Artificial IntelligenceSelf-submittedNot a finalist (self-declared)

Tessera

TSP · TegesSzmegesProxy/TesseraScore

Council score

Median of 3 models, weighted by the task's official criteria
64.5 / 100

An exceptionally engineered AI-native security proxy with a best-in-class human-control story, held back by a post-deadline single-commit push and an AI path that is simulated rather than shown running.

Criteria · line = median, dots = each member
Idea & Innovation30%
6.5

The deterministic-first design with sampled AI calls, EWMA-adaptive thresholds, a coverage gate and a rule that an error is never reported as SAFE goes well beyond a prompt wrapper. Commercial AI-informed WAFs already exist, which keeps a strong idea above average rather than exceptional, and Member A's 8 is generous against that prior art.

Members disagree here: scores range by 2.0 points.
Relation to Category20%
7.0

AI fills the exact gap the product claims, and removing the model calls leaves only a generic signature proxy. The runtime evidence is thin though, since no logs or artifacts show the model path executing and the demo simulates it, which supports the median between A's 8 and C's 5; missing committed API keys are not themselves evidence, as keys are never committed.

Members disagree here: scores range by 3.0 points.
Practical Applicability / Usability20%
6.0

The target user and use case are concrete, and control is well designed with separate approval and activation, editable policy and budget ceilings. Real deployment spans Redis, Ed25519 keys, a GitHub App and Auth0, and the path visible to the jury is a simulation.

Design (visual/UI)20%
7.0

The landing page and docs are polished, with a real component library and professional tooling visible in the code. The only screenshots actually described are static pixel-art hero images rather than real UI captures, so the rendered dashboard is unverifiable, which caps the score below B's 7.5.

Members disagree here: scores range by 2.5 points.
Completeness & Implementation Value10%
5.0

Roughly 58,700 LOC, 116 test cases and a working-looking Fastify ingress path with normalizer, runner and orchestrator exceed typical hackathon scope. Against that, the event-dated plan admits the proxy-dashboard wiring was still a plan on local mocks, the backend has no automated tests by its own docs, and the demo is scripted.

Members disagree here: scores range by 2.0 points.
Source lines58,715
Tests116 cases
Claims built5.0 / 10
Task fitYes

Strengths

  • Deterministic-first architecture that samples AI calls with explicit bounds, adapts thresholds via EWMA, and never reports an error as SAFE.
  • Control and verification built into the lifecycle: separate approval and activation, an AI read manifest, redaction and budget ceilings, with JEV context treated as data rather than instructions.
  • Unusually broad real implementation: proxy ingress and policy verification, a sandboxed repo host with tree-sitter and guarded analysis tools, a NestJS control plane, docs, landing and CLI.
  • Honest limitation statements in the docs, and a polished landing page with an interactive trace-a-request walkthrough.

Weaknesses

  • The AI path is never demonstrated running: no logs, eval outputs or run artifacts show JEV classification or AI policy generation on real inputs, and the hosted demo is a client-side simulation with hard-coded attack probabilities.
  • The event-dated integration plan states the proxy-dashboard wiring, bundle pulling, runtime config and JEV credentials were still planned or on local mocks, and the backend has no automated tests by its own documentation.
  • The submission form contains no explicit disclosure of AI tool use, even though an AGENTS.md agent guide in the dashboard points to AI-assisted development.
  • Deployment complexity is high for the stated target user of teams without security staff, and the repo ships with no root README and a placeholder description.

Red flags

  • The entire repository was pushed as one squashed commit on 5 October, after the 4 October deadline, with zero during-event commits.
  • The deck advertises a live demo, but the demo is a scripted JavaScript simulation of the AI path rather than a running system.
  • A real-looking dashboard login with an email and password was pasted in plain text into the submission form, undermining the security narrative.
Built during the event: unclear: 1 commits by 1 author, 2026-10-05 19:41 to 2026-10-05 19:41 UTC, so the history is squashed
Live demo: https://nodejs.org (HTTP 307); https://tessera.akowalcze.uk/ (HTTP 200)
Council v9
Aclaude:glm-5.3-flash74.080% agree
Bdots-studio/dots-3-note-preview:free65.590% agree
Cinclusionai/ling-3.0-flash-sante:free54.060% agree
Jclaude:glm-5.3–judge
Self-submitted and unverified: the result shown is the team's own claim. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub