OpenAI 2026 hackathon

Nexa ProofGate

Tests prove code runs. ProofGate proves AI stayed within authority by verifying Git changes, repository policy, required checks, owner approval, and tamper-evident evidence.

Solo project by Harish Patil · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,536 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Nexa ProofGate is a self-reported local-first AI-code admission control system built as a Node.js developer tool. It claims to verify Git changes against repository policy and require explicit owner approval before allowing code to be accepted into a repository, with tamper-evident proof generation.

What changed

The project description indicates that the author (Harish Patil) built this tool in response to concerns about AI agents generating code that passes tests but may violate repository authority boundaries. The system was developed for the OpenAI 2026 hackathon and is described as a deterministic, owner-controlled admission layer.

Single most important open question

Is there any evidence of real-world usage or integration with existing repositories or CI/CD systems beyond the author’s own development environment?

Back to contents

What The Product Actually Is

The description states that Nexa ProofGate is a local-first AI-code admission control system. It captures Git working-tree changes, loads committed repository authority policy, enforces allowed and protected paths, runs declared checks, and produces a deterministic admission result.

It also generates SHA-256 Proof Packs that bind:

  • the authorized task
  • Codex session lineage
  • Git branch and snapshot
  • changed-file evidence
  • committed policy and policy hash
  • test results
  • owner decision
  • timestamps and proof lineage

The system is described as having a browser-based evidence control room and uses Node.js for implementation.

Inference This appears to be an internal developer tool designed to enforce code change governance in AI-assisted development workflows, particularly where repository policy must be strictly enforced.

Back to contents

Positioning & Claim Evolution

The author states that ProofGate was built to address a gap between technical correctness (tests pass) and authority compliance. It positions itself as a solution for ensuring that AI-generated changes remain within defined boundaries, even when tests pass.

Key claims:

  • A passing test is not enough to unlock approval.
  • The system distinguishes between request, proposal, approval, authority, and execution.
  • GPT-5.6 is used only for advisory purposes; it cannot override deterministic decisions.
  • ProofGate blocks admission if an agent modifies a protected file, even if tests pass.

Inference The positioning implies a shift from blind trust in AI-generated code to a model of controlled, auditable, and policy-driven code acceptance, especially relevant in environments with strict compliance requirements.

Back to contents

Target Customer & ICP

The description does not explicitly name target customers or personas. However, it suggests the system is aimed at:

  • Repositories that require strict control over AI-generated changes
  • Teams using Git-based workflows and CI/CD pipelines
  • Developers working with AI agents like Codex or GPT-5.6 in code generation

The author notes that ProofGate remains local-first and deterministic, suggesting it may be used by small teams or individual developers rather than large enterprises.

Inference The ICP likely includes AI-assisted developers, DevOps engineers, and security-conscious teams who want to maintain control over code changes in their repositories.

Back to contents

Business Model & Pricing Evidence

There is no evidence of a business model, pricing structure, or monetization strategy in the description. The project is presented as a hackathon submission with no indication of commercial intent or revenue streams.

Inference No commercial business model is evident from the provided information.

Back to contents

Technical & Delivery Signals

The system is built using:

  • Node.js
  • Git integration
  • Browser-based UI
  • SHA-256 hashing for proof integrity
  • Codex and GPT-5.6 for development, not execution

Key technical features include:

  • Real Git evidence collection
  • Policy enforcement
  • Safe test execution
  • Immutable owner decisions
  • Drift detection
  • Process termination and timeout handling
  • Sensitive output redaction

The system is described as deterministic and fail-closed.

Inference It appears to be a developer-focused tool, likely intended for use in local development environments or CI/CD pipelines, with strong emphasis on security and auditability.

Back to contents

Traction & Maturity Signals

There is no evidence of traction, customers, revenue, or adoption beyond the author’s own development. The project is described as a V0.5 version submitted to a hackathon.

Inference No measurable traction or maturity indicators are evident.

Back to contents

Competitive Context

The description does not mention competitors or similar tools in the market. It focuses on its unique positioning around policy enforcement, owner control, and tamper-proof proofs, which aligns with broader trends in AI governance, code security, and DevOps compliance.

Inference There is no clear competitive landscape described; however, this product addresses a niche but growing area of concern in AI-assisted development workflows.

Back to contents

Key Risks & Red Flags

  • No real-world usage or integration evidence: The system is presented as local-only and not integrated into any production environments.
  • Unproven scalability: As a single-developer project, there’s no indication of how it scales beyond individual use cases.
  • Limited scope: It does not claim to replace professional security review or provide third-party attestation.
  • Dependency on author’s own development environment: No evidence of external testing or deployment.
  • No clear path to monetization or enterprise adoption: The product is described as deliberately local-first and owner-controlled, which may limit broader appeal.

Inference The risk lies in the lack of real-world validation, scalability concerns, and unclear commercial viability.

Back to contents

Diligence Questions To Ask The Founders

  1. Has ProofGate been tested or used in any actual repository environments?
  2. Are there plans to integrate with CI/CD platforms like GitHub Actions or GitLab CI?
  3. How does the system handle concurrent owner decisions or multi-user scenarios?
  4. What is the expected user experience for non-technical stakeholders who must approve changes?
  5. Is there a plan to support cryptographic authentication or signed external attestations?
  6. How does ProofGate detect and respond to malicious actors attempting to bypass its controls?

Back to contents

Investment/Partnership Verdict

The description presents Nexa ProofGate as a conceptual, hackathon-level prototype with strong technical foundations but no evidence of traction, commercialization, or real-world application.

Confidence Level Low

Verdict Not ready for investment or partnership at this stage. The product shows promise in addressing an emerging need in AI governance and code security, but lacks validation, scalability, and a clear path to market adoption.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.