Inspiration

In many small businesses, "the IT team" is one person, or the owner. Nobody watches dashboards all day, so they find out about a problem the worst way: when an angry customer calls. The Zikit challenge, "Before the phone rings," put a name to it: detect real incidents before they hit, without crying wolf, because if you alert on everything, nobody believes you.

What it does

DinoAlert is an early-warning system for small businesses. It ingests per-minute telemetry (CPU, RAM, disk, latency, errors) and server, firewall and app logs, learns what "normal" looks like for each company, and raises an alert, with a confidence level, evidence and a suggested next step, before the incident reaches customers.

It also tells real problems apart from things that only look bad, like nightly backups, payroll runs and bulk loads. Those are explained, not alerted.

Everything is shown in a 3D monitoring scene where each component has a visible state. A pink T-Rex mascot announces new alerts out loud, and a built-in assistant explains what is happening in plain language for non-technical users.

How we built it

  • Frontend: React 18 and Three.js, with a hand-built 3D scene and custom SVG charts. Seven views: monitoring, alerts, infrastructure, diagnosis, history, data and settings. Fully keyboard-accessible, with a 2D fallback when WebGL is not available.
  • Backend: a FastAPI API for ingestion, metrics, alerts and tenants, plus a separate worker that runs the detector minute by minute, using only data up to minute t, never the future.
  • Tiger Data: TimescaleDB on Tiger Cloud stores metrics, logs and alerts. Because it is standard PostgreSQL, data can arrive as a ZIP upload, through the API, or with plain SQL INSERTs. Uploads are isolated per company.
  • Vultr: production runs on a Vultr VM with Docker Compose, with nginx serving the app and proxying /api. The same compose file runs locally with its own database.
  • Gemini: powers a chatbot inside the dashboard that helps non-technical users understand their alerts and what they can do in the panel, in plain language.
  • Solana: certifies every action taken by the AI or by a user. Each action and its log is signed with an authorized key and recorded, so the server rejects commands without a valid signature, an intruder without the key cannot act, and every action leaves a verifiable trail for audits.
  • ElevenLabs: the mascot's phrases are generated in four voices (Tía Paola, Flor, David and Diego) and played when alerts appear or change severity.

Challenges we ran into

  • No peeking into the future. Every alert at minute t can only use data up to t, so the detector had to be fully incremental. We test it by running with data up to t and up to t+k and requiring identical alerts.
  • Decoys. Backups and payroll runs look exactly like incidents. We use each company's business context and repeating patterns to tell them apart.
  • Dirty data. Empty cells and telemetry blackouts are treated as missing, never as zero.
  • Trusting automated actions. If an AI can act on a server, someone must be able to prove who authorized each action. That is why we added cryptographic signatures with Solana.
  • Measuring honestly. Our first evaluation was too generous and counted alerts from other incidents as hits. We rebuilt it to be stricter.

Accomplishments that we're proud of

On a test dataset we built with four companies the system had never seen (a dental clinic, a hardware store, a school and a logistics company), DinoAlert warned about 12 of 12 incidents before impact, with a median lead time of about 4 hours and one false alarm. And it is real software in production, not a mockup: anyone can open it and test it with their own data.

What we learned

Time-series data, decoy handling and honest evaluation matter as much as the detection itself. An alert system is only useful if people trust it, and actions are only safe if you can prove who authorized them.

What's next for DinoAlert

More lead time on slow incidents (for example, estimating how many hours until a disk fills up), a single alert per incident that escalates instead of repeating, and real-time notifications when a high-risk alert appears.

Built With

  • backboard
  • elevenlabs
  • gemini
  • solana
  • tiger-data
  • vultr
Share this project:

Updates

Submission history