OpenAI 2026 hackathon

REDACTRA — Protect Sensitive Data Before AI

REDACTRA is a Thai-first local privacy gateway for managed AI web apps. It tokenizes detected sensitive data on-device and uses GPT-5.6 only after local privacy and intent checks.

Team of 2 · 2 likes · 0 comments

Archive position — measured, not model output

2 likes on Devpost

221 of the 7,856 archived projects have more likes, and 285 share exactly 2 — so this project's #435 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

REDACTRA is a self-reported Thai-first privacy gateway for managed AI web apps, designed to tokenize sensitive data on-device before sending prompts to external services like GPT-5.6. The project claims to intercept and process prompts locally using detectors for Thai identifiers, then only pass policy-eligible requests to an LLM for semantic risk assessment. It is presented as a solution to the dilemma organizations face when allowing AI use without risking data leakage.

The author states that REDACTRA operates with a local agent and browser guard, uses GPT-5.6 only after privacy checks, and includes reversible tokenization. The system is built using React/Vite, Node.js, TypeScript, Manifest V3, and OpenAI's Responses API. It is described as a proof-of-concept submitted to the OpenAI 2026 hackathon.

Key open question

Is there any evidence of actual deployment, usage or traction beyond the PoC? The description does not indicate whether REDACTRA has been tested in real-world environments or adopted by organizations.

Back to contents

What The Product Actually Is

The description states that REDACTRA is a privacy gateway for managed AI web apps, operating as a local agent and browser guard. It intercepts prompts before they are sent to external services such as GPT-5.6, using local detectors to identify Thai-sensitive data.

It includes:

  • A Manifest V3 Browser Guard
  • A Loopback Node.js Local Agent with an origin allowlist, policy engine, in-memory token vault, response guard, and SHA-256 audit chain
  • Integration with the OpenAI Responses API, using structured outputs and store: false
  • Thai language packs for enterprise and healthcare use cases
  • A Reversible placeholder tokenization system, restored only within the originating session

The product is described as a PoC submitted to the OpenAI 2026 hackathon, built with tools including React/Vite, Node.js, TypeScript, FastText, and Codex.

Inference: The system appears to be designed for organizations that want to allow AI use while preventing sensitive data from leaving their local environment. It separates detection from LLM evaluation, placing the latter only after privacy checks.

Back to contents

Positioning & Claim Evolution

The description states that REDACTRA is a Thai-first local privacy gateway for managed AI web apps. It positions itself as an alternative to either:

  • Uncontrolled copy-and-paste of sensitive data into AI tools
  • Blocking AI entirely

It claims to offer a visible and testable path for handling sensitive data, with a focus on Thai identifiers and locally meaningful risk.

The author also states that the novelty lies in:

  • The combination of Thai-first language packs
  • Reversible local tokenization
  • Executable privacy evidence (as opposed to architecture diagrams)

Inference: REDACTRA is positioned as a privacy control tool for AI use, not a general-purpose AI platform or service. It emphasizes local processing and policy enforcement, with LLMs used only in a limited, controlled way.

Back to contents

Target Customer & ICP

The description states that REDACTRA is designed for:

  • Thai healthcare
  • Financial
  • Legal
  • HR
  • Contact-center teams

These groups are said to want to allow employees to use managed AI web apps without copying raw identifiers into external services.

Inference: The target customer segment appears to be enterprise users in regulated industries, particularly those in Thailand, who are concerned about data privacy and compliance when using AI tools.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not include any information on:

  • Revenue model
  • Pricing structure
  • Monetization strategy
  • Customer acquisition or retention plans

Inference: There is no evidence of a business model beyond the PoC submission. The project is presented as a hackathon entry, with no indication of commercial intent or pricing.

Back to contents

Technical & Delivery Signals

The description includes:

  • Manifest V3 Browser Guard
  • Loopback Node.js Local Agent
  • OpenAI Responses API with structured outputs and store: false
  • Thai language packs for healthcare and enterprise
  • Reversible placeholder tokens
  • React/Vite Proof Console
  • Integration request capture proving no OpenAI calls are made for sensitive data

It also mentions:

  • Use of FastText for detection
  • Deterministic evaluation fixtures
  • Executable zero-call integration tests

Inference: The technical stack suggests a browser-based privacy control system, with local processing and limited LLM involvement. The use of structured outputs and deterministic fixtures implies an emphasis on reproducibility and testability.

Back to contents

Traction & Maturity Signals

Not evidenced.

The description does not include:

  • Customer data
  • Revenue or ARR
  • Adoption metrics
  • Product usage statistics
  • Deployment history

It is described as a PoC submitted to the OpenAI 2026 hackathon, with no indication of real-world use or product maturity beyond that.

Inference: There is no evidence of traction, adoption, or commercial deployment. The project remains in early-stage development.

Back to contents

Competitive Context

Not evidenced.

The description does not mention:

  • Competitors
  • Market positioning relative to other privacy tools
  • Prior art or similar solutions
  • Industry benchmarks or market size

Inference: No competitive context is provided. It is unclear whether REDACTRA is addressing a known gap in the market or if it is a novel concept.

Back to contents

Key Risks & Red Flags

  1. Unverified claims: The description is self-reported and unverified.
  2. No evidence of traction or adoption: The project is described as a hackathon PoC with no commercial deployment.
  3. Use of GPT-5.6: The author states that GPT-5.6 is not a real model (as it does not exist), but the description still refers to it, which may be misleading.
  4. No pricing or monetization strategy: No indication of how the product would generate revenue.
  5. Limited scope: The focus on Thai identifiers and specific use cases may limit scalability.

Inference: REDACTRA is a conceptual privacy tool, not a proven product. Its lack of real-world deployment, traction, or business model raises significant risk for commercial viability.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual technical architecture and how does it differ from generic AI gateways?
  2. How are false negatives in detection handled, and what is the risk tolerance level?
  3. Is there any evidence of real-world testing or pilot use cases beyond the PoC?
  4. What is the plan for scaling beyond Thai identifiers and into other markets?
  5. Are there any commercial partnerships or customers already engaged with REDACTRA?
  6. How does the system handle edge cases where detection fails or is uncertain?
  7. What are the plans for integrating with existing enterprise AI platforms or tools?

Back to contents

Investment/Partnership Verdict

Not evidenced.

The description does not provide:

  • Financials
  • Valuation
  • Funding history
  • Strategic partnerships
  • Market opportunity size

Inference: The project is a conceptual PoC, not a commercial entity. It lacks evidence of traction, revenue, or business model. Any investment or partnership potential would depend on future development and proof of concept validation.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.