OpenAI 2026 hackathon

ZeroKit AI Control Plane

Turn sanitized SaaS requirements into validated control-plane configs, least-privilege RBAC, endpoint maps, and auditable evidence with Codex + GPT-5.6.

Solo project by Mehmet Aydoğan · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #7,806 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

ZeroKit AI Control Plane is a developer tool that uses AI (specifically Codex + GPT-5.6) to generate SaaS configuration artifacts from sanitized requirements. It claims to produce reviewable, deterministic outputs including RBAC configs, endpoint maps, and auditable evidence — all within a privacy-preserving workflow.

What changed

The project was extended during the OpenAI 2026 hackathon to include a no-rebuild GitHub Pages preview, synthetic data boundaries, strict validation gates, and a documented human-review process. It is presented as a pre-existing tool that was meaningfully updated for submission.

Single most important open question

Is there any evidence of real-world usage or adoption beyond the hackathon context? The description states no revenue, customers, or traction data are available — only self-reported claims and a demonstration workflow.

Back to contents

What The Product Actually Is

The description states that ZeroKit AI Control Plane is a system that converts sanitized SaaS requirements into validated control-plane configurations. It generates artifacts such as:

  • Enabled and hidden panels
  • Least-privilege RBAC (Role-Based Access Control)
  • Configurable fields
  • Endpoint mappings
  • Brand settings
  • Privacy notes
  • Test gates

These outputs are produced using Codex and GPT-5.6, with a local preflight that blocks certain inputs and ensures deterministic generation within bounded tasks.

Inference The system appears to be a developer workflow for generating SaaS control-plane artifacts in a controlled, privacy-preserving way — not a production-ready authorization engine.

Back to contents

Positioning & Claim Evolution

The description states the product aims to:

  • Reduce repeated infrastructure rebuilding by SaaS teams
  • Make administrative decisions visible before runtime
  • Avoid putting customer data into AI model loops

It positions itself as a tool for developers working on SaaS admin infrastructure, not end-users or customers.

Inference This is a developer-centric tool built for internal use in SaaS product development — likely targeting engineering teams building admin panels or control systems.

Back to contents

Target Customer & ICP

The description implies the target customer is:

  • SaaS developers or engineering teams
  • Working on administrative infrastructure (roles, permissions, routes, etc.)
  • Looking to standardize and review control-plane configurations

Not evidenced No specific customer segment, persona, or use case beyond general SaaS development.

Back to contents

Business Model & Pricing Evidence

The description does not state:

  • Any pricing model
  • Revenue streams
  • Monetization strategy
  • Customer acquisition plans

Inference There is no evidence of a business model beyond the hackathon submission. The tool is presented as a developer workflow, not a commercial product.

Back to contents

Technical & Delivery Signals

The system uses:

  • Codex + GPT-5.6 for artifact generation
  • A local preflight to block secrets and non-reserved emails
  • Deterministic validators and fail-closed response envelopes
  • GitHub Pages for previewing results without rebuilding
  • Synthetic scenarios and unit tests
  • Human review step before final manifest

Inference The tool is built with a focus on privacy, determinism, and human oversight. It avoids runtime dependencies or model API calls in the browser preview.

Back to contents

Traction & Maturity Signals

The description states:

  • The project was extended for a hackathon submission
  • It includes synthetic scenarios and validation checks
  • A fresh reviewed artifact was generated and validated
  • Timestamped commits show prior work and new additions

Not evidenced No evidence of real-world usage, customer feedback, or adoption beyond the hackathon.

Back to contents

Competitive Context

The description does not mention:

  • Competitors in the SaaS control-plane or RBAC generation space
  • Market positioning relative to existing tools
  • Any competitive advantages claimed

Inference It is unclear whether this tool competes with or complements existing developer tools for SaaS configuration or access control.

Back to contents

Key Risks & Red Flags

  • No traction or revenue evidence: The product is presented as a hackathon submission, not a commercial offering.
  • Developer-focused but no customer data: No real-world usage or feedback from users.
  • AI dependency without production safeguards: While it uses human review and deterministic validation, the core AI workflow is not production-ready.
  • Unverified claims: All claims are self-reported; no third-party verification.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual use case for this tool in a real SaaS product?
  2. Has it been tested or used by any developers outside of the hackathon?
  3. Is there a plan to move beyond the demo and into production-ready deployment?
  4. How does it integrate with existing SaaS development workflows?
  5. What are the limitations of the current AI workflow, and how are they mitigated?

Back to contents

Investment/Partnership Verdict

Not evidenced No evidence of traction, revenue, or customer adoption beyond a hackathon submission.

Confidence level Low — this is a self-reported developer tool with no verified commercial activity.

Verdict This appears to be an early-stage prototype or proof-of-concept submitted for a hackathon. It shows technical capability and design thinking but lacks evidence of real-world usage, scalability, or commercial viability. Not suitable for investment or partnership without further demonstration of traction or product-market fit.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.