Open-source hackathon judging

Judging you don't
have to trust.

Scores go into a hash-linked, cryptographically signed chain. Anyone can replay it offline and prove the leaderboard was never quietly edited.

chain verified 126 ballots 0 breaks head a1f3…9c2b
The problem

Trust is not
a feature.

Most judging tools ask you to believe the final table. Edit a score in the database after the fact and nothing looks different. The winner changes; the evidence doesn't.

edit rejected · hash mismatch at block #0007
The chain

Every write points
back at the last one.

Each ballot becomes a block whose hash folds in the block before it. Change any score and every hash downstream breaks — the tampering has nowhere to hide.

append-only CHECK 1..5 in the DB versioned ballots
The seal

Signed, so it can't
quietly move.

At each checkpoint the chain's head is signed with an Ed25519 key. The signature travels with the results, so a verifier can confirm the head is authentic — not just internally consistent.

Ed25519 checkpoints domain-tagged offline verifiable
Fairness

Fair is reproducible,
not asserted.

Raw scores are normalized with a signed, deterministic run (ridge-additive-v1). Re-run it from the pinned inputs and you get the same result hash — down to a gauge error under 1e-6.

ridge-additive-v1 gauge < 1e-6 126 ballots pinned
Verify it yourself

You don't need our
server. Or our word.

Export the results bundle and check it on your own machine. The verifier re-runs the normalization from pinned inputs, re-computes the chain, and checks the signature.

$ python -m normalize.verify results.bundle → loading bundle …………………… 126 ballots, 40 submissions → recompute chain ……………… head a1f3…9c2b → verify Ed25519 checkpoint … signature OK → replay normalization ……… gauge 2.89e-17 → compare result hash ……… match RESULT: VERIFIED ✓
Self-host

One file.
One command. Your box.

No SaaS, no lock-in, no phone-home. It ships as a single Docker Compose stack — Django 5.2 and PostgreSQL 16 — that boots into a working, seeded instance.

$ git clone github.com/pal-123456789/dogfood-portal $ cd dogfood-portal $ docker compose up --build → web …………… healthy → db …………… healthy → seeded 40 submissions · 126 ballots · chain intact → open http://localhost:8000
What's actually inside

Shipped, not slideware.

Tamper-evident audit log
Immutable, hash-chained events with an atomic co-commit of every business write.
Ed25519 checkpoints
Signed chain heads plus a standalone offline verifier — no server required.
Append-only ballots
Versioned score history with a database CHECK 1..5 on every value.
Reproducible normalization
A signed run pins inputs so the result hash is byte-stable on replay.
Event-scoped roles
Judge and organizer access is enforced in the service layer, per event.
Organizer & judge UI
Stand up an event, add teams and tracks, and score assigned submissions in-app.
Hardened export
CSV-injection guard and no-store cache headers on judge and export views.
Operable by design
Docker Compose boot, seeded demo data, and a host-side replay harness.
Get started

Clone it. Run it.
Verify it.

Everything on this page maps to code in the repo. Nothing here is a mock.