Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,653 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
OkamiScan is a self-reported defensive security posture platform for authorised, non-intrusive website reviews. It performs bounded passive checks, converts observable response evidence into deterministic findings, and produces professional remediation reports with optional GPT-5.6 enhancement.
What changed
The project description indicates development was driven by the author's own experience or observation of a gap in existing tools — between simple header checkers, intrusive scanners, and AI-generated reports that may invent unsupported vulnerabilities. The platform is built using a mix of open-source and proprietary technologies including GPT-5.6, Next.js, Supabase, and Ollama.
Single most important open question
Is there any evidence of actual use or adoption beyond the author’s own testing environment?
What The Product Actually Is
The description states that OkamiScan is a defensive security posture platform for authorised, non-intrusive website reviews. It performs:
- Bounded passive checks
- Deterministic findings based on observable HTTP and TLS responses
- Professional remediation reports with optional GPT-5.6 enhancement
It does not perform exploitation or intrusive behavior — only inspecting publicly accessible HTTP/TLS resources within strict limits.
The product includes:
- Enterprise security posture dashboard
- Managed asset inventory
- Live passive assessment progress
- Detailed technical findings and evidence
- Historical comparisons and trend analysis
- Technology inventory
- Consultant-grade executive and engineering reports
- Print-friendly PDF export
- Deterministic, Ollama, and OpenAI report modes
It also features a judge-only hosted demo protected by signed sessions and durable rate limits.
Claim: The platform integrates GPT-5.6 only for advisory explanation fields after deterministic assessment is complete.
Evidence: The description explicitly states that AI cannot create findings, alter severity, change technical evidence, recalculate the score, or fabricate technologies and versions.
Positioning & Claim Evolution
The author positions OkamiScan as a solution addressing a gap in current tools:
- Simple header checkers with little context
- Intrusive scanners unsuitable for routine deployment reviews
- AI-generated reports that may invent unsupported vulnerabilities
It is described as an evidence-first tool where deterministic findings are the source of truth.
Claim: The product makes deterministic, testable evidence the source of truth.
Evidence: Stated in the write-up under "Why it exists".
Claim: AI is not the scanner; it enhances explanations only.
Evidence: Explicitly described as a “responsible AI by architecture” principle.
Target Customer & ICP
The description does not name specific customers or personas. However, it implies:
- Engineering teams who need to review website security
- Organisations requiring non-intrusive assessments
- Users seeking consultant-grade reports with executive and engineering guidance
Claim: The target audience is engineering teams needing secure, non-intrusive reviews.
Evidence: Implied from the problem statement and use case.
Business Model & Pricing Evidence
No information about pricing or business model is provided in the description. It does not state whether OkamiScan is a SaaS offering, a freemium tool, or a one-time product.
Claim: No pricing or monetization details are available.
Evidence: Not evidenced.
Technical & Delivery Signals
The author reports:
- Built with: codex, gpt-5.6, next.js, ollama, openai-responses-api, postgresql, supabase, tailwind-css, typescript, vercel, vitest
- Development workflow involved Codex throughout the lifecycle — from architecture to implementation and testing
- GPT-5.6 is integrated via OpenAI Responses API for advisory explanations only
- The system validates schema and grounding to reject unknown findings or contradictions
Claim: Codex was used as an engineering partner across all stages of development.
Evidence: Stated in the write-up.
Claim: GPT-5.6 is integrated after deterministic assessment, not during scanning.
Evidence: Explicitly described under “How Codex and GPT-5.6 were used”.
Traction & Maturity Signals
There is no evidence of revenue, customers, or adoption beyond the author’s own testing environment.
Claim: No traction data provided.
Evidence: Not evidenced.
Competitive Context
The description does not mention competitors or market positioning relative to existing tools. It only describes a gap it aims to fill.
Claim: No competitive landscape or comparison with other tools is given.
Evidence: Not evidenced.
Key Risks & Red Flags
- Unverified claims: All information is self-reported and unverified.
- No evidence of traction or customers — only author’s own testing.
- AI integration is limited to advisory role, which may not be sufficient for some users seeking full automation.
- Single-person team — raises questions about scalability, maintenance, and long-term viability.
Inference: The lack of any customer data or revenue suggests early-stage development with no commercial traction.
Evidence: Absence of such data in the description.
Diligence Questions To Ask The Founders
- What is the actual scope of your testing? Have you assessed real-world websites beyond your own?
- How do you plan to scale beyond a single developer’s workflow?
- Are there any plans for monetization or commercial partnerships?
- Can you provide examples of how deterministic findings are generated and validated?
- How does the system handle edge cases where passive checks fail or return ambiguous results?
Investment/Partnership Verdict
Not evidenced.
Claim: No investment or partnership potential can be assessed.
Evidence: The description lacks any data on traction, revenue, or market fit that would inform such a decision.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
