OpenAI 2026 hackathon

Rayluno

A local-first bilingual Windows assistant that proves every authorized action before it affects your computer.

Solo project by Zaid Hijazi · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,776 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Rayluno is a self-reported local-first Windows assistant designed for bilingual (Arabic/English) use, with an emphasis on security and user control. The project claims to implement a "verified execution" architecture that requires explicit consent before any action affects the system, using deterministic policies and bounded skill sets.

The author states that Rayluno is built with a combination of AI tools (Codex, GPT-5.6), Python, PowerShell, SQLite, and Ollama, among others. It includes features such as an "Explicit-consent Memory Vault", "Verified Execution", and a "Runtime Trust Center" to track actions and permissions.

Key commercial due-diligence read: The description presents a strong technical architecture but lacks evidence of revenue, customers, or adoption. There is no indication of traction, pricing, or business model beyond the author's own claims. The project appears to be in early development, with a focus on security and accessibility for specific user groups.

Most important open question: Is there any evidence that Rayluno has moved beyond prototype or demo stage into actual use by individuals or organizations?

Back to contents

What The Product Actually Is

The description states that Rayluno is:

  • A local-first Windows personal assistant.
  • Designed to support both Arabic and English languages.
  • Built with a verified execution model, where AI may propose actions but only those explicitly allowed by deterministic policies are executed.
  • Includes five connected product surfaces:
    • Personal Command Center
    • Explicit-consent Memory Vault
    • Verified Execution
    • Authenticated Execution Proof
    • Runtime Trust Center

It also includes:

  • A judge path that supports local speech recognition (Vosk), Arabic correction, and optional Ollama fallback.
  • A trust architecture involving:
    • Registered skills
    • Expiring, plan-specific approvals
    • Local receipt persistence
    • Hash-linked trust history protected by HMAC checkpoint

The system is described as not exposing general shell or unrestricted OS command authority to the AI model.

Inference: Rayluno appears to be a proof-of-concept or prototype tool focused on secure automation and control over personal computing tasks, particularly for users who value privacy and safety in AI-assisted workflows.

Back to contents

Positioning & Claim Evolution

The author positions Rayluno as:

  • A third path between unsafe extremes: either chat-only assistants or those with broad access that are hard to constrain.
  • An assistant that proves every authorized action before it affects your computer.
  • A tool for people who need hands-free or low-friction computing without surrendering control.

It is framed as a solution for users with specific needs:

  • People who cannot rely on traditional input
  • Those recovering from hand injuries
  • Creators managing multiple tasks
  • Busy professionals

The project also emphasizes:

  • No general command authority
  • Telemetry disabled by default
  • Explicit consent memory
  • Local-only verification

Inference: Rayluno positions itself as a secure, privacy-conscious alternative to mainstream AI assistants, targeting niche but high-value user groups. However, the description does not indicate any market positioning beyond its own self-reporting.

Back to contents

Target Customer & ICP

The author states that Rayluno targets:

  • People who need hands-free or low-friction computing
  • Users who cannot rely on traditional input
  • People recovering from hand injuries
  • Creators managing multiple tasks
  • Busy professionals

There is no mention of:

  • Specific industries
  • Enterprise use cases
  • Customer segments beyond general accessibility needs
  • Any defined persona beyond "users with specific accessibility or control concerns"

Inference: The ICP seems to be individuals with accessibility requirements or those prioritizing security and control in their computing environment. No evidence suggests a broader commercial customer base.

Back to contents

Business Model & Pricing Evidence

The description does not contain any information about:

  • Revenue streams
  • Pricing models
  • Monetization strategies
  • Customer acquisition plans
  • Subscription or licensing structures

There is no indication of whether the project intends to be monetized, nor how it would generate value for users.

Inference: No evidence exists regarding a business model or pricing strategy. The project appears to be in an early development phase without commercial traction or monetization plans.

Back to contents

Technical & Delivery Signals

The author reports:

  • Built using:
    • Codex powered by GPT-5.6
    • GitHub Actions
    • Python, PowerShell, SQLite, Ollama
    • Vosk for speech recognition
    • pywebview for UI
  • Reproducible setup instructions provided (Python 3.11+ environment)
  • 467 automated tests across Windows and Ubuntu
  • CI matrix for Python 3.11/3.13
  • Adversarial regression testing for various failure modes
  • Implementation of:
    • Write-ahead authorization
    • Installation-scoped HMAC evidence
    • Local SQLite data storage

The system is described as not exposing raw commands or arguments to the JavaScript interface.

Inference: The technical implementation shows a strong focus on security and reproducibility. However, there is no evidence of production deployment, scalability, or performance metrics beyond testing.

Back to contents

Traction & Maturity Signals

The description states:

  • This is a hackathon submission
  • The current activation endpoint is hosted on a third-party HTTPS subdomain as a temporary prototype
  • No revenue, customers, or adoption data are reported
  • The project includes:
    • A demo launcher script
    • Explicit approval flow
    • Fail-closed behavior for unknown actions
    • Inspection capabilities via Verified Execution

There is no mention of:

  • User feedback
  • Beta testing
  • Product usage statistics
  • Market validation
  • Commercial partnerships or integrations

Inference: Rayluno appears to be a prototype or early-stage product, likely not yet in production use. No evidence of traction or maturity beyond the author’s own development efforts.

Back to contents

Competitive Context

The description does not provide any information about:

  • Competitors
  • Market landscape
  • Differentiation from existing tools
  • Prior art or similar solutions

It only mentions that personal AI assistants often fall into two unsafe extremes:

  1. Chat-only, no meaningful work
  2. Broad tool access, difficult to constrain

Inference: The competitive context is not described. It's unclear whether Rayluno directly competes with existing AI assistants or fills a gap in the market for secure automation.

Back to contents

Key Risks & Red Flags

Key risks and red flags based on the description:

  • No commercial traction or revenue evidence
  • Prototype-only architecture — activation endpoint is temporary, hosted externally
  • Limited scope of functionality — only demonstrates core trust features, not full utility
  • No hardware-backed security — local HMAC checkpoint is not secure against tampering
  • No encryption for local data
  • Development installers are not Authenticode-signed
  • Crash recovery reconciliation remains future work

There is no evidence of:

  • Customer validation
  • Market demand
  • Scalable infrastructure
  • Long-term sustainability

Inference: The project is technically impressive but lacks commercial viability or real-world application. Risks include lack of traction, incomplete security features, and unclear path to monetization.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current status of Rayluno beyond the hackathon prototype?
  2. Are there any users currently testing or using Rayluno in real-world scenarios?
  3. How does the team plan to transition from a demo environment to a production-ready system?
  4. Is there a roadmap for addressing known limitations like crash recovery and encryption?
  5. What is the intended monetization strategy, if any?
  6. Are there plans to expand beyond Windows or support other platforms?
  7. Has the project undergone any independent security audits?
  8. How does Rayluno compare to existing tools in terms of usability and accessibility?

Back to contents

Investment/Partnership Verdict

The description presents Rayluno as a technically sophisticated prototype with strong emphasis on security, control, and accessibility. However, there is no evidence of commercial traction, revenue, or customer adoption.

The project appears to be in an early stage, likely not yet suitable for investment or partnership unless significant progress is made toward production readiness and market validation.

Verdict: Not ready for investment or partnership at this time. The product shows promise but lacks evidence of viability or scalability beyond the author’s own development efforts.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.