Product Thumbnail

Astartis x Codex

Enterprise developer security control plane around evidence

User Experience
Developer Tools
Artificial Intelligence
GitHub
Visit WebsiteSee on Product HuntGithubVercel

Hunted bykgosi blandakgosi blanda

Astartis x Codex - evidence-led developer security control plane.

Top comment

I'm inspired by enterprise-grade software. Working part-time in IT internships while at university, I've seen how efficient and fault-tolerant enterprise networking and cybersecurity systems can be. But these systems are only affordable for large enterprises and government ministries in Botswana — small companies and solo developers can't afford things like Essl access-level door lock systems or Dell's write-once-read-many (WORM) server architecture, which gives absolute immutability. So I built a hyper-scalable system and used Codex/GPT-5.6 to debug its C++-heavy errors. It can run on a server or your own laptop by changing configs via my GitHub repo — making it cheap and reliable for regions like Botswana, where cloud hosting is expensive and infrastructure can be unreliable.

Comment highlights

please give shoutouts , to anyone interested about cyber in your communities

For any more inquires, look at this first and realize that if an attacker still manages to get is to your system, our latest updates can impose absolute immutability for backup repositories. But breaches are still rare though with a zero-trust network

Astartis’ defense is layered around reducing and detecting that failure mode, not pretending it is impossible:

  1. Endpoint evidence is treated as a claim, not final truth
    A signed record from an offline device proves “this key produced this record at this time,” not “the world definitely looked this way.” In Astartis, that evidence should be scored against independent signals: NAC posture, network-zone context, policy state, agent health, decoy activity, audit-chain continuity, and server-side records where available.

  2. Keys should be scoped, rotatable, and revocable
    A laptop-held key should not be a permanent root of trust. It should be device-scoped, short-lived where possible, bound to posture, and revocable once the endpoint shows drift, missed check-ins, suspicious attribution, or failed proof-mode checks. If a stale offline key signs evidence after a risk threshold, that evidence can remain cryptographically valid but operationally downgraded.

  3. Offline capture needs freshness constraints
    The system should enforce capture windows, counters, monotonic sequence numbers, key epochs, and “last trusted contact” metadata. If a device was disconnected too long, its signatures are not accepted at full trust. They become quarantine evidence: useful for investigation, not enough to authorize access or clear an incident.

  4. Use cross-corroboration
    Bad evidence from one compromised endpoint should have to agree with things it cannot easily forge: switch/NAC observations, DHCP or identity logs, firewall decisions, WORM audit sequence, decoy triggers, peer network telemetry, and known policy snapshots. Astartis’ strongest argument is that Codex can explain these contradictions instead of just showing a green checkmark.

  5. Separate signing from high-trust authority
    The endpoint can sign what it observed, but it should not be able to grant itself trust. Admission, Zero Trust access, WORM unlocks, quarantine release, and recovery decisions should be made by the control plane using multiple signals.

the hash-at-capture-time model is solid against tampering after the fact, but it only proves the evidence wasn't altered post-signing - not that it was honest to begin with. if the offline device itself is compromised before capture, or the signing key gets pulled off a laptop that was sitting disconnected for a while, you'd get a validly signed, internally consistent record of something that was fake from the start. what's the actual defense against a compromised endpoint signing bad evidence with a legitimate key, as opposed to catching tampering after the signature's already been applied?

Congrats on shipping this. The local-first, disconnected-environment angle is the right call, most enterprise security tooling assumes constant connectivity and a budget most small teams don't have. Genuine question: how does evidence stay trustworthy once a device has been offline for a while and comes back online, do you reconcile state automatically or flag it for a human to review first?

About Astartis x Codex on Product Hunt

Enterprise developer security control plane around evidence

Astartis x Codex launched on Product Hunt on July 23rd, 2026 and earned 69 upvotes and 14 comments, placing #47 on the daily leaderboard. Astartis x Codex - evidence-led developer security control plane.

Astartis x Codex was featured in User Experience (367k followers), Developer Tools (516.3k followers), Artificial Intelligence (474.4k followers) and GitHub (41.3k followers) on Product Hunt. Together, these topics include over 243.8k products, making this a competitive space to launch in.

Who hunted Astartis x Codex?

Astartis x Codex was hunted by kgosi blanda. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.

Want to see how Astartis x Codex stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.