OpenAI 2026 hackathon

Proof-of-Care

Runtime governance for AI agents: one authenticated decision authorizes one exact action, for at most one dispatch attempt, with auditable policy and human review.

Solo project by El Amenmut · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #6,126 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Proof-of-Care is a self-reported runtime governance system for AI agents. The description states it enforces a trust boundary between agent intent and tool execution, using HMAC-signed capability manifests, canonical JSON action envelopes, and SQLite-backed state. It claims to bind one authenticated decision to one exact action, with auditable policy and human review.

What changed

The project was built over a 5-day Build Week for the OpenAI 2026 hackathon. The author states that it began as an executable governance specification and evolved through Milestone 8 (M8.0–M8.12), incorporating adversarial testing, security regression harnesses, and formalized authority binding.

The single most important open question

Is Proof-of-Care a working prototype or a conceptual framework? The description states it was submitted to a hackathon and does not claim production readiness. There is no evidence of revenue, customers, or adoption beyond the author’s own account.

Back to contents

What The Product Actually Is

The description states

Proof-of-Care is a runtime governance system for AI agents that places an enforceable, auditable trust boundary between agent intent and tool execution. It validates session and signed capability manifest, evaluates provider/operator policy, incorporates domain-specific standing and authenticated contextual provenance, binds authorization to a canonical exact-action envelope, requires a single atomic dispatch claim at the final adapter boundary, and preserves a causally linked, reviewable history of authorization decisions, dispatch claims, and execution outcomes.

Inferred It is a Python-based system with SQLite governance state, HMAC-signed manifests, and strict JSON action envelopes. It supports filesystem read and one allowlisted HTTPS webhook path. It uses subprocess local executor and has no third-party runtime dependencies.

Back to contents

Positioning & Claim Evolution

The description states

AI agents need more than static permission toggles and activity logs. Proof-of-Care began as an executable governance specification for that boundary, with a focus on hardening against adversarial use—not merely adding happy-path features.

Inferred It positions itself as a security-first approach to AI agent control, focused on runtime enforcement rather than documentation or static policies. It evolved from a prototype to a hardened system through adversarial testing and audit feedback.

Back to contents

Target Customer & ICP

The description states

Not explicitly stated. The project is described as a governance system for AI agents, but no specific customer segment or persona is named.

Not evidenced No evidence of target customers, use cases, or ideal customer profile beyond the author’s own claims.

Back to contents

Business Model & Pricing Evidence

The description states

Not explicitly stated. The project is described as a prototype built for a hackathon and does not claim production readiness or pricing model.

Not evidenced No evidence of business model, pricing, revenue, or monetization strategy.

Back to contents

Technical & Delivery Signals

The description states

Built with Python 3.9+, SQLite, HMAC, JSON, webhooks, pytest, GitHub, Codex, GPT-5.6. Uses strict canonical JSON action envelopes, transactional event and projection writes, local executor subprocess, and concrete filesystem/webhook adapters. No runtime third-party dependencies.

Inferred It is a Python-based system with strong security engineering practices, including adversarial testing, formalized state transitions, and atomic writes. It was built using constrained AI collaboration (Codex) and adversarial audit feedback.

Back to contents

Traction & Maturity Signals

The description states

The project was submitted to the OpenAI 2026 hackathon. Milestone 8 (M8.0–M8.12) was added during the Build Week, including security regression harnesses, canonical action envelopes, and atomic projection rebuilds. The suite grew from 343 to 528 passing tests.

Not evidenced No evidence of revenue, customers, product adoption, or post-hackathon traction. The system is described as not production-ready.

Back to contents

Competitive Context

The description states

Not explicitly stated. No mention of competitors or market positioning beyond the author’s own claims.

Not evidenced No evidence of competitive landscape, existing solutions, or differentiation in the market.

Back to contents

Key Risks & Red Flags

Inferred from the description

  • The system is described as a prototype built for a hackathon and not production-ready.
  • It has no third-party dependencies but also lacks broader integration or scalability claims.
  • The author states that runtime remediations are merged, but formal closure and audit are pending.
  • The project is self-reported and unverified; no external validation or traction data exists.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific AI agent use cases does Proof-of-Care intend to govern?
  2. Has the system been tested in any real-world or simulated environments beyond the hackathon?
  3. What are the key assumptions about trust and provenance that underpin its design?
  4. How does it scale with increasing numbers of agents or actions?
  5. Are there plans for integration with existing AI agent platforms or frameworks?

Back to contents

Investment/Partnership Verdict

The description states

Proof-of-Care is a prototype built for a hackathon and not claimed to be production-ready. It was submitted as part of the OpenAI 2026 hackathon.

Not evidenced No evidence of commercial traction, revenue, or market validation. The system is described as experimental and under active development.

Inference This is an early-stage technical prototype with strong security engineering claims but no demonstrated product-market fit or commercial viability. It may be a valuable R&D asset or proof-of-concept, but not a commercial investment or partnership target at this stage.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.