OpenAI 2026 hackathon

Veritylane

Compile tender security claims into inspectable evidence.

Solo project by Helen Kwok · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #7,532 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Veritylane is a self-reported tool for compiling tender security claims into inspectable evidence, built as a project for the OpenAI 2026 hackathon. It uses GPT-5.6 and Codex to structure requirements and deterministic scanners to assess repository-based evidence, producing structured JSON and HTML reports without generating compliance scores.

What changed

The author describes Veritylane as an experimental tool that transforms multilingual security requirements into evidence-linked assurance cases. It is not a commercial product but a proof-of-concept built in a single-person team context.

Single most important open question

Is there any evidence of traction, revenue, or customer adoption beyond the author’s own development work?

Back to contents

What The Product Actually Is

The description states that Veritylane is a project-local Codex skill using GPT-5.6 and deterministic TypeScript scanners to assess software security claims in tender contexts. It processes multilingual requirements and maps them to repository evidence, producing structured JSON and HTML reports.

It includes:

  • A Codex skill that defines the assessment procedure.
  • Use of GPT-5.6 for decomposing requirements and identifying evidence questions.
  • Deterministic scanners that inspect bounded repository inputs.
  • Output in structured JSON, assurance-case artifacts, and a self-contained HTML report with visualizations.

The tool is described as non-certifying: it does not generate compliance scores, but rather links claims to evidence states (e.g., technical evidence supported, human required).

Not evidenced:

  • Whether this is a working product or just a prototype.
  • Whether the tool has been used in real-world tender scenarios.
  • If any of its outputs have been adopted by public-sector clients.

Back to contents

Positioning & Claim Evolution

The author states that Veritylane helps software suppliers turn tender security clauses into evidence-linked assurance cases, without pretending that repository evidence proves compliance.

It is positioned as a tool for:

  • Reducing the time bid teams spend on defensible responses.
  • Preventing unsupported claims from entering tenders or contracts.
  • Supporting engineers and reviewers in answering security questions.

The core claim is:

“Compliance claims should be compiled from evidence, not generated from confidence.”

This positioning emphasizes evidence-based assurance, not certification or compliance scoring.

Not evidenced:

  • Whether this is a new market need or an existing solution gap.
  • How the tool differentiates from other security or compliance tools.
  • If there are any external endorsements or use cases beyond the author’s own work.

Back to contents

Target Customer & ICP

The description states that Veritylane is intended for software suppliers in public-sector tendering contexts, where:

  • Security requirements arrive as prose.
  • Evidence must be scattered across source code, configuration files, and organisational records.
  • Bid teams need defensible responses quickly.
  • Engineers and security reviewers must prevent unsupported claims.

It targets:

  • Public-sector software suppliers
  • Security reviewers and engineers
  • Tender bid teams

Not evidenced:

  • Whether the tool has been tested or used by actual public-sector clients.
  • If there are specific customer segments or personas beyond the author’s own use case.
  • If any of these users have provided feedback or paid for access.

Back to contents

Business Model & Pricing Evidence

The description does not state a business model or pricing structure. It is described as a hackathon project, with no mention of:

  • Revenue streams
  • Subscription plans
  • Licensing models
  • Paid APIs or cloud services

Not evidenced:

  • Any commercialization strategy.
  • Whether the tool is intended to be sold, licensed, or offered as SaaS.
  • If there are any pricing tiers or customer acquisition costs.

Back to contents

Technical & Delivery Signals

The project is built with:

  • Codex (development environment and part of the product)
  • GPT-5.6
  • TypeScript
  • Node.js 24
  • Deterministic scanners
  • HTML, CSS, Vega-Lite, Flint-chart

It includes:

  • A project-local Codex skill
  • A core scanner pipeline
  • No third-party runtime dependencies
  • Automated tests and CI on Ubuntu and Windows
  • Self-contained HTML reports with visualizations

The tool is described as:

  • Reproducible
  • Non-certifying
  • Focused on evidence mapping, not scoring

Not evidenced:

  • Whether the tool has been scaled beyond a single-person development environment.
  • If it has been integrated into existing CI/CD pipelines or enterprise systems.
  • Any performance metrics or scalability claims.

Back to contents

Traction & Maturity Signals

The project is described as a hackathon submission, built by a single developer (Helen Kwok). It includes:

  • A demo video
  • Automated tests
  • Node.js CI pipeline
  • Sanitized fixtures for testing

Not evidenced:

  • Any real-world usage or adoption.
  • Customer feedback or testimonials.
  • Revenue, ARR, or funding rounds.
  • Product roadmap or version history.

Back to contents

Competitive Context

The description does not mention any competitors. It is a self-contained project with no reference to:

  • Existing tools in the compliance, security, or tendering space
  • Market leaders or substitutes
  • Industry standards or frameworks (e.g., ISO 27001, NIST)

Not evidenced:

  • Whether similar tools already exist.
  • How Veritylane compares to them.
  • Any competitive advantage claimed by the author.

Back to contents

Key Risks & Red Flags

  • Single-person development: The project is a solo effort, raising questions about scalability and long-term maintenance.
  • No commercial traction: No evidence of customers, revenue, or adoption beyond the author’s own use.
  • Hackathon origin: The tool was built for a hackathon, not as a commercial product.
  • No third-party integrations: It is described as self-contained with no external dependencies, which may limit its utility in enterprise settings.
  • Unverified claims: The tool does not generate compliance scores or certifications — this may be a limitation for users seeking formal assurance.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the intended path to commercialization?
  2. Has the tool been tested with real public-sector clients or tender teams?
  3. How does it handle multi-actor obligations (e.g., where compliance depends on actions outside the repository)?
  4. Is there a plan for integrating with existing CI/CD or security tools?
  5. What are the limitations of the current deterministic scanners, and how might they scale?
  6. Are there any plans to support additional languages or regulatory frameworks beyond the 57-record government catalogue?

Back to contents

Investment/Partnership Verdict

The project is a self-reported hackathon submission with no evidence of commercial traction, revenue, or customer adoption. It is described as a proof-of-concept tool built by one person, focused on mapping security requirements to repository evidence.

There is no evidence that it has been used in production, scaled beyond a single developer, or adopted by any customers. The tool’s positioning as non-certifying and its focus on structured evidence mapping may not align with the needs of public-sector buyers seeking formal compliance outcomes.

Confidence level: Low

This is a preliminary project, not a product ready for investment or partnership. It requires further validation in real-world use cases, customer feedback, and commercialization strategy before any due-diligence assessment can proceed.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.