Dashboard Github URL: https://github.com/ogubuikeAlex/compliant-eu-dashboard
Production-ready FastAPI service implementing the compliance-by-design architecture:
- InvGuard produces explainable invoice fraud decisions.
- rify-AI commits each decision to a canonical, signed, verifiable anchor.
- The Compliance Toolkit generates AI Act artifacts from the verified decision trail.
Scope note. This v1 makes the service production-grade — persistence, config, security, observability, tests, and deployment — so those integrations can be swapped in without reworking the app.
python -m venv .venv
.\.venv\Scripts\Activate.ps1
pip install -e ".[dev]"
copy .env.example .env
uvicorn app.main:app --reloadOpen http://127.0.0.1:8000/docs. With defaults, tables are auto-created in a local
SQLite file (APP_AUTO_CREATE_TABLES=true).
docker compose up --buildThe API waits for Postgres, runs Alembic migrations via the entrypoint, then serves
under gunicorn/uvicorn workers on :8000.
All settings are environment-driven (prefix APP_); see .env.example.
Production boot is guarded: it refuses to start with the default signing secret,
a SQLite URL, or a wildcard CORS origin.
| Variable | Purpose |
|---|---|
APP_ENVIRONMENT |
development / staging / production |
APP_DATABASE_URL |
Async SQLAlchemy URL (SQLite or postgresql+asyncpg://…) |
APP_SIGNING_SECRET |
rify-AI HMAC secret (required, non-default in prod) |
APP_API_KEYS |
Optional keys for write endpoints; empty = open (dev) |
APP_CORS_ORIGINS |
Allowed origins (comma-separated or JSON) |
APP_RATE_LIMIT_* |
Fixed-window throttle (per client IP) |
| Method | Path | Notes |
|---|---|---|
GET |
/health, /health/ready |
Liveness / readiness (DB ping) |
POST |
/api/v1/decisions |
Score + anchor an invoice (API-key guarded when configured) |
GET |
/api/v1/decisions |
Paginated list (limit, offset) |
GET |
/api/v1/decisions/{id} |
Fetch one decision |
GET |
/api/v1/decisions/{id}/verification |
Independent tamper check |
GET |
/api/v1/compliance/model-card |
Templated model card |
GET |
/api/v1/compliance/bias-report |
Proxy-attribute bias metrics |
GET |
/api/v1/compliance/audit-report |
Combined auditor artifact |
Errors return a stable envelope: {"error": {"code", "message", "request_id"}}.
Every response carries an x-request-id correlation header echoed in structured logs.
rify-AI hashes a canonical JSON serialization of each decision (sorted keys,
stable separators) so the commitment is reproducible across processes — the basis for
independent verification. The anchored content is stored alongside the on-chain
commitment; verification re-hashes it and checks the signature, returning
valid / tampered / signature_invalid / unanchored.
{
"invoice_id": "INV-2026-001",
"vendor_id": "vendor-acme",
"buyer_id": "buyer-eu-payments",
"amount": 18450.0,
"currency": "EUR",
"invoice_date": "2026-07-20",
"due_date": "2026-08-19",
"bank_account": "DE89370400440532013000",
"vendor_region": "DE",
"company_size": "sme"
}make test # pytest (async, in-memory SQLite)
make lint # ruff
make typecheck # mypy (strict)
make migrate # alembic upgrade head
make revision m="add X" # autogenerate a migrationapp/
api/ # routes + middleware (request context, rate limit)
core/ # config, logging, errors, security
db/ # SQLAlchemy base, models, async session
domain/ # Pydantic schemas
repositories/ # persistence gateways
services/ # InvGuard, rify-AI, Compliance (pure business logic)
migrations/ # Alembic (async)
docs/adr/ # architecture decision records
Neo4j graph analysis, IPFS pinning, on-chain anchoring, SHAP, and LLM extraction remain the PRD's v2 items and are represented here by deterministic local stand-ins behind narrow interfaces.
Use oF Codex Proof: