ImpactHerHackYeah 2026 finalist

Sejf

Mikformatycy · Mikformatycy/sejf-place

Council score

Median of 3 models, weighted by the task's official criteria
82.8 / 100

An unusually deep, legally grounded and honestly scoped evidence vault for women facing domestic and economic abuse, with real tested cryptography, held back by a missed deck, thin visual and runtime proof, and an unhardened AI-key flow.

Criteria · line = median, dots = each member
Idea & Innovation30%
8.3

A decoy cover app with an action key, append-only SHA-256 chain, RFC 3161 timestamps and a browser verifier goes well beyond a common hidden-photo vault and is anchored in a documented threat model and source-verified legal research. The covert-vault concept itself is not new, which keeps it just below the top.

Relation to Category20%
9.2

The women-specific need is explicit in function, not branding: entry categories taken from the Niebieska Karta NK-A form, economic-violence amounts, verified help lines and law hints tied to UPPD art. 2. Stripping the branding leaves nothing generic.

Practical Applicability / Usability20%
7.5

The safety thinking is strong for the affected group: quick exit and shake, auto-lock, FLAG_SECURE, encrypted drafts, no telemetry, and an impact plan whose metrics are already computed in code. It loses points for the incomplete submission pack, an icon disguise that needs a native build and carries store-policy risk, and the lack of a pilot partner.

Design (visual/UI)20%
8.0

The code shows a disciplined, accessible, safety-conscious design system: icon-only entry rows, color-coded violence types, light and dark themes, screen-reader labels. But only 1 of 224 screenshots was described and no deck was given, so the polished look one member inferred from the screenshot count is not actually verifiable; the evidence supports the thinner-visual-proof view.

Completeness & Implementation Value10%
8.5

The whole loop exists as real, tested code rather than mocks: AES-256-GCM vault, hand-written RFC 3161 client against FreeTSA, CMS-signed verifiable ZIP, PDF report and 89 test cases. The heavy implementation evidence supports the higher scores over the lowest one, but the promised deck was not delivered, no runtime demo check was performed, and the AI proxy, qualified TSA and sound-button covers remain next steps.

Members disagree here: scores range by 2.0 points.
Source lines11,487
Tests89 cases
Claims built8.5 / 10
Task fitYes

Strengths

  • Source-verified Polish legal research (UPPD, Niebieska Karta NK-A, verified help lines) is baked into product function, with honest statements of what a timestamp does and does not prove.
  • A real cryptographic integrity pipeline, not mocked: AES-256-GCM, append-only hash chain, RFC 3161 client, CMS verification and a browser verifier that works without the app.
  • Threat-model-driven safety UX: cover app with action key, quick exit, shake and auto-lock, FLAG_SECURE, no telemetry, and a documented residual-risk table that states the stalkerware limitation plainly.
  • 89 test cases across crypto, chain, timestamps, reports, legal rules and the verifier, plus a measurable impact plan with metrics already computed in code.

Weaknesses

  • Submission deliverables incomplete: no presentation deck was provided and the presentation form fields are empty, a missed official requirement that the team's own handover doc still lists as open.
  • Evidence of the running product is thin: only 1 of 224 screenshots was described and no live demo check was performed, so design and behavior rest on code and tests alone.
  • The Gemini API key ships inside the app build while the server proxy meant to hide it is only an unwired sketch, and launcher-icon switching needs a native build with acknowledged store-policy risk.
  • Impact measurement depends on a pilot partner that is not yet secured, and advertised features such as qualified TSA timestamps and sound-button covers remain next steps.

Red flags

  • A live Gemini API key is embedded in the demo build and demo mode disables screenshot blocking; both are disclosed but must be reverted before any real use.
  • On iOS the cover always shows the system name Pocket plus a dialog on icon change, which could reveal the app to an abuser.
  • A single committer made all 11 commits within the event window with disclosed heavy AI-tool use; the disclosure keeps it compliant, but the team's independent mastery of the code is unverified.
Built during the event: yes: 11 commits by 1 author, 2026-10-03 18:21 to 2026-10-04 06:33 UTC
Live demo: none found in the form or README
Council v8
Aclaude:glm-5.3-flash81.8100% agree
Bdots-studio/dots-3-note-preview:free87.090% agree
Cinclusionai/ling-3.0-flash-sante:free79.070% agree
Jclaude:glm-5.3–judge
A HackYeah 2026 finalist, queued automatically for a council review; the council wasn't told how it placed. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub