OpenAI 2026 hackathon

frad3ail llm gateway

Coding agents read everything. frad3ail llm gateway redacts secrets before egress and turns every Codex session into provable audit evidence.

Solo project by Njabulo Majozi · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #4,224 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

The project described as "frad3ail llm gateway" is a self-reported local-first privacy gateway for LLM agents. It is designed to inspect, redact, and tokenize sensitive information in model-bound context before it leaves a developer's machine — specifically targeting Codex and OpenAI-compatible clients.

What changed

The author states they built this system as a response to the risk that coding agents (like Codex) may inadvertently expose secrets or PII through their context. The system is positioned as a local enforcement boundary that applies policy decisions to traffic before forwarding it, with evidence generation baked into the process.

Single most important open question

Is there any evidence of real-world usage or adoption beyond the author’s own development workflow? The description makes no claims about customers, revenue, or traction — only self-reported functionality and architecture.

Note: This analysis is based entirely on the self-reported project description provided by the author. No external verification, archived data, or third-party sources are available. All findings are drawn from that single source, which is unverified and may contain claims without substantiation.

Back to contents

What The Product Actually Is

The description states that frad3ail is a local-first, OpenAI-compatible privacy gateway for Codex and other compatible clients. It operates between the client and an upstream LLM provider, inspecting HTTP and WebSocket traffic before forwarding it.

Key technical components include:

  • A TypeScript-based gateway handling proxying of HTTP and WebSocket requests.
  • A Python service using FastAPI for heavy local analysis (with Magika, Presidio, and a custom South African ID recognizer).
  • Local persistence via Drizzle and SQLite.
  • An encrypted token vault with HMAC fingerprints and AES-256-GCM encryption.
  • A React-based dashboard for session and evidence inspection.

It is described as a pnpm monorepo built with Docker Compose for local deployment, and integrates with Codex through a dedicated profile.

Inference: The product appears to be a developer tool focused on privacy control in LLM agent workflows. It is not a SaaS offering but rather a local system intended for individual developers or small teams.

Back to contents

Positioning & Claim Evolution

The author positions frad3ail as:

  • A local privacy enforcement boundary that inspects model-bound context before sending it to an LLM provider.
  • A system that turns every Codex session into provable audit evidence, with tamper-evident logs and exportable JSONL output.
  • A solution that operates closer to where developers work, rather than at the network perimeter or in retrospective logs.

The name "frad3ail" is explained as a reference to “fragile trust boundaries” — implying that current LLM systems are vulnerable due to lack of enforcement and evidence at the point of interaction.

Claim vs Fact: The description states that frad3ail is built for developers using Codex, but does not claim adoption or usage beyond the author’s own workflow. It also claims local-first operation and deterministic detection, but no external validation supports these assertions.

Back to contents

Target Customer & ICP

The description implies that frad3ail targets:

  • Developers working with LLM agents, particularly those using Codex.
  • Teams or individuals concerned with privacy and data governance in agent-based workflows.
  • Organizations looking for local enforcement of sensitive data policies without relying on cloud services.

There is no explicit mention of enterprise customers, pricing models, or specific personas beyond the developer use case.

Inference: The ICP appears to be individual developers or small teams who want to protect their own development environments from leaking secrets or PII during LLM interactions.

Back to contents

Business Model & Pricing Evidence

The description does not provide any information about:

  • Revenue streams
  • Pricing models
  • Monetization strategy
  • Customer acquisition plans

It is described as a local tool, and the author mentions using Docker Compose and a profile installer, suggesting no commercial offering or subscription model.

Not evidenced: No evidence of business model or pricing structure exists in the provided description.

Back to contents

Technical & Delivery Signals

The system is built with:

  • Cloudflare, Codex, Docker, Drizzle, FastAPI, Hono, Magika, OpenAI, Presidio, React, SQLite, Turborepo, TypeScript, Vite, Vitest, WebSockets
  • A monorepo structure using pnpm
  • Local-first architecture with no external dependencies for detection
  • Encrypted tokenization and hash-chained audit logs

It supports:

  • HTTP and WebSocket proxying
  • Context extraction and classification
  • Policy-driven redaction and transformation
  • Session-scoped evidence generation
  • Tamper-evident logging

Inference: The technical stack suggests a developer-focused, privacy-oriented tool with strong local enforcement capabilities. It is not described as scalable or cloud-native.

Back to contents

Traction & Maturity Signals

There is no evidence of:

  • Customers or users
  • Revenue or monetization
  • Product adoption beyond the author’s own workflow
  • Market traction or growth metrics

The project was submitted to a hackathon, and the author describes it as a personal engineering effort. It is not described as a product in production or used by others.

Not evidenced: No traction or maturity signals are provided.

Back to contents

Competitive Context

The description does not mention:

  • Competitors
  • Market positioning relative to existing tools
  • Prior art or similar solutions

It is implied that frad3ail addresses a gap in current LLM agent privacy controls, but no comparison with other systems is made.

Not evidenced: No competitive landscape information is provided.

Back to contents

Key Risks & Red Flags

  • No external validation: The entire description is self-reported and unverified.
  • Limited scope: The system is described as local-only, which may limit its appeal to enterprise users or those needing centralized control.
  • Single-person development: The team size is listed as one (Njabulo Majozi), raising questions about scalability and long-term maintenance.
  • Unproven adoption: No evidence of real-world usage beyond the author’s own workflow.
  • No commercialization path: No indication that this will become a product with revenue or customers.

Inference: The lack of any traction, customers, or commercialization strategy raises concerns about viability as a business or investment opportunity.

Back to contents

Diligence Questions To Ask The Founders

  1. Has anyone else used frad3ail beyond your own workflow?
  2. Are there plans to support more LLM providers beyond Codex and OpenAI?
  3. What is the expected user experience for someone not technically inclined?
  4. How does the system handle false positives in detection?
  5. Is there a plan to move from local-only enforcement to centralized policy management?
  6. What are the long-term goals for scaling or monetizing this tool?

Back to contents

Investment/Partnership Verdict

Not evidenced: There is no evidence of revenue, customers, traction, or commercial viability beyond the author’s own development.

The project is described as a developer tool, built in a hackathon setting, with no indication of market demand or product-market fit. It is not a SaaS offering and does not appear to be monetized.

Verdict: Based on the self-reported description alone, there is insufficient evidence to support an investment or partnership decision. The project lacks demonstrated traction, customers, or business model. Any potential value lies in its technical innovation, but that is not sufficient for due-diligence-level commercial assessment without further evidence.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.