DefenceSelf-submittedNot a finalist (self-declared)

CloudLookout

404 Not Found Yet · dawidwojda/404-not-found-yet

Council score

Median of 3 models, weighted by the task's official criteria
75.5 / 100

A rigorously engineered and honestly scoped defensive cloud-exposure response prototype whose detection loop and degraded-state handling are genuinely live, held back mainly by limited conceptual novelty and a remediation loop proven only in fixture mode.

Criteria · line = median, dots = each member
Idea & Innovation30%
7.0

The built product is a focused cloud posture scanner with a safety-first remediation loop, an established category where Security Hub and Prowler already compete. The pitched differentiators (CodeQL, email, correlation) are roadmap rather than code, so the evidence supports the lower read: solid and well-reasoned, with the real originality sitting in evidence handling and degraded-state design rather than a new concept.

Members disagree here: scores range by 2.0 points.
Relation to Category20%
9.0

Squarely defensive work: real public SSH, S3 and IAM detectors plus a consequence-reducing remediation path with manual approval, verification and audit. Degraded handling is explicitly implemented (failed scans retain last-known findings, permission errors surface as permission_missing, per-source health), which matches the brief's incomplete-information requirement. All three members confirm this and none of their reservations change it.

Practical Applicability / Usability20%
7.0

A live public demo with a guided operator flow, judge credentials and readable error states is real. But onboarding requires a customer-deployed Terraform connector, Cognito and IAM setup, and the deployment allowlists a single tenant, account and region, so a judge or small team cannot connect their own environment and live remediation is disabled.

Design (visual/UI)20%
7.0

A deliberate visual system is evident: semantic severity colors, keyboard navigation, reduced-motion support, and polished error and denial states. Reservations stand about crisis readability of the dense cyberpunk style, and the five described screenshots skew toward error pages, so positive-state dashboard quality rests mostly on deck and docs.

Completeness & Implementation Value10%
8.5

Exceptional for 24 hours by any of the reviews: about 15,800 lines of TypeScript, 133 tests including Terraform tests, three infrastructure roots, and a deployed cross-account stack validated with concrete finding IDs. The measured facts support the higher scores here over member C's lower one; the only real gap is that live remediation was never executed against real AWS, so the flagship closed loop is proven live only through detection.

Members disagree here: scores range by 2.0 points.
Source lines15,800
Tests133 cases
Claims built9.0 / 10
Task fitYes

Strengths

  • Real, verified cross-account AWS integration: STS AssumeRole with ExternalId, identity re-verification, paginated discovery, and a live public demo with retained SSH, S3 and IAM findings from a documented two-account validation.
  • Degraded-scenario engineering in the code: failed or partial scans retain last-known findings, permission errors show as permission_missing, historical observations never fake RESOLVED, and denied reads were actually tested.
  • Unusually deep remediation safety logic: read-only discovery role, separate approved roles, resource allowlists, expiring proposals, idempotent leases, and independent verification before marking anything resolved.
  • Strong engineering breadth and honest claim hygiene for a 24-hour build: 133 automated tests, Terraform as code, live remediation disabled by default, and the fixture demo clearly labeled as such.

Weaknesses

  • Live remediation was never executed against real AWS, so the detect-to-verified-fix loop is demonstrated only in the labeled fixture mode.
  • Limited conceptual novelty: the category is established and the pitched differentiators (CodeQL, email scanning, correlation) are planned, with documentation describing a broader product than the code delivers.
  • Onboarding is heavy for the stated small-team user: Terraform connector, Cognito and IAM setup, and a single tenant, account and region allowlist that binds the public demo to one member's account.
  • Described screenshots skew toward error and denial states, leaving positive-state dashboard quality and the crisis readability of the dense cyberpunk style under-evidenced.
Built during the event: partly: 1 commit before the event; 39 commits by 1 author, 2026-10-03 07:29 to 2026-10-04 08:10 UTC
Live demo: https://ddi5yfgblvh7i.cloudfront.net (HTTP 200)
Council v9
Aclaude:glm-5.3-flash74.090% agree
Bdots-studio/dots-3-note-preview:free83.580% agree
Cinclusionai/ling-3.0-flash-sante:free70.070% agree
Jclaude:glm-5.3–judge
Self-submitted and unverified: the result shown is the team's own claim. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub