Safety-first mutual disclosure system: Readiness Gate, Evidence Ledger, Behavior Scoring, Jurisdiction Packs, and counsel-ready exports.
This system provides a secure, privacy-preserving platform for managing disclosure readiness and evidence collection in legal and compliance contexts. The architecture prioritizes safety, privacy, and compliance through metadata-only storage and strict RBAC controls.
- Readiness Gate: Session-based readiness assessment and scoring
- Evidence Ledger: Metadata-only evidence tracking with cryptographic verification
- Behavior Scoring: Risk assessment and behavioral analysis
- Jurisdiction Packs: Locale-specific compliance and legal frameworks
- Counsel-Ready Exports: Structured data export for legal proceedings
- RBAC & Safety Mode: Role-based access control with safety-first information minimization
The following criteria must be met for this safety-first mutual disclosure system:
- Docker Compose Health:
docker-compose upbrings all services to healthy state - Container Orchestration: All services (API, web, database) start successfully
- Service Discovery: Internal service communication works correctly
- Health Checks: All services report healthy status via health endpoints
- Metadata-Only Storage: System stores only evidence metadata, never raw documents
- Cryptographic Hashes: All evidence references use cryptographic verification
- No Raw Documents: Absolute guarantee that no raw document content is stored
- Evidence Integrity: Hash-based verification of evidence authenticity
- RBAC Implementation: Role-based access control fully implemented and tested
- Safety Mode Enforcement: Sensitive information minimization active by default
- Rate Limiting: API rate limiting configured and functional
- Privacy Controls: Request ID tracking, audit logging, and data redaction
- Security Documentation: SECURITY.md covers vulnerability reporting and policies
- Playwright Smoke Tests: Full end-to-end test covering:
- User login and authentication
- Session creation and management
- Evidence addition (metadata only)
- Readiness assessment
- Data export functionality
- CI Pipeline: Continuous integration passes on fresh repository clone
- Test Coverage: All modules and features have adequate test coverage
- Local Test Execution: Tests run successfully via pnpm workflows
- Readiness Gate: Session-based readiness assessment functional
- Evidence Ledger: Metadata tracking and verification working
- Behavior Scoring: Risk assessment algorithms implemented
- Jurisdiction Packs: Locale-specific compliance frameworks available
- Export Functionality: Counsel-ready data exports generate correctly
- User Management: Authentication and user session management
- API Endpoints: All documented API endpoints functional and tested
- Contributing Guidelines: CONTRIBUTING.md defines development workflow
- Security Policy: SECURITY.md covers reporting, scope, and compliance stance
- Code Ownership: CODEOWNERS file assigns module responsibility
- Architecture Decisions: ADR documents key architectural choices
- API Documentation: OpenAPI specifications complete and current
See docs/adr/ for key architectural decisions, including:
- ADR-0001: Metadata-Only Storage - Core privacy and compliance architecture
# Clone repository
git clone <repository-url>
cd financial-readiness-gate-evidence-ledger
# Install dependencies
pnpm install
# Start development environment
docker-compose up
# Run tests
pnpm test
# Run Playwright tests
pnpm test:e2e├── apps/
│ ├── api/ # Backend API service
│ └── web/ # Frontend application
├── packages/
│ └── ui/ # Shared UI components
├── docker/ # Docker configuration
├── openapi/ # API documentation
├── docs/
│ └── adr/ # Architecture Decision Records
├── SECURITY.md # Security policy and reporting
├── CONTRIBUTING.md # Development guidelines
└── CODEOWNERS # Code ownership assignments
This system implements a metadata-only architecture as a fundamental privacy and compliance measure:
- No Raw Document Storage: The system never stores actual document content
- Cryptographic Verification: All evidence uses hash-based integrity checking
- RBAC Controls: Strict role-based access control throughout
- Safety Mode: Default information minimization and redaction
- Audit Trail: Comprehensive logging with request ID tracking
MIT License - see LICENSE file for details.
For security vulnerabilities, see SECURITY.md for reporting procedures and policies.