Inspiration
SecEff was inspired by the challenge of managing cloud platforms in construction. These systems support safety AI, BIM processing, IoT monitoring, analytics, and site operations, but cloud teams often have to look at security, cost, and carbon impact separately. We wanted to create one place where teams could understand whether a cloud resource is risky, wasteful, carbon-heavy, or ready for action.
What it does
SecEff analyzes a mock construction cloud estate and turns raw scan data into four connected outputs:
- Cloud Security: detects public access, risky open ports, missing encryption, identity issues, and attack paths.
- Resource Efficiency: finds idle, orphaned, underused, and over-provisioned resources.
- Carbon Footprint: estimates emissions based on energy use and regional carbon intensity.
- AI Recommendation: suggests next actions to reduce risk, cost, and emissions.
For carbon impact, SecEff uses:
$$ \text{carbon kgCO2} = \frac{\text{kWh per month} \times \text{regional carbon intensity}}{1000} $$
For savings, SecEff only counts cost reduction when a resource is actually wasteful:
$$ \text{saved cost} = \begin{cases} 1.0 \times \text{monthly cost}, & \text{idle or orphaned resources} \ 0.6 \times \text{monthly cost}, & \text{over-provisioned resources} \ 0, & \text{security-only or healthy resources} \end{cases} $$
How we built it
We built SecEff with a static HTML, CSS, and JavaScript frontend to keep the demo lightweight and easy to run. The backend is a Node.js Express server that serves the frontend and exposes API endpoints for the dashboard.
The backend reads a mock cloud dataset from JSON, then runs several analysis layers:
- a security analyzer for findings and graph data
- a resource efficiency engine for waste detection
- a carbon calculation engine using regional carbon intensity
- an AI recommendation flow for practical next steps
Feature 4 uses a Python worker called by the Node.js backend. If an API key is available, SecEff calls an AI model for recommendations. If no key is available, it falls back to a local rule-based recommendation engine.
Challenges we ran into
One challenge was making all four features feel connected instead of separate. Security, cost, carbon, and recommendations all had to come from the same dataset so the dashboard could tell one clear story.
Another challenge was balancing design and functionality. We wanted the interface to feel polished and technical, but still readable and easy to demo. We also had to make sure the backend could serve both static frontend pages and API responses from one place.
A third challenge was calculating savings realistically. Fixing a security issue does not always save money, so we separated security remediation from cost optimization.
Accomplishments that we're proud of
We are proud that SecEff combines cloud security, resource efficiency, carbon intelligence, and AI recommendations into one workflow. The project does not just show alerts; it explains what matters, why it matters, and what action should come next.
We are also proud of the visual security graph, the dashboard-style frontend, and the fallback recommendation system that still works even without an external AI API key.
What we learned
We learned that cloud governance is not only about finding problems. It is about connecting technical signals to business impact. A public database, an idle GPU, or a carbon-heavy workload all require different actions, and the platform needs to explain those differences clearly.
We also learned how to connect a static frontend, Node.js backend, Python analysis worker, and AI recommendation logic into one working demo.
What's next for SecEff
Next, SecEff could connect to real cloud providers such as AWS, Azure, or Google Cloud instead of using mock data. We would also like to add user authentication, historical trend tracking, automated remediation workflows, and more advanced AI recommendations.
In the future, SecEff could become a full cloud governance layer for construction companies, helping teams build safer, leaner, and more sustainable cloud operations.
Log in or sign up for Devpost to join the conversation.