HubMI.plHackYeah 2026 finalist

Małopolski Hub Innowacji Społecznych

DropTheBase; · Drop-the-Base/malopolski-hub-2026

Council score

Median of 3 models, weighted by the task's official criteria
68.0 / 100

A genuinely built and well-tested seven-module prototype with real matchmaking and standout accessibility work, held back by missing video and PDF deliverables, no verifiable live demo, and a mid-event defect record whose fixes rest on the team's own word.

Criteria · line = median, dots = each member
Challenge fulfilment40%
7.5

All seven modules plus extras exist as real routes, views and tests, and matchmaking is a genuine TF-IDF pipeline with a relevance threshold, no-match state, PII masking and per-match justifications. The median reflects that the team's own QA caught matchmaking returning HTTP 500 with weak scoring mid-event, and the fixes are self-documented with no verifiable live demo, which supports A over both B's confidence and C's dismissal of the committed tests.

Members disagree here: scores range by 4.5 points.
Implementation potential20%
7.0

The deployment story is real: JWT admin auth, 14 ORM models, Docker Compose with seed data, an open-data REST/CSV API and a costed plan of roughly 170-200 PLN per month. It is capped by SQLite-only storage with a hand-rolled migration shim, one shared admin password with no roles or SSO, and a PII scrubber that still misses names and street addresses.

Members disagree here: scores range by 2.5 points.
Accessibility & intuitiveness20%
7.0

Systematic WCAG 2.1 AA work is visible in code: two high-contrast modes, text scaling, ETR simple language, focus-trapped dialogs, ARIA tabs, per-page titles and a skip link. The first build failed basics per the team's own QA, the fixes were never confirmed by any audit or demo check, and residual issues remain, such as meaning conveyed by color alone on the map and a powiat dropdown listing only 12 of 22.

Members disagree here: scores range by 3.0 points.
Bonus (UI, materials, MVP quality)20%
5.0

MVP quality is high, with 51 test cases, a thoughtful design system and a disciplined QA-then-fix cycle, but the pack contains zero screenshots and no standalone mockups. The required three-minute video and PDF deck were not submitted in required form, only in-repo markdown and HTML, which the measured facts support; B's view that a markdown pitch is acceptable is contradicted by the deck being recorded as not provided.

Members disagree here: scores range by 3.5 points.
Source lines23,504
Tests51 cases
Claims built8.0 / 10
Task fitYes

Strengths

  • All seven modules plus extras are implemented on both backend and frontend, backed by 51 test cases in 17 files, a smoke test and seed data rather than mocks.
  • Matchmaking is a real pipeline: need detection, TF-IDF ranking with a threshold and no-match fallback, PII masking before the LLM, and per-match justifications covered by tests.
  • Accessibility engineering is unusually thorough in code, from high-contrast themes and text scaling to ETR mode, focus-trapped dialogs, ARIA patterns and a skip link.
  • Honest and deployable engineering process: the team committed its own critical QA report and answered it with documented fixes and regression tests, plus Docker Compose, an open-data API with CSV export and a costed infrastructure plan.

Weaknesses

  • Neither required deliverable was submitted in required form: no three-minute video and no PDF deck of at most 10 slides, only in-repo markdown and HTML, and no live demo link was verified.
  • The team's own QA report shows the mandatory matchmaking returning HTTP 500 with weak scoring, a hardcoded admin queue and exposed personal data, and all subsequent fixes are self-reported without independent verification.
  • Production gaps: SQLite only with a hand-written migration shim, a single shared admin password with no roles or SSO, and a PII scrubber that misses names and street addresses.
  • Materials and polish gaps: zero screenshots, no standalone UX mockups, a powiat dropdown covering 12 of 22 powiaty, and a nearly empty submission form whose solution summary is in English for a Polish-language task.

Red flags

  • The committed QA report shows a critical mid-event state (matchmaking down, Rick Roll videos in the innovations feed, hardcoded admin queue, unauthenticated personal data) that the jury can only take on the team's word as fixed.
  • Inflated claims persisted: a '98% AI matchmaking' figure flagged in QA crept back into the UI, and a '100% modules done' claim sat alongside a broken mandatory module.
  • DEMO_MODE, on by default, pre-fills the author's identity and auto-ticks the RODO consent checkbox, undercutting the platform's own data-protection demonstration.
Built during the event: yes: 68 commits by 1 author, 2026-10-03 11:18 to 2026-10-04 06:14 UTC
Live demo: none found in the form or README
Council v9
Aclaude:glm-5.3-flash68.0100% agree
Bdots-studio/dots-3-note-preview:free78.070% agree
Cinclusionai/ling-3.0-flash-sante:free42.050% agree
Jclaude:glm-5.3–judge
A HackYeah 2026 finalist, queued automatically for a council review; the council wasn't told how it placed. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub