TY for your response. People like you make me miss the old HN. I (antidotally) feel that now its much more common to just down vote and feel self-righteous as opposed to actually taking the time to craft an articulate response. The reason I feel its more than the readers is because "dang" and the other hall monitors do their best to enforce this also. Its no longer the "hacker mentality" its post what helps the YC portfolio and no matter the merit we are OK with it. Honestly its not so hard to see why they fell in so hard with Trump given their true nature e.g: Zuck being the #1 funder of things that will essentially kill the open internet. I'm starting to think it was all fake, just a bunch of Trump-esq BS even before Trump.
This comment will be flagged soon and disappear just like anything else that does not support their "Trumpish" view of what the world should be.
I fully agree; but we also MUST STOP PRETENDING like HN and YC are good faith actors here. They are not. They blatantly curate (by flagging) comments and do everything possible to help both companies do this. Its not just OpenAI/Anthropic, there is a toxic ecosystem here supporting itself and doing everything possible to subvert the will of the people. There is 0 interest in merit and absolute focus on regulatory capture here and all YC investors and staff are fully complicit.
I'm old enough to remember when "Google" was something that ended conversations. People — myself included — would literally say "Google it," the facts would be located, and that was that. Now that Google wants to be the conversation, I'm worried there will no longer be a bias-free source of information for the masses.
This is all new, so I may be a bit hyperbolic, but the reason OpenAI introducing ads bothers me is the implicit (or even explicit) bias that can be smuggled into a chat in ways that simply aren't possible when you're just clicking through to an external source. There are all kinds of implications to Google no longer being that source of truth, even by default. Maybe this has quietly been the case for a long time, but this feels like the final move — pushing their ad bias (i.e., whoever paid the most) into a conversational system, where dark patterns are far easier to implement and much harder to detect.
One answer to this might be domain-specific agents — narrower, accountable, ideally something you (or your community) actually run. But even then it all falls back on trust: you being a good-faith actor, and others trusting that you are one. Which is to say, we're back to the same problem, just at a smaller scale.
https://codify.nyc is the one I am going to be launching first, hopefully in a few weeks. I only have 100 or so cities on board and live right now. They have been very useful in understanding all the mechanics and nuance of delivering services at the city/local level.
Your project looks interesting, let me know if you see any place we could work together.
I was doing this because some portals that have been setup are setup by the end users; its a platform. But these were the ones that "I" the developer of Project20x/Codify had setup internally.
This is a really good point though, I think I should remove that.
1. Yes, I have had 3 potential clients mention this to me and initially I was a bit caught off guard. I am also concerned that it could be more and some decided to just not move forward because they believed outright that it was a "Scam".
2. I agree, I think I was a bit too worried because I do not know how to navigate this space "Gov Tech" very well.
Thankyou very much for your response; developing a product in a silo can cause tunnel vision which leads to blowing things out of proportion, your comment has really helped me to put things into perspective.
My biggest concern by far is that they seem to have put codify.inc on a registry so ISP's are blocking or showing the red "this is a scam - go back to safety" page. I really liked and invested a lot into that "branding".
TL;DR: Hawaii's SOC mislabeled my civic-tech staging subdomains as a phishing scam, then pushed it as a press release — multiple outlets ran it. I'm about to launch the city-tier version (Miami, Boston, NYC, LA, Vegas) and want HN's advice on correcting the record before then.
I'm Arion. I'm building Project20x — an AI-native governance platform (policy authoring → codification → delivery as digital public goods). It's the substrate that turns policy into running services. I'm building it across all 50 states and 40+ countries concurrently, because government actually runs on interagency dependencies, not silos — VA hands off to HUD, HHS coordinates with every state Medicaid office, etc.
The subdomain pattern at the time was {agency}.{state}.{country}.codify.inc — so the Hawaii subprojects lived at dlir.hi.usa.codify.inc, health.hi.usa.codify.inc, etc. Real staging environments. Not impersonations. No credential capture, no solicitation of money, no fake state seal.
In late 2025 the Hawaii SOC published an alert flagging those subdomains as phishing impersonating state agencies — and pushed it out as a press release. KITV ran the segment in the URL above. Several other Hawaii outlets ran their own write-ups off the same release. So "scam" is now indexed across multiple sites, not one. The same effort that went into a coordinated press push could have gone into one email to a contact page — but I hadn't published one, and they didn't ask.
Here's what I think is fair, and what I think isn't:
Fair: A citizen unfamiliar with Codify could be thrown by a .inc URL that contains an agency abbreviation as a subdomain label (dlir.hi.usa.codify.inc) — even though the apex is codify.inc not .gov, and every page header read "Codify Inc official portal for [agency name]." The on-page identification was there; the URL itself was the surprise. That's a comms-and-onboarding failure on my part, and the fix is to stop putting agency abbreviations into deep subdomain paths. The new pattern is per-city apex (codify.la, codify.nyc, codify.boston, codify.miami, codify.vegas) — clearly a Codify property at first glance, no nested abbreviations to misread. I've also published a security contact ([email protected]) and a public registry listing live vs. staging vs. claimable subprojects. The SOC didn't reach out before the alert because I hadn't published a contact. That's fixed.
Not fair: "Scam" is a factual claim and it's wrong. Every page header on the flagged subdomains read "Official Codify Inc portal" or "Official Project20x portal for [agency name]" — including the screenshots used in the "scam" example. The site never claimed to be the agency, never collected information on the agency's behalf, and never solicited money. This is a civic-tech project in the same spirit as DOGE / USDS / 18F — same DOGE-shaped goal, achieved by compilation rather than chainsaw. Building in public on the open internet has a cost I underestimated, but mislabeling civic-tech as fraud has a cost too.
Why I'm asking now: I'm launching the city-tier version — "DOGE for cities" — for Miami, Boston, NYC, LA, and Las Vegas, on per-city apex domains (codify.miami, codify.la, codify.nyc, codify.boston, codify.vegas). No more nested codify.inc subdomains. Playbook this time: clear "Codify Inc portal" header on every page, published security contact, .gov counterpart links, and CIO/CISO outreach before launch. Rather get it right than clean up again.
Codify — democratic digital public infrastructure that turns your problems into structured, executable programs.
The idea: describe any problem in plain language (voice or text), and AI codifies it into a structured program with the right people, steps, timeline, and agents to get it done. It's a 5-step wizard: Define Problem → Codify Solution → Setup Program → Execute Program → Verify Outcome.
It runs across 50+ domains — codify.healthcare (EMR backend), codify.education (LMS backend), codify.finance, codify.careers (HRM backend), codify.law, plus 13 city domains (codify.nyc, codify.miami, codify.london, codify.tokyo, etc.). Each domain tailors the AI assessment and program output to that sector.
The platform is Project20x — think of it as the infrastructure layer. If Codify is the verb ("codify your healthcare problem into a care program"), Project20x is the operating system that runs it all: multi-tenant governance, AI agent orchestration, and domain-specific sys-cores for healthcare, education, city services, etc.
Every US federal agency and state-level department has a subdomain — ed.usa.project20x.com (Dept of Education), doj.usa.project20x.com, hhs.usa.project20x.com, etc. — with AI agents representing each agency's mandate. Same structure at the state level.
The political side: Project20x hosts policy management for both parties — dnc.project20x.com and rnc.project20x.com — where legislative intent gets codified into executable governance through a 10-step policy lifecycle. Right now I'm building out the multi-agent environment so agency agents can negotiate with each other, make deals, and send policy proposals up to the HITL (human-in-the-loop) politician for approval. Each elected official has a profile (e.g. https://project20x.com/u/donald-trump) where constituents can engage and where policy proposals land for review.
The name is a nod to structured policy frameworks, but the goal is nonpartisan infrastructure: democratically governed essential services delivered as AI-native social programs.
Stack: Nuxt 2/Vue 2 frontend, Laravel 10 API, Python/LangGraph agent orchestration, Flutter mobile app. Currently live across all domains.
I think in some ways we are past it; unfortunately not the funny ways. Some examples:
1. The presidents response to bombing of school girls was basically "stop hitting yourself"
2. Fox news host Dept. of Defense head and the "Dept. of War" name "change"
3. Building a grand ballroom while taking benefits away from hungry kids
4. Elon musk on stage with the chainsaw bragging about acts that save no money but did harm the poorest people on earth.
5. The fact that our media does not really care about any of this unless they get a ratings bump from it
Obviously we all could go on and on.. but the biggest loss IMO is objective truth. There are and will always be things that are true and I feel that we are losing a hold of that so that bad actors can just say to us: "no thats not what your seeing".
Its like in the movie, if they had looked at the plant growing and said: "Thats FAKE NEWS" then run to the field and claimed they did it all.
PG said something along the lines of: "There should be no truth that is increasingly unpopular to speak."
If you don't believe what I shared is true, address that directly. But seeing my post sitting at 1 point and [flagged] after 2 hours is not OK. Just as DJT can't flag away his issues, you shouldn't be able to do so on HN.
One of the things I've loved most about HN is that it was real — grounded in observability, empirical evidence, not bias or feelings. I really hope that what happened to my post is not the beginning or a continuance of the end for that ethos.
Note: To all the downvotes; I did this publicly and not anon for a reason, if you will do the same I am more than willing to provide evidence for all of these claims as long as its done publicly and in the open.