OpenAI 2026 hackathon

Provifact

Provifact turns “we think our Macs are secure” into audit-ready proof with read-only Intune evidence, deterministic drift checks, and evidence-cited GPT-5.6 explanations.

Solo project by Tiberius Olnhausen · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,742 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Provifact is a self-reported tool that connects Git-based approved security baselines with read-only Microsoft Intune observations for macOS endpoints. It claims to produce deterministic drift checks and GPT-5.6-generated explanations of configuration states, aiming to reduce manual effort in audit readiness.

What changed

The project was built during a hackathon (OpenAI 2026) as a vertical slice focused on Apple endpoints managed via Microsoft Intune. It includes a public demo with sanitized evidence and a structured workflow using Git, GitHub Actions, Cloudflare Workers, and OpenAI GPT-5.6.

Single most important open question

Does Provifact actually produce audit-ready proof that can be trusted by qualified humans, or does it merely generate plausible-sounding explanations without sufficient grounding in verified facts?

Back to contents

What The Product Actually Is

The description states that Provifact:

  • Connects an approved endpoint-security baseline stored in Git to read-only Microsoft Intune observation.
  • Produces a traceable evidence chain: Approved intent → observed state → deterministic drift → sanitized proof → bounded GPT-5.6 explanation → human review.
  • Provides a public "Mission Control" experience for inspecting findings, change history, evidence health, and implementation backlog.
  • Uses Python, TypeScript, Cloudflare Workers, MkDocs, Microsoft Graph, GitHub Actions, and OpenAI GPT-5.6.

It is described as a system that:

  • Shows approved target values, observed values, reviewed provider definitions, assignment and collection evidence.
  • Identifies whether settings are aligned, drifting, unsupported, unmapped, or unevaluated.
  • Delivers plain-language GPT-5.6 explanations citing verified evidence.
  • Does not claim CIS certification, CMMC assessment results, or organizational compliance verdicts.

Inference The product appears to be a proof-of-concept tool built for audit readiness in macOS endpoint security management, using deterministic logic and AI-assisted explanation.

Back to contents

Positioning & Claim Evolution

The author states that Provifact was built because teams should not have to reconstruct months of configuration history every time an audit begins. It positions itself as a way to automate evidence collection and reduce manual effort in compliance audits.

Claims include:

  • Turning “we think our Macs are secure” into audit-ready proof.
  • Providing deterministic drift checks.
  • Using GPT-5.6 for explanations that cite evidence.
  • Separating rule enforcement from AI interpretation, with humans retaining authority.

Inference Provifact positions itself as a tool to streamline audit readiness by combining Git-based intent, Intune observation, and AI-assisted explanation — but it does not claim to replace human judgment or provide compliance verdicts.

Back to contents

Target Customer & ICP

The description states that Provifact serves:

  • Endpoint engineers.
  • Security teams.
  • GRC (Governance, Risk, Compliance) teams.
  • Audit teams.

It is described as targeting users who need to prove endpoint configurations are secure and compliant, especially in environments using Microsoft Intune for macOS management.

Inference The primary customer segments appear to be security and compliance professionals working with managed macOS endpoints in Microsoft Intune. The tool is aimed at reducing audit burden through automation and clarity.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not mention any pricing model, monetization strategy, or business model. It only describes the technical architecture and functionality of the tool.

Back to contents

Technical & Delivery Signals

The project uses:

  • Python for typed provider, baseline, evidence, drift, sanitization, and verification layers.
  • Microsoft Graph with GET-only collection.
  • Git and GitHub Actions for intent, review history, protected workflows.
  • Cloudflare Workers and Static Assets for public product delivery.
  • TypeScript for Worker runtime and Assistant contract.
  • MkDocs for documentation.

It includes:

  • A pinned 98-rule macOS Level 1 planning inventory derived from NIST.
  • Four exact Intune provider mappings reviewed and used in deterministic evaluation.
  • Sanitized tenant snapshots without publishing raw data.
  • Bounded GPT-5.6 model with structured output, no tools, server-side credentials.

Inference The tool is built with a strong emphasis on security boundaries, deterministic logic, and reproducibility — suggesting a focus on trustworthiness and auditability in its design.

Back to contents

Traction & Maturity Signals

Not evidenced.

There is no mention of revenue, customers, usage metrics, or adoption. The project is described as a hackathon submission with a public demo, but no evidence of traction or market validation is provided.

Back to contents

Competitive Context

Not evidenced.

The description does not reference competitors or the broader marketplace for endpoint security audit tools. No comparison to existing solutions is made.

Back to contents

Key Risks & Red Flags

  • Unverified claims: The tool is self-reported and unverified; no third-party audits, customer feedback, or performance data are provided.
  • AI dependency without control: While GPT-5.6 is used for explanation, it is constrained to cite evidence — but the risk of misinterpretation remains if the deterministic logic fails.
  • Limited scope: The current version only supports Apple endpoints in Microsoft Intune; no roadmap for other platforms or tools is given.
  • No commercialization plan: No indication of how this would scale into a product or service, or whether it will be monetized.

Inference The tool is experimental and likely not production-ready. It lacks evidence of traction, scalability, or commercial viability.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific audit standards or frameworks does Provifact aim to support?
  2. How does the deterministic drift engine handle edge cases where data from Intune is incomplete or ambiguous?
  3. Are there any known limitations in how GPT-5.6 handles complex or unusual configurations?
  4. Has the tool been tested with real-world data beyond the synthetic demo?
  5. What are the plans for expanding support beyond macOS and Microsoft Intune?
  6. How does Provifact ensure that its Git-based intent is kept up to date with evolving security requirements?
  7. Is there a mechanism for users to validate or override GPT-5.6 explanations?

Back to contents

Investment/Partnership Verdict

Not evidenced.

There is no evidence of funding, valuation, or investment interest. The project is described as a hackathon submission with no indication of commercial intent or traction. It is not clear whether this is a product in development or an experimental prototype.

Inference At this stage, Provifact appears to be a proof-of-concept tool with potential for future development but lacks the evidence required for investment or partnership consideration.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.