OpenAI 2026 hackathon

PlanGuard

An AI Cloud Risk Operations platform that investigates runtime drift, explains security and compliance impact, and recommends fixes before risks become incidents.

Solo project by naz3karim Karim · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,974 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

PlanGuard is a self-reported AI Cloud Risk Operations platform that claims to investigate runtime drift, explain security and compliance impact, and recommend fixes before risks become incidents. The project was built as part of the OpenAI 2026 hackathon by one founder (Karim), using a stack including React, FastAPI, Python, PostgreSQL/Supabase, and AI tools like Codex and GPT-5.6. It positions itself as a unified platform for monitoring cloud risk, security posture, compliance readiness, and website security. The description states that it supports runtime drift monitoring, integrates security findings, assets, attack paths, and remediation workflows, and aims to make cloud risk management proactive through AI.

What Changed: The project evolved from an initial concept focused on cloud security operations into a platform with Website Security Posture Management (WSPM), redesigned dashboards, and expanded integrations. It also introduced AI capabilities for investigating drift and explaining impact in plain language.

Single Most Important Open Question: Is there any evidence of actual usage or traction beyond the hackathon prototype? The description does not state whether PlanGuard has been deployed, tested with users, or has any customers.

Back to contents

What The Product Actually Is

The description states that PlanGuard is a Cloud Risk Operations platform. It helps organizations monitor:

  • Runtime drift
  • Cloud security posture
  • Website security posture
  • Compliance readiness

It brings together:

  • Security findings
  • Assets
  • Attack paths
  • Compliance reporting
  • Remediation workflows

The platform aims to help engineering and security teams quickly identify, prioritize, and resolve cloud risks.

Inference: Based on the tech stack (React, FastAPI, Python, PostgreSQL/Supabase) and the description of its functionality, PlanGuard appears to be a web-based SaaS product with a frontend dashboard and backend services for processing and analyzing cloud security data. It is not evident whether it includes real-time monitoring or is more of an audit/review tool.

Back to contents

Positioning & Claim Evolution

The description states that PlanGuard was inspired by the need to reduce time spent switching between tools to understand runtime drift, compliance posture, and infrastructure changes. The platform aims to be a single workspace for cloud risk operations.

It claims to:

  • Investigate runtime drift
  • Explain security and compliance impact
  • Recommend fixes before risks become incidents

The project evolved from an initial idea into a more feature-rich tool with:

  • Website Security Posture Management (WSPM)
  • Redesigned executive dashboard and core experience
  • Rebuilt interfaces for findings, reports, assets, attack paths, and users
  • Lightweight notification framework for cloud risk events

Inference: The positioning has shifted from a basic monitoring tool to a more comprehensive platform that integrates multiple aspects of cloud security and compliance. The use of AI tools like Codex and GPT-5.6 suggests an emphasis on automation and rapid iteration.

Back to contents

Target Customer & ICP

The description states that PlanGuard is designed for:

  • Engineering teams
  • Security teams

It aims to help these teams:

  • Monitor cloud risk
  • Understand what changed
  • Take action before small issues become security incidents

Inference: The target customer appears to be organizations with cloud infrastructure and security operations, likely in mid-to-late stage startups or enterprises. The ICP is not explicitly defined beyond "cloud security teams" and "engineering teams."

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not state anything about pricing, monetization, or business model. It only describes the product’s features and functionality.

Back to contents

Technical & Delivery Signals

The project was built using:

  • Frontend: React, TypeScript, Tailwind
  • Backend: FastAPI, Python
  • Database: PostgreSQL/Supabase
  • Infrastructure: AWS, Docker, Terraform, OpenTofu
  • AI tools: Codex, GPT-5.6

It was developed during the OpenAI 2026 hackathon.

Inference: The tech stack indicates a modern cloud-native SaaS product with a focus on developer experience and integration with cloud infrastructure. The use of AI tools like Codex suggests an emphasis on rapid development and iteration, which could be a signal of early-stage innovation or prototyping rather than a mature product.

Back to contents

Traction & Maturity Signals

Not evidenced.

There is no mention of:

  • Revenue
  • Customers
  • Users
  • Adoption
  • Product usage metrics
  • Deployment status

The project was submitted as a hackathon entry, and the description does not indicate any post-hackathon traction or development.

Back to contents

Competitive Context

Not evidenced.

The description does not reference competitors, market size, or competitive positioning beyond stating that teams spend too much time switching between tools. No mention of existing platforms in the cloud security or compliance space is provided.

Back to contents

Key Risks & Red Flags

  • No traction or revenue: The project is described as a hackathon prototype with no evidence of real-world usage.
  • Unverified claims: All features and capabilities are self-reported; there is no independent verification.
  • Single founder: The team size is listed as one, which may indicate limited execution capacity.
  • AI tool dependency: Heavy reliance on AI tools like Codex and GPT-5.6 suggests a prototype or early-stage product, not a production-ready solution.
  • Lack of clarity on business model: No information about monetization or pricing.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current status of PlanGuard beyond the hackathon? Is it in active development or testing?
  2. Have you conducted any user research or pilot testing with security teams?
  3. How do you plan to monetize this platform, and what is your go-to-market strategy?
  4. What are the key technical challenges that remain before a production-ready version?
  5. Are there any existing partnerships or integrations in place?
  6. What is the timeline for expanding support for additional cloud providers and compliance frameworks?

Back to contents

Investment/Partnership Verdict

Not evidenced.

There is no evidence of revenue, customers, traction, or financials to assess investment viability or partnership potential. The project is described as a hackathon prototype with no indication of commercial progress beyond the initial build. It is unclear whether it has moved past the idea stage into product-market fit or early adoption.

The description states that the platform aims to be proactive in cloud risk management, but without real-world usage or data, this remains unproven. The single-founder team and lack of traction raise concerns about execution capability.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.