Inspiration

Every quarter I get a notification about a new data leak, my information exposed somewhere I never agreed to share it. With a background in cybersecurity, I know the attack surface is only getting larger and the rise of AI tools like Eleven labs make impersonation far easier than ever. Each day, it becomes more and more plausible that someone could combine AI voice and face cloning with a stolen personal history to build a convincing digital impersonation of you, capable of identity theft with far greater reach than a stolen password alone.

Companies I've never done business with hold far more information on the average person than most people realize, and most of the time we never gave those companies our information in the first place. And even when you know your data is out there with a data broker, actually tracking down every broker and sending an opt-out request is slow, manual, and easy to give up on.

What it does

Aegis Sentinel runs the reconnaissance a scammer would run on you, on yourself, so you can close the holes first.

It queries Have I Been Pwned for every breach an email address appears in and the categories of data each one leaked, and runs a live data-broker and web-exposure search via SerpApi to find where else that identity shows up publicly. It then reasons about the combination of what's exposed rather than counting leaks in isolation, producing an Exposure Score and a set of realistic attack chains that show how individually minor exposures compound into serious risk. For the highest-priority exposures found, it drafts ready-to-send opt-out requests and remediation checklists. A human reviews and approves every draft; Aegis never submits anything on its own.

How we built it

The agent runs on Cloud Run, reasoning through Gemini on Vertex AI with service-account authentication, no API key in code. Recon is genuinely live: Have I Been Pwned for breach data, SerpApi for broker and web exposure. Scan history persists in Firestore, and a Cloud Scheduler job fires the agent autonomously on a recurring cron, no human needs to trigger it. Secrets live in Secret Manager, mounted at deploy time rather than stored in code or environment files.

The frontend went through two builds: an initial pass in Google AI Studio, and a visual revamp using Claude Design, before landing on a hand-refined single-file dashboard hosted on Firebase Hosting. GitHub holds the source, and Cursor was the primary code editor for the backend.

Challenges we ran into

Vertex AI quota exhaustion. Our recon layer got too good at its job: a single scan could surface 20-30+ broker and web-exposure hits, and drafting a removal request for each meant 20-30+ back-to-back Gemini calls. That volume alone was enough to trip Vertex AI's free-tier per-minute quota mid-scan, returning 429 RESOURCE_EXHAUSTED errors. The fix was architectural, not a retry loop: we capped each scan to drafting the highest-priority exposures (ranked by real-world risk reduction) instead of every exposure found, while keeping the scoring and attack-chain reasoning running over the full, uncapped inventory. Recon stays exhaustive; drafting stays sustainable.

Silent field-name drift breaking the UI. At one point strikes and attack chains stopped rendering in the dashboard, not with an error, just blank. The root cause turned out to be a real architecture gap: our reasoning prompts described a strict JSON schema in plain English but never actually attached one to the Gemini API call. Without a response_schema constraining the output shape, the model was free to invent its own field names run to run, draft_content one time, drafted_request the next. The permanent fix was writing and enforcing real JSON schemas on all three reasoning calls, which now guarantees a stable, predictable output contract instead of hoping the model's phrasing stays consistent.

Cloud Run container recycling mid-scan. With a live scan legitimately taking 130-200+ seconds, we hit cases where Cloud Run recycled the container before a long-running request finished, silently truncating the result. Fixed by explicitly setting the Cloud Run request timeout and a minimum instance count so a live scan is never competing with a cold start.

A GitHub deployment loop under time pressure. Stale remotes, an authentication token that wasn't reaching GitHub's prompt, and a repository with unrelated remote history all compounded into a genuinely painful hour of git plumbing that cost real submission time. The eventual fix, deleting and recreating the repo clean, was blunt but effective, and it's now a documented step in our own playbook for next time.

Accomplishments that we're proud of

Shipping our first autonomous AI agent and watching it actually work: live breach data in, real reasoning out, a scheduled heartbeat firing with nobody at the keyboard. Learning the Google Cloud and Vertex AI platform from a cold start to a deployed, schema-correct production agent in one sitting. And submitting our first official hackathon entry, start to finish.

What we learned

How to stand up and deploy a real autonomous agent end to end: ADK, Gemini via Vertex AI, Cloud Run, Firestore, and Cloud Scheduler working together as one system. Why response_schema isn't optional if you actually need a stable contract with an LLM's output, describing a shape in the prompt is not the same as enforcing it. How to reason about and defend against API rate limits at the architecture level instead of just retrying harder. And a fast, hands-on education in building better frontends with Claude Design.

What's next for Aegis Sentinel

First, moving this out of demo mode & hardening it so it can go live to the public without my API keys being burned. Also. a few quality of life changes like making the "scanning" feature more prominent and when the scan is done, having a "scan completed" pop up. Then, I'll be building the infrastructure to start fielding real users: broadening recon coverage beyond the current broker set, wiring the paste and public-code exposure checks that are currently stubbed, and hardening the approval and submission flow so new users can safely run this on their own identity.

Share this project:

Updates

Submission history