Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #4,598 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
IDcognito is a self-reported privacy tool that presents users with a visual "Exposure Graph" showing how their digital identity connects across breaches, broker listings, search results, and social profiles. It uses synthetic data and GPT-5.6 for limited evidence review but does not perform live lookups or claim remediation.
What changed
The author states this is a rebuilt version from first principles using a simpler idea after prior attempts failed due to lack of test data or ground truth. This iteration focuses on showing digital exposure as a connected graph with evidence-backed relationships and a bounded AI feature for advisory review.
Single most important open question
Is there any evidence that IDcognito has traction, revenue, or customers beyond the synthetic demo? The description makes no claims about real-world adoption or monetization.
What The Product Actually Is
The description states that IDcognito is a tool designed to help people "see, understand, and shrink their digital exposure." Its centerpiece is an "Exposure Graph" which connects identity attributes to breach records, broker listings, search results, social profiles, and evidence-backed relationships. Selecting a node reveals supporting evidence, while one-hop expansion shows related people without confirming those connections.
A "Cleanup Copilot" converts findings into a prioritized, user-approved review queue. GPT-5.6 powers one deliberately bounded feature: Evidence Review, which examines evidence attached to observations and returns an advisory verdict (likely relevant, likely a collision, or insufficient evidence), along with citations, uncertainty, and a suggested human review step.
The system uses synthetic data generated by SynthWorld, an open-source deterministic generator for testing identity exposure. The shared judge build uses unmistakably synthetic data and performs no live real-person HIBP or Bright Data lookups.
Inference This is a privacy visualization and advisory tool built around a synthetic dataset and AI-assisted review process. It does not appear to be a production-ready service with live integrations, nor does it claim to perform actual identity cleanup actions.
Positioning & Claim Evolution
The author states that they have worked in Enterprise Identity Management for years but found personal identity management even more complex due to social media and breaches. They note that most privacy tools produce flat lists of alarming findings without showing how those findings connect or how trustworthy each conclusion is.
This project evolved from earlier versions that tried to cover too much before having realistic test data, measurable ground truth, or an honest end-to-end harness. The current version was rebuilt around a simpler idea: people should be able to see their digital exposure as a connected evidence graph, and every product claim should be testable without using anyone’s real personal data.
Inference The positioning has shifted from trying to do everything to focusing on visualizing exposure through a connected graph with evidence-backed relationships. The emphasis is on transparency and testability rather than action or automation.
Target Customer & ICP
The description states that IDcognito helps people see, understand, and shrink their digital exposure. It targets individuals who are concerned about privacy and want to know what information is publicly available about them.
It appears to be aimed at users who are already aware of identity risks and are looking for tools to better understand and manage them.
Inference The target customer seems to be privacy-conscious individuals, likely tech-savvy or early adopters of privacy tools. There is no mention of enterprise customers or B2B use cases.
Business Model & Pricing Evidence
Not evidenced.
The description does not contain any information about pricing models, monetization strategies, or business model assumptions. No revenue streams, subscriptions, or paid features are mentioned.
Technical & Delivery Signals
IDcognito uses a FastAPI and SQLAlchemy backend with PostgreSQL adapter, plus a React, TypeScript, Vite, and react-force-graph-2d frontend. The judge deployment uses a deterministic in-memory adapter. Every external dependency sits behind a port, making the zero-key synthetic implementation a first-class path rather than a special demo branch.
GPT-5.6 is integrated through one EvidenceReviewer port using the OpenAI Responses API, strict structured output, store=false, bounded input, explicit uncertainty, one attempt, and sanitized failures. The public judge deployment uses the equivalently shaped deterministic golden adapter so shared credentials cannot consume API credits.
Codex served as the autonomous engineering collaborator, working from mechanistically checkable specifications: writing analytical assertions before implementations, running quality gates, inspecting browser screenshots, packaging deployments, auditing releases, and producing submission-video pipelines.
Inference The technical stack suggests a modern web application with backend APIs, frontend visualization, and AI integration. The use of synthetic data and deterministic adapters indicates strong emphasis on reproducibility and testing rather than live data handling.
Traction & Maturity Signals
Not evidenced.
There is no mention of actual users, customers, or real-world usage beyond the synthetic demo. No revenue figures, user growth metrics, or product adoption data are provided. The project is described as a hackathon submission with no indication of ongoing development or commercial traction.
Competitive Context
Not evidenced.
The description does not reference competitors or market positioning relative to existing privacy tools or identity management platforms. No competitive landscape analysis or differentiation strategy is presented.
Key Risks & Red Flags
- No real-world data integration: The system uses only synthetic data and does not perform live lookups against breach databases or broker services.
- Limited AI scope: GPT-5.6 is used only for advisory review, not for identity confirmation or remediation.
- No monetization strategy: No evidence of pricing, subscriptions, or revenue model.
- Unproven user demand: No indication of actual users or market traction beyond the author's own claims.
- Synthetic-only deployment: The public version is intentionally synthetic, which may limit its perceived value to potential investors or partners.
Diligence Questions To Ask The Founders
- What are your plans for transitioning from synthetic data to live integration with breach databases and broker services?
- How do you intend to monetize this product if it currently only works with synthetic data?
- Have you received any feedback from users or potential customers beyond the hackathon context?
- Is there a timeline for moving beyond the current synthetic-only demo toward real-world functionality?
- What are your thoughts on privacy compliance and data handling in a live environment?
Investment/Partnership Verdict
Not evidenced.
There is no evidence of revenue, customer base, or traction to support an investment or partnership decision. The project appears to be a hackathon submission focused on demonstrating technical capability with synthetic data rather than building a viable product for real users. Any potential for commercial success depends heavily on future development and integration with live data sources, which are not yet evident in the description.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
