Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #3,659 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
Deadbolt is a self-reported tool for performing security audits on software repositories, described as "keyless" and "evidence-backed." It was submitted by a single founder (Luis David Calvo) to the OpenAI 2026 hackathon. The product is built using AI tools like GPT-5.6 and Codex, with a frontend framework of Next.js.
What changed
There is no evidence of prior version or evolution. This is a single submission to a hackathon, with no indication of prior development or traction.
The single most important open question
Is there any evidence of actual usage, revenue, or customer feedback beyond the hackathon submission?
What The Product Actually Is
The description states: “Keyless, evidence-backed security audits for repositories you own.”
- The product is described as a tool that performs security audits on software repositories.
- It claims to be "keyless", suggesting no manual input or access required.
- It is described as producing "evidence-backed" results, implying some form of audit trail or justification.
Evidence
- Tagline: “Keyless, evidence-backed security audits for repositories you own.”
- Technology stack: codex, gpt-5.6, next.js, openai-responses-api, typescript, vercel, zod.
- Submitted to OpenAI 2026 hackathon.
Inference The product likely uses AI to analyze code repositories and generate security audit reports — but this is inferred from the tech stack and tagline, not confirmed.
Positioning & Claim Evolution
The description states: “Keyless, evidence-backed security audits for repositories you own.”
- The positioning is that of a self-service, automated tool for auditing software repositories.
- It is positioned as a solution to a problem in code security.
- No prior positioning or evolution is described — this is the first public statement.
Evidence
- Tagline only.
- No mention of prior versions, market feedback, or evolution of claims.
Inference The product may have evolved from an idea to a prototype, but no evidence supports that claim. The tagline suggests a focus on automation and audit quality.
Target Customer & ICP
The description states: “for repositories you own.”
- The target customer is the owner of software repositories.
- It implies a developer or team managing codebases.
Evidence
- Tagline: “Keyless, evidence-backed security audits for repositories you own.”
Inference The tool likely targets developers or DevOps teams who manage code repositories and are concerned with security. No further segmentation is evident.
Business Model & Pricing Evidence
No evidence of pricing, monetization, or business model is provided in the description.
Evidence
- No mention of pricing.
- No indication of revenue streams.
- No customer acquisition or retention strategy.
Inference The product may be a prototype or pre-revenue tool. It's unclear if it will be sold as SaaS, freemium, or otherwise.
Technical & Delivery Signals
The description states: “Built with (author-declared): codex, gpt-5.6, next.js, openai-responses-api, typescript, vercel, zod.”
- The tool is built using AI tools like GPT and Codex.
- It uses modern frontend stack: Next.js, TypeScript, Vercel.
- It integrates with OpenAI APIs.
Evidence
- Technology stack: codex, gpt-5.6, next.js, openai-responses-api, typescript, vercel, zod.
Inference The tool is likely a web-based application that leverages AI for code analysis and audit generation. The use of GPT suggests it may be a generative-AI product.
Traction & Maturity Signals
No evidence of traction or maturity is provided.
Evidence
- Submitted to a hackathon.
- No mention of users, customers, or adoption.
- No data on usage, retention, or revenue.
Inference This is likely an early-stage prototype or proof-of-concept. There is no indication of product-market fit or customer feedback.
Competitive Context
No evidence of competitive landscape is provided.
Evidence
- No mention of competitors.
- No reference to existing tools in the security audit space.
Inference The tool may be positioned in a niche within code security, but there is no indication of how it compares to existing solutions or whether such a market exists.
Key Risks & Red Flags
- No traction: Submitted to a hackathon — no evidence of real-world usage.
- Unverified claims: The description is self-reported and unverified.
- Single founder: No team or external validation.
- No pricing or monetization model: Unclear how the product will be commercialized.
- AI dependency: Heavy reliance on GPT and Codex may raise concerns about accuracy, scalability, or cost.
Diligence Questions To Ask The Founders
- What is the actual problem you are solving, and how did you identify it?
- How does your tool determine what constitutes a security issue in a repository?
- Have you tested this with real repositories? What were the results?
- Is there any plan to monetize or scale this beyond the hackathon submission?
- What is the long-term vision for this product, and how do you see it evolving?
Investment/Partnership Verdict
Not evidenced.
There is no evidence of revenue, traction, or customer feedback to support a commercial due-diligence read. The project is described as a hackathon submission with no indication of prior development, adoption, or business model.
The description is self-reported and unverified — it does not provide any facts about product-market fit, scalability, or commercial viability. Any inference beyond the stated tagline and tech stack should be treated as speculative.
Confidence Low.
Next Step
If this is a pre-revenue prototype, further due diligence would require access to internal data, user feedback, or a working version of the product.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.

