OpenAI 2026 hackathon

Q-Ray Vision

Kazakhstan's first AI antivirus: 9 ML models, 5-layer detection pipeline, anti-ransomware and anti-phishing (371K+ domains) protecting Kaspi, Halyk and eGov users on Windows 10/11.

Solo project by no name · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,750 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Project: Q-Ray Vision

Self-reported basis: The description is entirely from the author’s own submission to the OpenAI 2026 hackathon on Devpost — unverified, self-reported and without independent corroboration.

Commercial due-diligence read: Q-Ray Vision appears to be a self-contained, AI-powered antivirus engine built in Kazakhstan, targeting local threats with a focus on phishing, ransomware, and malware specific to Central Asian markets. It is described as an MVP with real-time protection, using 9 ML models and a 5-layer detection pipeline. The project is claimed to be developed by a single team member from Semey, Kazakhstan, and is positioned as the first homegrown AI antivirus in the region.

Most important open question: Is there evidence of any actual user adoption or traction beyond the authors’ own use?

Back to contents

What The Product Actually Is

The description states that Q-Ray Vision is a full-featured AI antivirus for Windows 10/11, built with:

  • A 5-layer detection pipeline:
    • Trust check
    • Hashing
    • Evidence collection
    • Static ML analysis
    • Dynamic sandbox (Unicorn Engine)
  • 9 ML models, trained on the EMBER2024 dataset and running fully on-device via ONNX Runtime
  • Real-time protection using a kernel-mode driver and AMSI integration
  • An anti-phishing database of 371K+ domains, with a goal to reach 1M+
  • Anti-ransomware behavioral protection with AES-256 encrypted quarantine

The system is described as built with 150K+ lines of C++20 and a JS-based interface layer, using static analysis and sandboxing for detection.

Inference: The product is an antivirus engine designed to detect local threats in Kazakhstan and Central Asia, with a focus on phishing, ransomware, and malware specific to the region. It is described as an MVP with real-time protection, but no evidence of actual deployment or user base is provided.

Back to contents

Positioning & Claim Evolution

The project is positioned as:

  • The first AI antivirus developed in Kazakhstan
  • A local solution for threats that foreign vendors ignore
  • Focused on protecting users of local services like Kaspi, Halyk, and eGov
  • Built by a team from Semey, Kazakhstan, competing in a market dominated by global players

The claim evolution shows:

  • Initial focus on local threat detection
  • Emphasis on self-reliance due to sanctions and licensing issues
  • A move toward AI-first engine, with ML models running locally
  • A stated goal of public beta with 500+ users and B2B pilots

Inference: The positioning is clearly regional, with a narrative around local threat awareness and national self-sufficiency. It is not yet clear if the project has evolved beyond an MVP or gained traction beyond its creators.

Back to contents

Target Customer & ICP

The description states that Q-Ray Vision targets:

  • Users of Kaspi, Halyk, eGov, and other local services
  • Small businesses in Kazakhstan and Central Asia
  • General users on Windows 10/11

There is no explicit mention of a B2B or enterprise ICP beyond the stated goal of B2B pilots.

Inference: The primary customer base appears to be individual users and small businesses in Kazakhstan, with a focus on local threats. No evidence of a defined ICP beyond this.

Back to contents

Business Model & Pricing Evidence

No information is provided about pricing, licensing, or monetization strategy.

Not evidenced

Back to contents

Technical & Delivery Signals

The project is described as:

  • Built using C++20, with a JS-based interface layer
  • Uses 150K+ lines of code
  • Implements a 5-layer detection pipeline:
    • Trust check → Hashing → Evidence collection → Static ML analysis → Dynamic sandbox (Unicorn Engine)
  • 9 ML models trained on EMBER2024 and running via ONNX Runtime
  • Real-time protection using a kernel-mode driver and AMSI integration
  • Anti-phishing database of 371K+ domains

The team used Codex to accelerate development during Build Week, and is working on:

  • Refactoring the C++20 core
  • Building an automated ML model update pipeline
  • Shipping a user dashboard

Inference: The technical stack suggests a strong engineering effort with local threat awareness. However, no evidence of production deployment or scalability beyond MVP.

Back to contents

Traction & Maturity Signals

The description states:

  • A working MVP with real-time protection used daily on the team’s own machines
  • One of the first AI-first antivirus engines developed in Central Asia
  • Team of 4 from Semey, Kazakhstan
  • Goal to reach 1M+ phishing domains
  • Next milestones: public beta with 500+ users, and B2B pilots

Not evidenced: No data on actual user adoption, customer base, or revenue.

Back to contents

Competitive Context

The project is described as being developed in a market dominated by global antivirus vendors. It is positioned as the first homegrown AI antivirus in Kazakhstan, suggesting it is competing with foreign solutions that may not address local threats.

Inference: The competitive context is defined by the lack of localized, AI-powered solutions for Central Asian users. However, no evidence of competitor analysis or market positioning beyond this.

Back to contents

Key Risks & Red Flags

  • Single developer team (as per description, only 1 member listed)
  • No verified user base or adoption
  • No revenue or monetization strategy
  • MVP-level product, not yet in production
  • Self-reported claims without independent verification
  • Limited technical depth — no evidence of integration with larger ecosystems or enterprise platforms

Inference: The project is at a very early stage, and the lack of verified traction or user data raises significant risk. The single-team structure may limit scalability.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual user base beyond your own machines?
  2. How are you planning to scale beyond the MVP?
  3. Are there any partnerships or pilot programs with local businesses or government entities?
  4. What is the plan for monetization and pricing?
  5. How do you intend to maintain and update the phishing database and ML models?
  6. What are the technical challenges in scaling to a larger user base?

Back to contents

Investment/Partnership Verdict

Not evidenced

The project is described as an MVP with real-time protection, built by a single team from Kazakhstan. It is positioned as a solution for local threats but lacks evidence of traction, revenue, or customer adoption.

Confidence: Low

Next steps: If this were a due-diligence context, further investigation would be needed into whether the authors have any actual users, partnerships, or funding beyond their own use and development.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.