Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #6,296 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
ReCyra AI is a self-reported counterfactual security analyst powered by GPT-5.6 Sol and a deterministic attack-graph engine. It allows users to simulate proposed changes in cybersecurity contexts (e.g., disabling MFA, delaying patches) and assess risk impact before acting.
What changed
The project was submitted as part of the OpenAI 2026 hackathon. The author describes building a tool that combines large language models with structured reasoning and deterministic simulations to evaluate security decisions.
Single most important open question
Does ReCyra offer a viable commercial product or service, or is it an experimental prototype? There is no evidence of revenue, customers, or adoption beyond the author’s own account.
What The Product Actually Is
The description states that ReCyra AI is a counterfactual security analyst. It allows users to describe proposed changes in natural language and simulates consequences using both GPT-5.6 Sol and a deterministic attack-graph engine.
Key components include:
- A frontend built with React, TypeScript, Vite, and Cytoscape.js.
- A backend built with FastAPI, Pydantic, and NetworkX.
- Integration with Codex SDK for GPT-5.6 Sol.
- Use of structured investigation plans validated by schema.
- Deterministic engine to calculate risk numbers.
- Two-stage model flow: planning → simulation → explanation.
The system is described as rejecting invalid outputs and using fallback behavior when needed.
Confidence Low — based entirely on self-reported implementation details without independent verification or evidence of functionality beyond the author’s own account.
Positioning & Claim Evolution
The author claims ReCyra AI is a "GPT-5.6 Sol powered security analyst that simulates proposed changes before they happen."
It positions itself as:
- A tool for evaluating cybersecurity decisions.
- An alternative to traditional dashboards that only show what is happening now.
- A way to assess risk impact, evidence, and safe next actions.
The project evolved from a personal question: “What if a security team could test a decision before taking the risk?” This suggests an intent to solve real-world problems in enterprise security but does not indicate any traction or market validation.
Confidence Low — claims are self-reported and lack external corroboration.
Target Customer & ICP
The description states that ReCyra AI targets security teams who receive requests like:
- “Can we disable MFA for this executive?”
- “Can the VPN patch wait another month?”
It is implied that these users are looking to evaluate trade-offs involving exposure, time, business pressure, and compensating controls.
However, there is no explicit mention of:
- Specific industries or company sizes.
- Named customers or use cases beyond hypotheticals.
- Any segmentation strategy or persona definition.
Confidence Very low — no evidence of target customer identification or market research.
Business Model & Pricing Evidence
There is no evidence in the description of any business model, pricing structure, monetization strategy, or revenue streams.
The author mentions:
- Using Codex SDK.
- Building a local version with existing login credentials (no API key required).
- No mention of paid subscriptions, licensing, or enterprise sales.
Confidence Not evidenced — no indication of how the product would be sold or funded.
Technical & Delivery Signals
The project uses:
- Frontend: React, TypeScript, Vite, Cytoscape.js
- Backend: FastAPI, Pydantic, NetworkX
- AI/ML stack: GPT-5.6 Sol via Codex SDK
- Architecture: Two-stage model flow (planning → simulation → explanation)
- Safety mechanisms: Schema validation, deterministic fallbacks, rejection of invalid outputs
The author notes:
- 33 automated tests and six deterministic scenario evaluations.
- Integration with existing tools like vulnerability scanners and identity systems is planned but not implemented yet.
Confidence Medium — technical architecture is described in detail, but no evidence of production deployment or scalability.
Traction & Maturity Signals
The description contains no evidence of:
- Revenue
- Customers
- Adoption
- Product-market fit
- Market traction
- Any form of user feedback or usage metrics
It does state that the current version passes 33 automated tests and six deterministic evaluations, but this is not indicative of real-world use.
The project was submitted to a hackathon, indicating early-stage development.
Confidence Very low — no signs of traction or maturity beyond prototype status.
Competitive Context
There is no evidence in the description of:
- Competitors
- Market analysis
- Competitive positioning
- Prior art or similar products
The author does not reference existing tools for cybersecurity risk assessment, simulation, or decision support.
Confidence Not evidenced — no competitive landscape information provided.
Key Risks & Red Flags
Several risks and red flags are implied by the description:
- Unproven commercial viability: No evidence of revenue, customers, or product-market fit.
- Prototype nature: Submitted to a hackathon; likely not production-ready.
- Dependency on proprietary AI models: Reliance on GPT-5.6 Sol and Codex SDK may pose long-term sustainability issues.
- Limited scope: Only tested with curated demo data; integration with real systems is planned but unimplemented.
- Trustworthiness concerns: While safety mechanisms are described, the system still relies heavily on LLMs for interpretation and explanation.
Confidence Medium — these are inferred from the lack of evidence rather than stated facts.
Diligence Questions To Ask The Founders
- What is your plan to transition from a hackathon prototype to a commercial product?
- Have you identified specific enterprise customers or use cases beyond hypotheticals?
- How do you intend to monetize ReCyra AI? Is there a pricing model in place?
- What are the technical limitations of integrating with real asset inventories, vulnerability scanners, and identity systems?
- Are there any legal or compliance implications around using GPT-5.6 Sol for security decision-making?
- How does ReCyra handle edge cases or unexpected inputs during simulations?
Investment/Partnership Verdict
Not evidenced.
There is no evidence of:
- Revenue
- Customers
- Traction
- Product-market fit
- Commercial viability
The project appears to be a self-reported hackathon prototype, not a commercial offering.
Inference If this were to become a viable product, it would require significant development, validation, and integration with real enterprise systems. As of now, there is no indication that such steps have begun.
Confidence Very low — the description offers no basis for assessing investment or partnership potential.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
