Skip to content

Repository files navigation

Compliant EU

Dashboard Github URL: https://github.com/ogubuikeAlex/compliant-eu-dashboard

Production-ready FastAPI service implementing the compliance-by-design architecture:

  1. InvGuard produces explainable invoice fraud decisions.
  2. rify-AI commits each decision to a canonical, signed, verifiable anchor.
  3. The Compliance Toolkit generates AI Act artifacts from the verified decision trail.

Scope note. This v1 makes the service production-grade — persistence, config, security, observability, tests, and deployment — so those integrations can be swapped in without reworking the app.

Quick start (local, SQLite)

python -m venv .venv
.\.venv\Scripts\Activate.ps1
pip install -e ".[dev]"
copy .env.example .env
uvicorn app.main:app --reload

Open http://127.0.0.1:8000/docs. With defaults, tables are auto-created in a local SQLite file (APP_AUTO_CREATE_TABLES=true).

Run with Postgres (Docker)

docker compose up --build

The API waits for Postgres, runs Alembic migrations via the entrypoint, then serves under gunicorn/uvicorn workers on :8000.

Configuration

All settings are environment-driven (prefix APP_); see .env.example. Production boot is guarded: it refuses to start with the default signing secret, a SQLite URL, or a wildcard CORS origin.

Variable Purpose
APP_ENVIRONMENT development / staging / production
APP_DATABASE_URL Async SQLAlchemy URL (SQLite or postgresql+asyncpg://…)
APP_SIGNING_SECRET rify-AI HMAC secret (required, non-default in prod)
APP_API_KEYS Optional keys for write endpoints; empty = open (dev)
APP_CORS_ORIGINS Allowed origins (comma-separated or JSON)
APP_RATE_LIMIT_* Fixed-window throttle (per client IP)

Endpoints

Method Path Notes
GET /health, /health/ready Liveness / readiness (DB ping)
POST /api/v1/decisions Score + anchor an invoice (API-key guarded when configured)
GET /api/v1/decisions Paginated list (limit, offset)
GET /api/v1/decisions/{id} Fetch one decision
GET /api/v1/decisions/{id}/verification Independent tamper check
GET /api/v1/compliance/model-card Templated model card
GET /api/v1/compliance/bias-report Proxy-attribute bias metrics
GET /api/v1/compliance/audit-report Combined auditor artifact

Errors return a stable envelope: {"error": {"code", "message", "request_id"}}. Every response carries an x-request-id correlation header echoed in structured logs.

Verification & tamper detection

rify-AI hashes a canonical JSON serialization of each decision (sorted keys, stable separators) so the commitment is reproducible across processes — the basis for independent verification. The anchored content is stored alongside the on-chain commitment; verification re-hashes it and checks the signature, returning valid / tampered / signature_invalid / unanchored.

Example request

{
  "invoice_id": "INV-2026-001",
  "vendor_id": "vendor-acme",
  "buyer_id": "buyer-eu-payments",
  "amount": 18450.0,
  "currency": "EUR",
  "invoice_date": "2026-07-20",
  "due_date": "2026-08-19",
  "bank_account": "DE89370400440532013000",
  "vendor_region": "DE",
  "company_size": "sme"
}

Development

make test        # pytest (async, in-memory SQLite)
make lint        # ruff
make typecheck   # mypy (strict)
make migrate     # alembic upgrade head
make revision m="add X"   # autogenerate a migration

Project layout

app/
  api/           # routes + middleware (request context, rate limit)
  core/          # config, logging, errors, security
  db/            # SQLAlchemy base, models, async session
  domain/        # Pydantic schemas
  repositories/  # persistence gateways
  services/      # InvGuard, rify-AI, Compliance (pure business logic)
migrations/      # Alembic (async)
docs/adr/        # architecture decision records

For V2

Neo4j graph analysis, IPFS pinning, on-chain anchoring, SHAP, and LLM extraction remain the PRD's v2 items and are represented here by deterministic local stand-ins behind narrow interfaces.

Use oF Codex Proof:

Screenshot (309) Screenshot (310)

About

eu-comply is a compliance Toolkit that exposes three capabilities behind one REST surface: score an invoice (InvGuard), verify a decision's cryptographic anchor (rify-AI), and generate EU AI Act artifacts (the Compliance Toolkit). Every response is JSON. All write operations are anchored and persisted, so the decision trail is durable and auditable

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages