OpenAI 2026 hackathon

Sindook Steward

Threat-aware access and key-rotation planning for encrypted files

Solo project by Ruddro Roy · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #6,722 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Sindook Steward is a local workbench for managing access control decisions on encrypted files, using AI to interpret threats and guide cryptographic operations. It is built as a prototype for an OpenAI hackathon and includes a deterministic policy engine, a React interface, and a Docker-based judge path.

What changed

The project evolved from a standalone open-source encryption tool (Sindook) into a new workbench (Sindook Steward), which adds a decision layer using GPT-5.6 for threat classification and integrates with the original CLI tool for execution.

Single most important open question

Is there any evidence of traction, revenue, or adoption beyond the author’s own prototype? The description states no such data exists, and all claims are self-reported.

Back to contents

What The Product Actually Is

The description states that Sindook Steward is a local workbench for handling access events on encrypted files. It supports four actions: adding a recipient, routine key hygiene, removing a recipient, and responding to escaped ciphertext copies.

It uses:

  • A pinned version of the Sindook CLI (v0.3.0)
  • GPT-5.6 for classifying risk signals
  • A deterministic policy engine
  • A React-based UI
  • A Docker judge path for testing

The system is designed to not execute commands directly but instead guide operators through a reviewable workflow that includes:

  • Describing the access change and threat
  • Using GPT-5.6 to classify risk signals
  • Checking against deterministic policy
  • Reviewing exact recipients, cost, guarantees, and remaining risk
  • Typing literal approval "ROTATE" before execution

Execution is performed via a pinned binary against a disposable sample vault, with an evidence ledger showing what changed.

Inference The product is not a production-ready service but a prototype for a hackathon submission. It does not appear to support real-world file encryption or key management beyond local testing.

Back to contents

Positioning & Claim Evolution

The author states that Sindook Steward was built as a decision layer over the Sindook CLI, which they describe as an open-source file-encryption tool named after the Bengali word for "strongbox".

The positioning is:

  • A local workbench, not a cloud service
  • Focused on threat-aware access control
  • Designed to avoid false promises about what can be undone or controlled

The claim evolution shows:

  1. The original Sindook project was a public encryption tool.
  2. Sindook Steward adds an AI-driven decision layer for managing access events.
  3. It emphasizes that the AI does not execute commands, and that security decisions are authoritative.

Inference The positioning is defensive — it avoids overpromising on what AI can do in a security context, but this also limits its commercial appeal or scalability.

Back to contents

Target Customer & ICP

The description states:

  • The system is designed for operators managing access to encrypted files
  • It supports local workflows, not cloud-based services
  • It is built for security professionals or developers who need to manage access control decisions

It does not state:

  • Who the end users are beyond operators
  • Whether it targets enterprise, individual developers, or internal teams
  • If there’s a defined persona or ICP

Inference The target customer is likely technical users with security responsibilities, but no clear segmentation or persona is described.

Back to contents

Business Model & Pricing Evidence

The description states:

  • The project is a hackathon submission
  • It is built as a local prototype
  • No pricing, monetization, or business model is mentioned
  • The system uses open-source tools and a Docker judge path for testing

There is no evidence of:

  • Revenue streams
  • Pricing models
  • Customer acquisition plans
  • Monetization strategy

Inference There is no business model or pricing evidence. The project appears to be a proof-of-concept, not a commercial offering.

Back to contents

Technical & Delivery Signals

The description states:

  • Built with Go, React, Docker, and GPT-5.6
  • Uses a deterministic policy engine that overrides AI decisions
  • GPT-5.6 is used only for interpreting threats, not for executing commands
  • The system includes a sample vault, tests, and a judge path
  • It supports fast rotation (without re-encryption) and deep rotation (with new key)
  • The interface shows residual risk before approval

It also states:

  • The project was built using Codex for coding and debugging
  • The author used ChatGPT Work for documentation and editing
  • No real secrets or keys are passed to the AI model

Inference The technical stack is functional but limited to a local prototype. The use of deterministic policy and clear separation from AI execution suggests a strong emphasis on security, but not scalability.

Back to contents

Traction & Maturity Signals

The description states:

  • This is a hackathon submission
  • It is a local prototype
  • No revenue, customers, or adoption data are provided
  • The author built the system in one week (Build Week)
  • The repository includes a dated baseline and commit history

There is no evidence of:

  • Customers
  • Revenue
  • Product usage
  • Market traction
  • Product maturity beyond prototype stage

Inference No traction or maturity signals exist. This is a very early-stage prototype.

Back to contents

Competitive Context

The description does not mention:

  • Competitors
  • Existing tools in the access control or encryption space
  • How this differs from other solutions

It only states that the author built it to avoid false promises and to help interpret security decisions without allowing AI to control them.

Inference No competitive context is provided. The project appears to be unique in its approach but lacks any comparison to existing tools or markets.

Back to contents

Key Risks & Red Flags

  • No commercial traction or revenue: This is a prototype, not a product with users.
  • Limited scope and maturity: Built for a hackathon, not production use.
  • AI role is minimal and controlled: The AI does not execute commands — this may limit its utility in real-world applications.
  • No security review or production-ready features: The author notes that it would need an external security review to be production-ready.
  • Self-reported only: All claims are unverified, and no third-party data is available.

Inference The project is not ready for commercial use. It may be a useful concept but lacks any evidence of viability or scalability.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the intended path to production readiness?
  2. Are there plans to expand beyond local execution and support real-world file encryption?
  3. How would this product integrate with existing enterprise access control systems?
  4. Has the author considered how to handle edge cases or adversarial inputs in the AI model?
  5. Is there any plan for external security review or compliance validation?
  6. What is the long-term vision for monetization or commercial adoption?

Back to contents

Investment/Partnership Verdict

Not evidenced.

The description states that this is a hackathon submission, not a commercial product. There is no evidence of:

  • Revenue
  • Customers
  • Traction
  • Product-market fit
  • Commercial viability

It is a local prototype with a clear security-focused design, but it does not appear to be ready for investment or partnership at this stage.

Inference This project is not suitable for investment or partnership unless there are plans to scale beyond the prototype stage. It may be of interest as a concept or proof-of-concept, but no commercial due-diligence case can be made from the provided evidence.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.