{"id":50260883,"url":"https://github.com/matematicsolutions/patron","last_synced_at":"2026-05-27T10:04:39.379Z","repository":{"id":359125424,"uuid":"1243751570","full_name":"matematicsolutions/patron","owner":"matematicsolutions","description":"Lokalny RODO-safe agent AI dla polskich kancelarii prawnych. Zero-cloud self-host, 5 konektorow MCP polskiego prawa (SAOS/NSA/ISAP/KRS/EUR-Lex), audit trail hash-chain (AI Act art. 12), bring-your-own-model. Fork willchen96/mike (MIT) -\u003e AGPL-3.0.","archived":false,"fork":false,"pushed_at":"2026-05-20T17:57:15.000Z","size":2890,"stargazers_count":0,"open_issues_count":13,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-20T17:58:11.771Z","etag":null,"topics":["agpl","ai-agent","audit-trail","eu-ai-act","gdpr","law-firms","legal-tech","matematic","mcp","model-context-protocol","patron","poland","polish-law","self-hosted"],"latest_commit_sha":null,"homepage":"https://matematic.co","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/matematicsolutions.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":"governance/CONSTITUTION.md","roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-19T16:21:03.000Z","updated_at":"2026-05-20T17:57:21.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/matematicsolutions/patron","commit_stats":null,"previous_names":["matematicsolutions/patron"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/matematicsolutions/patron","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matematicsolutions%2Fpatron","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matematicsolutions%2Fpatron/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matematicsolutions%2Fpatron/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matematicsolutions%2Fpatron/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/matematicsolutions","download_url":"https://codeload.github.com/matematicsolutions/patron/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matematicsolutions%2Fpatron/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33560734,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-27T02:00:06.184Z","response_time":53,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agpl","ai-agent","audit-trail","eu-ai-act","gdpr","law-firms","legal-tech","matematic","mcp","model-context-protocol","patron","poland","polish-law","self-hosted"],"created_at":"2026-05-27T10:01:11.793Z","updated_at":"2026-05-27T10:04:39.373Z","avatar_url":"https://github.com/matematicsolutions.png","language":"TypeScript","funding_links":[],"categories":["Pokrewne repozytoria - reszta ekosystemu MateMatic"],"sub_categories":["Inne"],"readme":"# Patron\n\n[![License: AGPL v3](https://img.shields.io/badge/License-AGPL_v3-blue.svg)](./LICENSE)\n[![Tests](https://img.shields.io/badge/tests-69%2F69_passing-brightgreen)](./backend)\n[![AI Act](https://img.shields.io/badge/AI_Act-Art._12_record--keeping-orange)](./governance/CONSTITUTION.md)\n[![RODO](https://img.shields.io/badge/RODO-art._5%2F25%2F30%2F32-orange)](./governance/CONSTITUTION.md)\n[![Stack](https://img.shields.io/badge/stack-zero--cloud-success)](./governance/CONSTITUTION.md)\n[![MCP](https://img.shields.io/badge/MCP-6_connectors-blue)](https://github.com/matematicsolutions)\n[![Node](https://img.shields.io/badge/Node-20%2B-brightgreen)](https://nodejs.org)\n\n\u003e **Lokalny agent AI dla polskiej kancelarii prawnej.** Self-host\n\u003e zero-cloud (Postgres + MinIO), 6 konektorów polskiego i unijnego prawa\n\u003e (SAOS / NSA / ISAP / KRS / EUR-Lex / EU-Compliance), audit trail z hash-chain (AI Act art. 12),\n\u003e bring-your-own-model (Gemini / Claude / Ollama lokalny).\n\nPatron jest forkiem [Mike](https://github.com/willchen96/mike) (dokumentowy\nasystent prawny, MIT). Dodaje polonizację, polski legal stack i wymogi\ncompliance, których potrzebuje kancelaria. Pełne zasady opisuje\n[governance/CONSTITUTION.md](./governance/CONSTITUTION.md).\n\n## Zawartość\n\n- `frontend/` - aplikacja Next.js\n- `backend/` - Express API, klient MCP, audit trail, dispatch narzędzi\n- `backend/src/lib/input-security/` - lokalny, deterministyczny skan dokumentów wejściowych (prompt-injection / ukryte akcje PDF / zaciemnienie) przed wejściem do modelu lub RAG (ADR-0019/0020)\n- `backend/src/lib/mcp-security/` - lokalny, deterministyczny skan definicji konektorów MCP (typosquat / drift opisu / hidden-instructions / tool-poisoning) PRZED ich załadowaniem do kontraktu MCP (ADR-0025/0028)\n- `backend/schema.sql` - schemat Postgresa (Supabase-compatible)\n- `governance/` - **Konstytucja AI Patrona** + Implementation Playbook + ADR\n- `deploy/` - runbook wdrożeniowy (`docker-compose`)\n- `scripts/bundle-mcp.cjs` - bundler 6 serwerów MCP do obrazu backendu\n\n## Konektory MCP polskiego i unijnego prawa (osobne repo)\n\n| Konektor | Domena | Zwraca |\n|---|---|---|\n| [`mcp-saos`](https://github.com/matematicsolutions/mcp-saos) | orzeczenia powszechne, SN, TK, KIO | search / get_judgment / search_by_case |\n| [`mcp-nsa`](https://github.com/matematicsolutions/mcp-nsa) | orzecznictwo NSA + 16 WSA (CBOSA) | search / get_judgment / search_by_case |\n| [`mcp-isap`](https://github.com/matematicsolutions/mcp-isap) | legislacja PL (Dz.U. + M.P., Sejm ELI) | search_acts / get_act / get_act_text |\n| [`mcp-krs`](https://github.com/matematicsolutions/mcp-krs) | Krajowy Rejestr Sądowy (MS) | get_entity / get_entity_full / get_board |\n| [`mcp-eu-sparql`](https://github.com/matematicsolutions/mcp-eu-sparql) | prawo UE (EUR-Lex + CJEU, live SPARQL) | search_by_celex / search_by_date_range / search_cjeu |\n| [`mcp-eu-compliance`](https://github.com/matematicsolutions/mcp-eu-compliance) | compliance UE offline (GDPR, AI Act, DORA, NIS2, eIDAS 2.0, CRA) | eu_search / eu_article / eu_compare / eu_check_applicability / eu_evidence |\n\n## Wdrożenie produkcyjne\n\nPełny runbook: **[deploy/README.md](./deploy/README.md)**.\nSkrót dla niecierpliwych:\n\n```bash\n# 1. Klon 7 repo (patron + 6 mcp-*)\ngit clone matematicsolutions/patron \u0026\u0026 cd patron\nfor d in mcp-saos mcp-nsa mcp-isap mcp-krs mcp-eu-sparql mcp-eu-compliance; do\n  (cd .. \u0026\u0026 git clone matematicsolutions/$d \u0026\u0026 cd $d \u0026\u0026 npm install \u0026\u0026 npm run build)\ndone\n\n# 2. Bundle MCP do obrazu backendu\nnode scripts/bundle-mcp.cjs\n\n# 3. Config sekretów\ncp .env.docker.example .env.docker\nnano .env.docker\n\n# 4. Up\ndocker compose --env-file .env.docker up -d\n```\n\nWymaga osobno postawionego Supabase + MinIO (osobne stack). Patrz runbook.\n\n## Governance (przed wdrożeniem)\n\n- [**Konstytucja AI Patrona v1.2.0**](./governance/CONSTITUTION.md) -\n  9 zasad, granice produktu, role (Administrator / Operator / Inspektor),\n  audyt, ewolucja. Mapowanie na AI Act art. 12, RODO art. 5/25/30/32\n  i etykę zawodową. Art. 5 obejmuje kontrolę wejścia dokumentów.\n- [**Implementation Playbook**](./governance/IMPLEMENTATION_PLAYBOOK.md) -\n  6-8 tygodni wdrożenia krok po kroku, z macierzą RACI.\n- [**ADR**](./governance/adr/) - Architecture Decision Records (0001-0020),\n  m.in. [0001 hash-chain](./governance/adr/0001-hash-chain-audit-trail.md),\n  [0002 dual-license](./governance/adr/0002-dual-license-agpl-shell-mit-connectors.md),\n  [0019 skan dokumentów wejściowych](./governance/adr/0019-input-document-security-pipeline-pl.md),\n  [0020 wpięcie w ingest](./governance/adr/0020-wpiecie-input-security-w-ingest.md).\n\nKancelaria przed wdrożeniem czyta i podpisuje **Konstytucję v1.2.0**\n(sekcja podpisów na końcu pliku).\n\n## Licencja\n\nStack jest **dual-license** (zob. [ADR-0002](./governance/adr/0002-dual-license-agpl-shell-mit-connectors.md)):\n\n- `patron` (ten repo, powłoka) - **AGPL-3.0-only** ([LICENSE](./LICENSE) + [NOTICE](./NOTICE))\n- `mcp-saos`, `mcp-nsa`, `mcp-isap`, `mcp-krs`, `mcp-eu-sparql` - **MIT**\n\nKancelaria self-host używa, modyfikuje i dystrybuuje Patrona wewnątrz\norganizacji bez dodatkowych obowiązków. Konkurent, który oferuje\nPatrona jako SaaS osobom trzecim, otwiera swoje modyfikacje.\n\nPatron jest forkiem [Mike](https://github.com/willchen96/mike) (MIT,\n©2025 Will Chen). Pełne attribution: [NOTICE](./NOTICE).\n\n---\n\n## Local development\n\nDalsza część README opisuje uruchomienie lokalne (development).\nDo wdrożenia produkcyjnego użyj `deploy/README.md` (Docker).\n\n### Contents (legacy)\n\n- `frontend/` - Next.js application\n- `backend/` - Express API, Supabase access, document processing, and database schema\n- `backend/schema.sql` - Supabase schema for fresh databases\n- `backend/migrations/` - incremental database updates for existing deployments\n\n## Prerequisites\n\n- Node.js 20 or newer\n- npm\n- git\n- A Supabase project\n- A Cloudflare R2 bucket, MinIO bucket, or another S3-compatible bucket\n- At least one supported model provider API key: Anthropic, Google Gemini, or OpenAI\n- LibreOffice installed locally if you need DOC/DOCX to PDF conversion\n\n## Database Setup\n\nFor a new Supabase database, open the Supabase SQL editor and run:\n\n```sql\n-- copy and run the contents of:\n-- backend/schema.sql\n```\n\nThe schema file is based on `supabase-migration.sql` and folds in the later files in `backend/migrations/`.\n\nFor an existing database, do not run the full schema file over production data. Apply the incremental files in `backend/migrations/` instead.\n\n## Environment\n\nCreate local env files:\n\n```bash\ntouch backend/.env\ntouch frontend/.env.local\n```\n\nCreate `backend/.env`:\n\n```bash\nPORT=3001\nFRONTEND_URL=http://localhost:3000\nDOWNLOAD_SIGNING_SECRET=replace-with-a-random-32-byte-hex-string\nSUPABASE_URL=https://your-project.supabase.co\nSUPABASE_SECRET_KEY=your-supabase-service-role-key\n\nR2_ENDPOINT_URL=https://your-account-id.r2.cloudflarestorage.com\nR2_ACCESS_KEY_ID=your-r2-access-key\nR2_SECRET_ACCESS_KEY=your-r2-secret-key\nR2_BUCKET_NAME=mike\n\nGEMINI_API_KEY=your-gemini-key\nANTHROPIC_API_KEY=your-anthropic-key\nOPENAI_API_KEY=your-openai-key\nRESEND_API_KEY=your-resend-key\nUSER_API_KEYS_ENCRYPTION_SECRET=your-long-random-secret\n```\n\nCreate `frontend/.env.local`:\n\n```bash\nNEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co\nNEXT_PUBLIC_SUPABASE_PUBLISHABLE_DEFAULT_KEY=your-supabase-anon-key\nNEXT_PUBLIC_API_BASE_URL=http://localhost:3001\n```\n\nSupabase values come from the project dashboard. Use the project URL for `SUPABASE_URL` / `NEXT_PUBLIC_SUPABASE_URL`, the service role key for the backend `SUPABASE_SECRET_KEY`, and the anon/public key for `NEXT_PUBLIC_SUPABASE_PUBLISHABLE_DEFAULT_KEY`. If your Supabase project shows multiple key formats, use the legacy JWT-style anon and service role keys expected by the Supabase client libraries.\n\nProvider keys are only needed for the models and email features you plan to use. Model provider keys can be configured in `backend/.env` for the whole instance, or per user in **Account \u003e Models \u0026 API Keys**. If a provider key is present in `backend/.env`, that provider is available by default and the matching browser API key field is read-only.\n\n## Install\n\nInstall each app package:\n\n```bash\nnpm install --prefix backend\nnpm install --prefix frontend\n```\n\n## Run Locally\n\nStart the backend:\n\n```bash\nnpm run dev --prefix backend\n```\n\nStart the main app:\n\n```bash\nnpm run dev --prefix frontend\n```\n\nOpen `http://localhost:3000`.\n\n## First Run\n\n1. Sign up in the app.\n2. If you did not set provider keys in `backend/.env`, open **Account \u003e Models \u0026 API Keys** and add an Anthropic, Gemini, or OpenAI API key.\n3. Create or open a project and start chatting with documents.\n\n## Troubleshooting\n\n**Sign-up confirmation email never arrives.** Confirmation emails are sent by Supabase Auth, not by Mike. For local development, the simplest fix is to disable email confirmation in **Supabase \u003e Authentication \u003e Providers \u003e Email**. For production, configure custom SMTP in Supabase; the built-in mailer is heavily rate-limited and may be restricted on newer projects.\n\n**The model picker shows a missing-key warning.** Add a key for that provider in **Account \u003e Models \u0026 API Keys**, or configure the provider key in `backend/.env` and restart the backend.\n\n**DOC or DOCX conversion fails.** Install LibreOffice locally and restart the backend so document conversion commands are available on the process path.\n\n## Useful Checks\n\n```bash\nnpm run build --prefix backend\nnpm run build --prefix frontend\nnpm run lint --prefix frontend\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmatematicsolutions%2Fpatron","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmatematicsolutions%2Fpatron","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmatematicsolutions%2Fpatron/lists"}