Community engineering / PLANNED

AeglysAI Community Hackathons

Build. Break. Measure. Improve.

A community engineering program for exploring adaptive authorization, behavioral risk, cloud-native security and resilient distributed systems using the open-source AeglysAI research platform.

Participant registration is not open yet. The official registration form will be linked here when available.

Explore AeglysAI on GitHub ↗
Three challenges / one research direction

The planned event timeline

Participation is FREE. Planned USD $300 prize per hackathon. Prizes and rules are subject to official event terms until finalized. No prize has been awarded. Exact dates and time zones are pending.

01PLANNED

AeglysAI Adaptive Authorization Challenge

Launch: November 2026
Submission: January 2027

  • RBAC
  • ABAC
  • Contextual risk
  • Adaptive authorization
  • Policy explainability
Explore the challenge →
02PLANNED

AeglysAI Behavioral Risk Challenge

Launch: December 2026
Submission: February 2027

  • Behavioral anomaly detection
  • Risk evidence
  • Identity/context signals
  • Explainability
  • False-positive reduction
Explore the challenge →
03PLANNED

AeglysAI Autonomous Resilience Challenge

Launch: January 2027
Submission: March 2027

  • Incident detection
  • Policy-bounded response
  • Resilience
  • Observability
  • Distributed-system security
Explore the challenge →

For people who build and investigate

Platform engineers, SREs, cloud engineers, security engineers and distributed systems engineers can investigate operational security problems with reproducible tests. Researchers and engineers from other disciplines are welcome.

  • Platform Engineers
  • Cloud Engineers
  • Security Engineers
  • Distributed Systems Engineers
  • SREs
  • Software Engineers
  • AI/ML Engineers
  • Researchers
  • Graduate Students

Practical problems to investigate

Authorization and identity

Test how roles, attributes and identity context affect policy decisions across service boundaries. Explain who can do what and why.

Risk and observability

Explore which signals support a risk decision, how to trace its evidence and how to distinguish anomalies from legitimate operational changes.

Resilience and incident response

Use isolated failure scenarios to evaluate detection, recovery and policy-bounded response. Document safeguards and effects on distributed services.

How participation works

  1. Register for a hackathon

    Use the official form once available. Review finalized eligibility and event terms before entering.

  2. Choose a challenge

    Explore the repository, define a scoped problem and work in an isolated test environment.

  3. Build and measure

    Document assumptions, create reproducible tests and explain both successes and limitations.

  4. Submit and share

    Share code, evidence and documentation through the official submission channel when announced.

Evidence before spectacle

Proposed judging rewards sound engineering and honest security reasoning. A clear negative result can be valuable when it is reproducible. The proposed scoring weights below total 100%. Independent review, eligibility checks, conflict disclosure and tie handling must be finalized in official terms before launch.

  • Technical Correctness — 25%
  • Security & Threat Reasoning — 20%
  • Architecture & Engineering — 20%
  • Reproducibility — 15%
  • Innovation — 10%
  • Documentation & Explainability — 10%
Read deliverables and proposed rules →

Code of Conduct

Program conduct expectations: treat others respectfully, welcome different backgrounds and experience levels, give constructive feedback, and credit collaborators and prior work. Harassment, discrimination and intimidation are unacceptable.

Test only systems and data you are authorized to use. Keep credentials and personal information out of submissions. Report vulnerabilities privately to the affected maintainer rather than exposing sensitive details publicly.

A reporting contact and enforcement procedure will be published with official event terms before registration opens. Do not post conduct reports or sensitive vulnerability details in public submissions.