance layer in a real enterprise environment?
- What is your roadmap for moving from demonstration to production-ready software?
- How do you plan to monetize this solution in the enterprise market?
Investment/Partnership Verdict
- Not evidenced. The description provides no information about funding rounds, valuations, or investment history.
- The project appears to be a solo developer's hackathon submission with no evidence of commercial traction or viability.
- The author explicitly states that this is not production-ready and only proves the governed flow with controlled synthetic scenarios.
- There is no evidence of revenue, customers, or market validation beyond the self-reported description.
- The single-person team size raises concerns about scalability and long-term development capacity.
- The project's positioning as an enterprise AI governance solution suggests potential market interest, but the lack of any commercial evidence makes it difficult to assess viability.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.

