OpenAI 2026 hackathon

OkamiScan

Evidence-first passive security assessment with deterministic findings and grounded GPT-5.6 remediation.

Solo project by Ovidiu STRINU · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,653 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

OkamiScan is a self-reported defensive security posture platform for authorised, non-intrusive website reviews. It performs bounded passive checks, converts observable response evidence into deterministic findings, and produces professional remediation reports with optional GPT-5.6 enhancement.

What changed

The project description indicates development was driven by the author's own experience or observation of a gap in existing tools — between simple header checkers, intrusive scanners, and AI-generated reports that may invent unsupported vulnerabilities. The platform is built using a mix of open-source and proprietary technologies including GPT-5.6, Next.js, Supabase, and Ollama.

Single most important open question

Is there any evidence of actual use or adoption beyond the author’s own testing environment?

Back to contents

What The Product Actually Is

The description states that OkamiScan is a defensive security posture platform for authorised, non-intrusive website reviews. It performs:

  • Bounded passive checks
  • Deterministic findings based on observable HTTP and TLS responses
  • Professional remediation reports with optional GPT-5.6 enhancement

It does not perform exploitation or intrusive behavior — only inspecting publicly accessible HTTP/TLS resources within strict limits.

The product includes:

  • Enterprise security posture dashboard
  • Managed asset inventory
  • Live passive assessment progress
  • Detailed technical findings and evidence
  • Historical comparisons and trend analysis
  • Technology inventory
  • Consultant-grade executive and engineering reports
  • Print-friendly PDF export
  • Deterministic, Ollama, and OpenAI report modes

It also features a judge-only hosted demo protected by signed sessions and durable rate limits.

Claim: The platform integrates GPT-5.6 only for advisory explanation fields after deterministic assessment is complete.

Evidence: The description explicitly states that AI cannot create findings, alter severity, change technical evidence, recalculate the score, or fabricate technologies and versions.

Back to contents

Positioning & Claim Evolution

The author positions OkamiScan as a solution addressing a gap in current tools:

  • Simple header checkers with little context
  • Intrusive scanners unsuitable for routine deployment reviews
  • AI-generated reports that may invent unsupported vulnerabilities

It is described as an evidence-first tool where deterministic findings are the source of truth.

Claim: The product makes deterministic, testable evidence the source of truth.

Evidence: Stated in the write-up under "Why it exists".

Claim: AI is not the scanner; it enhances explanations only.

Evidence: Explicitly described as a “responsible AI by architecture” principle.

Back to contents

Target Customer & ICP

The description does not name specific customers or personas. However, it implies:

  • Engineering teams who need to review website security
  • Organisations requiring non-intrusive assessments
  • Users seeking consultant-grade reports with executive and engineering guidance

Claim: The target audience is engineering teams needing secure, non-intrusive reviews.

Evidence: Implied from the problem statement and use case.

Back to contents

Business Model & Pricing Evidence

No information about pricing or business model is provided in the description. It does not state whether OkamiScan is a SaaS offering, a freemium tool, or a one-time product.

Claim: No pricing or monetization details are available.

Evidence: Not evidenced.

Back to contents

Technical & Delivery Signals

The author reports:

  • Built with: codex, gpt-5.6, next.js, ollama, openai-responses-api, postgresql, supabase, tailwind-css, typescript, vercel, vitest
  • Development workflow involved Codex throughout the lifecycle — from architecture to implementation and testing
  • GPT-5.6 is integrated via OpenAI Responses API for advisory explanations only
  • The system validates schema and grounding to reject unknown findings or contradictions

Claim: Codex was used as an engineering partner across all stages of development.

Evidence: Stated in the write-up.

Claim: GPT-5.6 is integrated after deterministic assessment, not during scanning.

Evidence: Explicitly described under “How Codex and GPT-5.6 were used”.

Back to contents

Traction & Maturity Signals

There is no evidence of revenue, customers, or adoption beyond the author’s own testing environment.

Claim: No traction data provided.

Evidence: Not evidenced.

Back to contents

Competitive Context

The description does not mention competitors or market positioning relative to existing tools. It only describes a gap it aims to fill.

Claim: No competitive landscape or comparison with other tools is given.

Evidence: Not evidenced.

Back to contents

Key Risks & Red Flags

  • Unverified claims: All information is self-reported and unverified.
  • No evidence of traction or customers — only author’s own testing.
  • AI integration is limited to advisory role, which may not be sufficient for some users seeking full automation.
  • Single-person team — raises questions about scalability, maintenance, and long-term viability.

Inference: The lack of any customer data or revenue suggests early-stage development with no commercial traction.

Evidence: Absence of such data in the description.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual scope of your testing? Have you assessed real-world websites beyond your own?
  2. How do you plan to scale beyond a single developer’s workflow?
  3. Are there any plans for monetization or commercial partnerships?
  4. Can you provide examples of how deterministic findings are generated and validated?
  5. How does the system handle edge cases where passive checks fail or return ambiguous results?

Back to contents

Investment/Partnership Verdict

Not evidenced.

Claim: No investment or partnership potential can be assessed.

Evidence: The description lacks any data on traction, revenue, or market fit that would inform such a decision.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.