OpenAI 2026 hackathon

TraceProof

TraceProof turns Codex sessions into local, tamper-evident proof packs linking prompts, code changes, approvals, and tests—so AI-assisted work is verifiable.

Solo project by Dimitris Lisgaras · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #7,358 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

TraceProof is a self-reported local-first plugin for Codex that captures and chains coding session events into tamper-evident proof packs. It claims to make AI-assisted work verifiable by linking prompts, code changes, approvals, and tests using SHA-256 hashing and Git snapshots.

What changed

The author states they built a working installable plugin and dashboard with cryptographic verification features, including redaction of credentials, local storage, and live multi-project monitoring. They also claim to have addressed challenges around distinguishing activity from evidence and treating traces as sensitive data.

Single most important open question

Does TraceProof actually solve a real problem in AI-assisted development workflows, or is it an academic or experimental tool that lacks commercial traction or adoption?

Back to contents

What The Product Actually Is

The description states that TraceProof is:

  • A local-first Codex plugin and interactive dashboard
  • Designed to turn coding sessions into tamper-evident proof packs
  • Uses SHA-256 hash chaining and a head anchor to detect tampering
  • Captures requests, tool activity, permission boundaries, Git state, and test execution
  • Redacts likely credentials before storage
  • Stores captured data locally on the developer's machine
  • Provides a dashboard for verification, claim-to-change-to-validation graphs, timeline, evidence inspector, and transparent proof score

The author describes it as a tool that:

  • Uses native Codex lifecycle hooks
  • Implements Node.js for local capture and verification
  • Leverages Next.js, React, and TypeScript for the dashboard
  • Supports live multi-project monitoring
  • Includes an Integrity Lab where judges can modify sealed events to see verification fail

Inferred: The system appears to be a developer tool focused on auditability and integrity of AI-assisted code changes.

Back to contents

Positioning & Claim Evolution

The author states:

  • AI coding agents produce large changes quickly, but reviewers must still answer why they should trust the change
  • Existing traces show activity (prompts, tokens) but do not connect original requests to code changes and validation
  • TraceProof aims to make AI-assisted work reviewable by default

The positioning is:

  • A developer tool for AI-assisted code review
  • Positioned as a solution to trust issues in AI coding workflows
  • Claims to provide verifiable proof of AI-assisted work

Inferred: The author evolved the idea from observing that trace data alone does not create trust, but rather requires linking claims to changes and then to verifiable evidence.

Back to contents

Target Customer & ICP

The description states:

  • TraceProof is built for developers working with Codex
  • It supports live multi-project monitoring, suggesting use in team or enterprise settings
  • The dashboard allows judges to inspect proof packs, implying a role for reviewers or auditors

Inferred: The primary customer appears to be developers using AI coding tools, particularly those in environments where code review and auditability are important.

Not evidenced:

  • No stated target industry, company size, or specific use cases
  • No evidence of existing customers or adoption

Back to contents

Business Model & Pricing Evidence

The description states:

  • TraceProof is a plugin and dashboard
  • It is installable (as a Codex plugin)
  • The public demo contains fictional projects and synthetic sessions
  • No pricing, licensing model, or monetization strategy is mentioned

Inferred: The business model appears to be developer tooling, likely with a freemium or open-source approach, but no evidence of revenue streams.

Not evidenced:

  • No pricing information
  • No stated monetization strategy
  • No evidence of paid customers or subscriptions

Back to contents

Technical & Delivery Signals

The description states:

  • Built using Codex lifecycle hooks
  • Uses Node.js for local capture and verification
  • Implements SHA-256 hash chaining and a head anchor
  • Uses Git snapshots to capture branch, commit, and working-tree state
  • Includes credential redaction and bounded payload capture
  • Dashboard built with Next.js, React, TypeScript
  • Supports browser-side proof verification
  • Uses Node’s built-in test runner for integrity tests

Inferred: The tool is technically robust in its implementation, with cryptographic and local-first design principles.

Not evidenced:

  • No evidence of production deployment or scalability
  • No evidence of performance metrics or user feedback on technical delivery

Back to contents

Traction & Maturity Signals

The description states:

  • Built as a solo project (1 team member)
  • Submitted to the OpenAI 2026 hackathon
  • Contains a public demo with fictional projects
  • The demo is described as synthetic, not real-world data
  • No mention of user adoption, feedback, or usage metrics

Inferred: The project is in early development and lacks real-world traction.

Not evidenced:

  • No revenue, customers, or user base
  • No evidence of product-market fit or adoption
  • No evidence of ongoing development or iteration beyond the hackathon submission

Back to contents

Competitive Context

The description does not mention any competitors or existing tools in this space.

Inferred: The author appears to be targeting a niche within AI-assisted code review and auditability, but no competitive landscape is described.

Not evidenced:

  • No mention of existing tools or platforms
  • No evidence of market analysis or differentiation from other solutions

Back to contents

Key Risks & Red Flags

The description states:

  • The public demo contains fictional projects and synthetic sessions
  • The tool is built as a solo project, with no team or external support
  • It is designed for local-first use, which may limit scalability or enterprise adoption
  • No evidence of real-world testing or feedback

Red flags:

  • Lack of real-world usage: The demo is synthetic and fictional
  • Solo development: No team or external validation
  • Limited scope: Designed for local use, not enterprise or CI/CD pipelines
  • No monetization strategy: No indication of how the tool will be commercialized

Back to contents

Diligence Questions To Ask The Founders

  1. What specific problem in AI-assisted development workflows are you solving?
  2. Have you tested TraceProof with real developers or teams, and what feedback did you get?
  3. How does TraceProof integrate into existing CI/CD pipelines or team workflows?
  4. What is your plan for monetization or commercial viability?
  5. Are there any known limitations in scalability or performance at scale?
  6. How do you plan to address the challenge of credential redaction and data sensitivity?
  7. What are the key assumptions about developer behavior or adoption?

Back to contents

Investment/Partnership Verdict

The description states:

  • TraceProof is a self-reported hackathon project
  • It is built as a local-first tool with cryptographic integrity features
  • The author claims to have solved issues around distinguishing activity from evidence
  • No revenue, customers, or traction data are provided

Inferred: This is an early-stage idea with strong technical execution but no demonstrated commercial viability or market traction.

Not evidenced:

  • No financials, revenue, or customer data
  • No indication of a scalable business model
  • No evidence of competitive positioning or market demand

Verdict Not ready for investment or partnership. The tool shows promise in its technical design and solves a plausible problem, but lacks real-world validation, traction, and commercial clarity.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.