OpenAI 2026 hackathon

Secoria

AI cyber-defense agents that investigate threats, prevent attacks, and prove every fix worked.

Solo project by Waleed Mohamed · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,889 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Secoria is a self-reported local web-based cyber-defense application designed to assist security analysts in investigating threats and preventing attacks. The project was built as part of the OpenAI 2026 hackathon by one founder, Waleed Mohamed. It claims to use a collective of specialized AI agents that analyze different domains of cybersecurity evidence without hiding disagreement or generating false confidence.

The description states Secoria investigates suspicious activity across identity, endpoint, and network evidence using "specialized agents" and then correlates their findings. It also supports preventive defense by assessing Linux hosts over SSH for vulnerabilities and creating staged remediation plans with post-remediation verification.

Key commercial due-diligence questions include: Is there any evidence of traction or customer adoption beyond the hackathon? What is the actual technical architecture and scalability of the solution? How does it compare to existing security tools in the market?

The most important open question is whether Secoria's approach can scale beyond a local research platform to real-world enterprise environments, especially given its current focus on isolated testbeds.

Back to contents

What The Product Actually Is

The description states that Secoria is a local web-based cyber-defense application with two workflows:

  1. Runtime Defense: Investigates suspicious activity across identity, endpoint, and network evidence using specialized agents.
  2. Preventive Defense: Assesses isolated Linux hosts over SSH for vulnerabilities and creates staged remediation plans.

The product combines:

  • A Python security engine
  • A Next.js and TypeScript interface
  • Docker-based Linux testbeds
  • Controlled SSH execution
  • Deterministic security specialists
  • Sealed evidence packages
  • Constrained GPT-5.6 investigation

It uses a "remediation engine" that employs validated action types and command templates, preventing GPT-5.6 from generating arbitrary shell commands.

Inference: The product appears to be an experimental or demonstration platform rather than a production-ready tool, based on its current use of isolated testbeds and local execution.

Back to contents

Positioning & Claim Evolution

The description states that Secoria was inspired by the idea of using a collective of specialized cyber-defense agents instead of one general-purpose model. These agents analyze different domains, preserve disagreement, and support human analysts with evidence-bound conclusions.

It claims to:

  • Investigate threats across identity, endpoint, and network evidence
  • Preserve disagreement rather than producing false confidence
  • Prevent language models from inventing evidence
  • Prove remediation through reassessment rather than command success
  • Enforce human approval in decision-making

The author also states that Secoria is a local research and demonstration platform using isolated Linux testbeds, not yet production-ready.

Inference: The positioning appears to be focused on improving analyst workflows in small security teams by leveraging AI for evidence collection and remediation while maintaining human control and transparency.

Back to contents

Target Customer & ICP

The description states that Secoria was inspired by security teams that have more alerts than they can investigate, particularly small teams struggling to connect evidence, understand what really happened, fix underlying weaknesses, and verify risks are gone.

It also mentions that the long-term goal is to help small security teams operate with the investigative and defensive depth of a much larger organization.

Inference: The target customer appears to be small-to-medium-sized security teams or analysts who face resource constraints in threat investigation and remediation. However, no specific customer segments or personas are defined beyond this general description.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not provide any information about pricing models, monetization strategies, or business models. It only describes the technical functionality of the product.

Back to contents

Technical & Delivery Signals

The description states that Secoria was built using:

  • Codex, Docker, GPT-5.6, ML, Next.js, Node.js, OpenAI Agents SDK, Pytest, Python, React, TypeScript
  • A Python security engine
  • A Next.js and TypeScript interface
  • Docker-based Linux testbeds
  • Controlled SSH execution
  • Deterministic security specialists
  • Sealed evidence packages
  • Constrained GPT-5.6 investigation
  • Approval-gated remediation
  • Rollback, revert, and post-remediation verification

It also mentions that the remediation engine uses validated action types and command templates to prevent GPT-5.6 from generating arbitrary shell commands.

Inference: The technical stack suggests a hybrid approach combining traditional security tools with AI components, emphasizing control over AI behavior through constraints and human oversight.

Back to contents

Traction & Maturity Signals

Not evidenced.

There is no evidence of revenue, customers, or adoption beyond the project being submitted to a hackathon. The description explicitly states that the current version is a local research and demonstration platform using isolated Linux testbeds.

Back to contents

Competitive Context

Not evidenced.

The description does not mention any competitors or how Secoria compares to existing solutions in the cybersecurity market.

Back to contents

Key Risks & Red Flags

  • Limited scope: The product is described as a local research and demonstration platform, not yet production-ready.
  • Single founder: Only one team member (Waleed Mohamed) is mentioned.
  • Unverified claims: All claims about functionality and benefits are self-reported without independent verification.
  • No traction or revenue data: No evidence of customers, users, or monetization exists.
  • Technical limitations: The use of isolated testbeds may limit real-world applicability.
  • AI dependency: Heavy reliance on GPT-5.6 raises questions about scalability and control.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific problems in current security workflows does Secoria solve that existing tools don't?
  2. How does Secoria ensure the accuracy of its AI-generated evidence and conclusions?
  3. Has there been any testing or validation beyond the hackathon environment?
  4. What are the plans for moving from isolated testbeds to production Linux hosts?
  5. Are there any partnerships or integrations with existing security platforms?
  6. What is the roadmap for addressing scalability and enterprise deployment challenges?
  7. How does Secoria handle privacy and data protection in its AI-assisted analysis?

Back to contents

Investment/Partnership Verdict

Not evidenced.

There is no evidence of financial performance, customer traction, or market validation to support an investment or partnership decision. The project remains at a very early stage, described as a hackathon submission with no commercial activity beyond that point. Any potential value would depend on future development and execution, which cannot be assessed from this self-reported description alone.

Confidence Level: Low — based entirely on self-reported information without external validation or evidence of traction, revenue, or customer adoption.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.