{"id":49537865,"url":"https://github.com/sapsan14/aletheia-ai","last_synced_at":"2026-05-02T12:31:33.724Z","repository":{"id":335468516,"uuid":"1145870311","full_name":"sapsan14/aletheia-ai","owner":"sapsan14","description":"ProofGPT — verifiable AI responses: signed, timestamped, PKI-anchored proofs of LLM output provenance.","archived":false,"fork":false,"pushed_at":"2026-04-27T16:02:25.000Z","size":13194,"stargazers_count":1,"open_issues_count":9,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-04-27T16:14:25.447Z","etag":null,"topics":["anthropic","llm","pki","proof","typescript","verifiable-ai"],"latest_commit_sha":null,"homepage":null,"language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sapsan14.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-01-30T10:15:23.000Z","updated_at":"2026-04-27T16:02:27.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/sapsan14/aletheia-ai","commit_stats":null,"previous_names":["sapsan14/aletheia-ai"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/sapsan14/aletheia-ai","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sapsan14%2Faletheia-ai","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sapsan14%2Faletheia-ai/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sapsan14%2Faletheia-ai/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sapsan14%2Faletheia-ai/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sapsan14","download_url":"https://codeload.github.com/sapsan14/aletheia-ai/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sapsan14%2Faletheia-ai/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32534964,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-02T12:25:33.646Z","status":"ssl_error","status_checked_at":"2026-05-02T12:24:51.733Z","response_time":132,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anthropic","llm","pki","proof","typescript","verifiable-ai"],"created_at":"2026-05-02T12:31:31.998Z","updated_at":"2026-05-02T12:31:33.704Z","avatar_url":"https://github.com/sapsan14.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Enterprise Agent Trust Framework\n\n\u003e ⚠️ **University research prototype** — reflection-informed, **not** a production system. For discussion, experimentation, and clear technical understanding. **Not legal advice.**\n\n[![Java](https://img.shields.io/badge/Java-21-orange?logo=openjdk)](https://openjdk.org/)\n[![Spring Boot](https://img.shields.io/badge/Spring%20Boot-3.5-brightgreen?logo=spring)](https://spring.io/projects/spring-boot)\n[![License](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n![Context](https://img.shields.io/badge/Context-QTSP%20experience-lightgrey)\n[![PQC](https://img.shields.io/badge/PQC-ML--DSA--65-teal)](docs/developers/en/PLAN_PQC.md)\n\n[![CI](https://img.shields.io/github/actions/workflow/status/sapsan14/aletheia-ai/ci.yml?branch=main\u0026logo=githubactions\u0026label=CI)](https://github.com/sapsan14/aletheia-ai/actions/workflows/ci.yml)\n[![Open issues](https://img.shields.io/github/issues/sapsan14/aletheia-ai?logo=github)](https://github.com/sapsan14/aletheia-ai/issues)\n[![Open PRs](https://img.shields.io/github/issues-pr/sapsan14/aletheia-ai?logo=github)](https://github.com/sapsan14/aletheia-ai/pulls)\n[![Last commit](https://img.shields.io/github/last-commit/sapsan14/aletheia-ai/main?logo=git)](https://github.com/sapsan14/aletheia-ai/commits/main)\n[![Delivery board](https://img.shields.io/badge/Delivery%20board-Projects%20v2-0969da?logo=github)](https://github.com/users/sapsan14/projects/5)\n\n**Written for PKI engineers and architects**—**trust / security / solution architects** who draw the boxes and flows, and **PKI practitioners** who run CAs, TSPs, QTSP-oriented services, validation, and crypto operations. The **architecture** question we stress: where does **agent output and governed action** sit in a **trust stack** you already know (**X.509 path logic, signature verification, revocation, timestamps, audit discipline** under **eIDAS** and **ETSI EN 319 xxx**)? From there we map **how** that **reference architecture** **relates** to **EU AI Act** traceability and integrity language—article by article—without treating the Act as a PKI spec.\n\n*PKI / QTSP experience informs the design; this repository is **not** a QTSP product.*\n\n**University research prototype** — a **strong, runnable sketch** of that argument in code: **hash → sign → (optional) RFC 3161 timestamp → evidence package**, plus **path validation**, **OCSP/CRL**, and **hybrid classical + post-quantum** signing where enabled. Grounded in ongoing **reflections and design notes** (e.g. [2026-03-24](https://github.com/sapsan14/life/blob/main/2026-03-24.md), [2026-03-25](https://github.com/sapsan14/life/blob/main/2026-03-25.md)); elaborated for engineering audiences in-repo ([vision note](docs/vision/eu_ai_act_multi_sector_opportunities.md)). **Not legal advice.** Not a production offering.\n\n**Primary law (AI Act):** [Regulation (EU) 2024/1689 — EUR-Lex (consolidated EN)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) · **Navigator (unofficial, convenient):** [artificialintelligenceact.eu](https://artificialintelligenceact.eu/) — use EUR-Lex for authoritative text.\n\n\u003e **Want to plug an agent in?** [`partner-integrations/QUICKSTART.md`](partner-integrations/QUICKSTART.md) is the five-minute, copy-paste path: mint a key → `eatf init` → `eatf doctor` → `eatf agents sync` → `eatf sign --download` → `eatf verify`. End state is a real, offline-verifiable `.aep` evidence bundle — no UI clicks beyond the API key, no `curl`. See [RFC #72](https://github.com/sapsan14/aletheia-ai/issues/72) for the design.\n\n---\n\n## Why this prototype exists\n\nFrom a **PKI and trust-architecture perspective**, the interesting question is whether **high-risk AI obligations** (logging, transparency, robustness “in places”) can be **grounded in artefacts you already understand**: **CMS/CAdES-style or equivalent signing**, **[X.509](https://www.rfc-editor.org/rfc/rfc5280) path validation**, **revocation** ([OCSP](https://www.rfc-editor.org/rfc/rfc6960), [CRL](https://www.rfc-editor.org/rfc/rfc5280#section-5)), **TSA** ([RFC 3161](https://www.rfc-editor.org/rfc/rfc3161)), and **policy** aligned with **EN 319 102 / 401 / 411**—i.e. the same **trust-service** toolbox as under **[eIDAS](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910)**.\n\nThe **AI Act** (especially **Chapter III, Section 2**) frames *what* deployers may need to show in terms of logging, transparency, oversight, and robustness. **This codebase** is an **implementation hypothesis** stated in **PKI terms**: bind agent outputs and sensitive **actions** to **signed, timestamped, verifiable evidence**, policy, and human steps—so **engineers and architects** can **inspect** the chain and **challenge the design**, not only read narrative mapping.\n\nWe deliberately map **[Article 10](https://artificialintelligenceact.eu/article/10/)** here to **integrity and provenance** (hashes, signatures, timestamps)—**not** to ML “data quality” as a PKI claim. In-app mapping: **`/trust/regulatory-mapping`**.\n\n**MCP angle:** experimental **governance** next to identity ([MCP](https://modelcontextprotocol.io/)) and detection—see [mcp-ecosystem.md](docs/concepts/mcp-ecosystem.md).\n\n---\n\n## Core mapping (summary table)\n\n*PKI-native summary: which AI Act articles we discuss against which **eIDAS / ETSI** levers, and what the repo actually runs. Full tables and sector matrix below.*\n\n| AI Act (navigator → EUR-Lex) | Idea in this prototype | eIDAS / ETSI (entry points) | What the repo runs |\n|------------------------------|------------------------|----------------------------|--------------------|\n| [**Art. 10**](https://artificialintelligenceact.eu/article/10/) · [EUR-Lex context](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) | **Integrity \u0026 provenance** only—not ML dataset “quality” as a crypto claim | [eIDAS (EU) No 910/2014](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910) (trust services, e-signatures); [**EN 319 102-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/), [**EN 319 132-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31913201/); [ETSI digital signatures](https://www.etsi.org/technologies/digital-signatures) | Canonical payloads, **signatures**, **Evidence Packages** |\n| [**Art. 12**](https://artificialintelligenceact.eu/article/12/) | Tamper-evident trails, PKI-related events | [**EN 319 401**](https://www.etsi.org/deliver/etsi_en/319400_319499/319401/), [**EN 319 411-1**](https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/) | **Audit ledger**, signed events, [**OCSP**](https://www.rfc-editor.org/rfc/rfc6960) / [**CRL**](https://www.rfc-editor.org/rfc/rfc5280) where configured |\n| [**Art. 13**](https://artificialintelligenceact.eu/article/13/) | Verifiable crypto / policy state for deployers and auditors | [eIDAS trust services — Commission overview](https://digital-strategy.ec.europa.eu/en/fact-pages/electronic-trust-services_en); [**EN 319 102-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/), [**EN 319 412-1**](https://www.etsi.org/deliver/etsi_en/319400_319499/31941201/); [EU Digital Identity / eIDAS hub](https://eidas.ec.europa.eu/) | **Chain-of-trust validation**, verification UI/API |\n| [**Art. 6**](https://artificialintelligenceact.eu/article/6/) + [**Annex III**](https://artificialintelligenceact.eu/annex/3) · [Annex III (EUR-Lex)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) | Motivation when agents touch **high-risk** use types | Same stack as above | Scenario docs, sector matrix—**not** a compliance certificate |\n\n\u003e **Focus:** cryptographic **integrity** and **provenance**, not ML **data quality** under the Act.\n\n---\n\n## What is implemented (prototype depth)\n\n**PKI / crypto pipeline**\n\n- **Digital signatures** over canonical content (RSA; optional [**ML-DSA**](https://csrc.nist.gov/publications/detail/fips/204/final) hybrid — [PQC plan](docs/developers/en/PLAN_PQC.md))\n- **Certificate path validation** ([PKIX / X.509](https://www.rfc-editor.org/rfc/rfc5280)) and QTSP-oriented trust configuration (**deployment-dependent**)\n- [**RFC 3161**](https://www.rfc-editor.org/rfc/rfc3161) timestamping (real or mock TSA)\n- **Hash-chained audit** events; signing where enabled\n- **Evidence Packages** (`.aep`): export + **offline** verification (JAR/scripts in repo)\n- **Spring Boot** + **Next.js**; REST + partner/MCP-style **governed actions** and attestation flows\n\nTechnical entry: [docs/README.md](docs/README.md).\n\n---\n\n## Post-quantum cryptography (PQC)\n\n- Dual-signing: RSA-4096 + **ML-DSA-65** ([NIST PQC project / Dilithium](https://csrc.nist.gov/projects/post-quantum-cryptography))\n- Bouncy Castle BCPQC; [strategy doc](docs/developers/en/PLAN_PQC.md) · `GET /api/v1/crypto/health`\n\n---\n\n## Additional prototype components\n\n- **Delegation chain modelling** — [delegation builder](docs/features/delegation-builder.md), [concepts](docs/knowledgebase/understanding_delegation_chains.md), `/delegation-chains/builder`\n- **Human-in-the-loop** — approvals / review queues (demo tenants)\n- **Policy-gated actions** — illustrative policies only (**not** legal compliance)\n\n---\n\n## Deep dive — regulatory mapping (engineering argument, not legal canon)\n\n**PKI lens:** the tables below are for **mapping conversations**—they do **not** replace **CP/CPS** discipline or notified-body work. **Not legal advice.** Counsel validates classifications. Extended analysis: [eu_ai_act_multi_sector_opportunities.md](docs/vision/eu_ai_act_multi_sector_opportunities.md).\n\n### Speaking lines (hypothesis, not statutory interpretation)\n\n- The **AI Act** frames *what* trust and traceability may be required in places; **eIDAS / ETSI** show *how* the EU often implements **integrity and validation** in practice—this prototype **tests alignment in software**.\n- **Article 10** in *this* mapping means **integrity \u0026 provenance**—not ML training-data “quality” as a PKI deliverable.\n\n### Three-column mental model (EN)\n\n| EU AI Act | eIDAS / ETSI | Aletheia (prototype) |\n|-----------|--------------|----------------------|\n| [**Art. 6**](https://artificialintelligenceact.eu/article/6/) — high-risk AI systems | [Trust services](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910); CA / TSP / [QTSP (Commission)](https://digital-strategy.ec.europa.eu/en/fact-pages/qualified-trust-service-providers-qttsp_en) | End-to-end **PKI path**: CA material, **validation**, cross-border **trust-service** practice per [eIDAS hub](https://eidas.ec.europa.eu/) |\n| [**Art. 10**](https://artificialintelligenceact.eu/article/10/) — data integrity \u0026 provenance (*not* “quality” on this axis) | [eIDAS](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910) e-signatures (integrity + authenticity) | Signed artefacts; integrity checks |\n| [**Art. 12**](https://artificialintelligenceact.eu/article/12/) — logging, traceability | Non-repudiation; [**EN 319 401**](https://www.etsi.org/deliver/etsi_en/319400_319499/319401/), [**EN 319 411-1**](https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/) | Serials; [OCSP](https://www.rfc-editor.org/rfc/rfc6960) / [CRL](https://www.rfc-editor.org/rfc/rfc5280); validation history |\n| [**Art. 13**](https://artificialintelligenceact.eu/article/13/) — transparency (verifiability) | [**EN 319 102-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/); [electronic trust services (EU)](https://digital-strategy.ec.europa.eu/en/fact-pages/electronic-trust-services_en) | Chain validation; **source / anchor verification** |\n| [**Art. 14**](https://artificialintelligenceact.eu/article/14/) — human oversight | *Indirect:* [qualified trust services](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910) + audit trails → **accountability**; human control remains **process** | Validation + audit **evidence** for reviewers—not a substitute for governance |\n| Reliability / future | [eIDAS 2.0 — (EU) 2024/1183](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183); [EU eIDAS policy](https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation); [ETSI quantum-safe crypto](https://www.etsi.org/technologies/quantum-safe-cryptography) | Hybrid RSA + ML-DSA; [PoC PQC](docs/developers/en/PLAN_PQC.md) |\n\n### Full layer mapping (EU AI Act → eIDAS/ETSI → prototype)\n\n| Layer | EU AI Act | → eIDAS / ETSI | → Aletheia (prototype) | One-liner (EN) |\n|-------|-----------|----------------|-------------------------|----------------|\n| **Data integrity \u0026 provenance** | [**Art. 10**](https://artificialintelligenceact.eu/article/10/) — scope here: integrity + provenance; “data quality” in the Act ≠ this PKI slice | [eIDAS](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910); [**EN 319 102-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/), [**EN 319 132-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31913201/) | Signed artefacts | Art. 10 → integrity \u0026 provenance via signatures; **not** an ML data-quality claim. |\n| **Traceability \u0026 logging** | [**Art. 12**](https://artificialintelligenceact.eu/article/12/) | [**EN 319 401**](https://www.etsi.org/deliver/etsi_en/319400_319499/319401/), [**EN 319 411-1**](https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/) | OCSP/CRL; audit | Art. 12 → PKI-anchored traceability. |\n| **Transparency \u0026 verifiability** | [**Art. 13**](https://artificialintelligenceact.eu/article/13/) | [**EN 319 102-1**](https://www.etsi.org/deliver/etsi_en/319100_319199/31910201/), [**EN 319 412-1**](https://www.etsi.org/deliver/etsi_en/319400_319499/31941201/); [trust services (EU)](https://digital-strategy.ec.europa.eu/en/fact-pages/electronic-trust-services_en) | Path validation; root / policy provenance | Art. 13 → cryptographic verifiability. |\n| **Human oversight (supporting)** | [**Art. 14**](https://artificialintelligenceact.eu/article/14/) (*indirect*) | [eIDAS trust stack](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910); audit-friendly logs | Evidence for review | Art. 14 → PKI does not add the human; it makes outcomes **reviewable** and **attributable**. |\n| **High-risk trust architecture** | [**Art. 6**](https://artificialintelligenceact.eu/article/6/) | CA, TSP, [QTSP](https://digital-strategy.ec.europa.eu/en/fact-pages/qualified-trust-service-providers-qttsp_en); [**EN 319 401**](https://www.etsi.org/deliver/etsi_en/319400_319499/319401/) | Configurable trust material + validation + verification UX | Strong trust layer **analogous** to regulated PKI—**prototype**, not a national scheme. |\n| **Crypto agility / PQC** | High-risk chapter context ([Arts 9–15 navigator](https://artificialintelligenceact.eu/section/3-2/)) | EU / [ETSI quantum-safe](https://www.etsi.org/technologies/quantum-safe-cryptography) | Hybrid [ML-DSA](https://csrc.nist.gov/publications/detail/fips/204/final) | Future-proofing—**not** a claim that the Act mandates PQC. |\n\n### Official \u0026 secondary anchors\n\n| Resource | URL |\n|----------|-----|\n| **AI Act (EU law)** | [EUR-Lex CELEX 32024R1689](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) |\n| **AI Act — implementation timeline** | [Commission AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline) |\n| **Navigator — Annex III** | [artificialintelligenceact.eu/annex/3](https://artificialintelligenceact.eu/annex/3) |\n| **Navigator — Arts 9–15** | [Section 3(2) high-risk](https://artificialintelligenceact.eu/section/3-2/) |\n| **Deployer — Art. 26** | [navigator](https://artificialintelligenceact.eu/article/26/) |\n| **FRIA — Art. 27** | [navigator](https://artificialintelligenceact.eu/article/27/) |\n| **eIDAS (2014)** | [EUR-Lex 910/2014](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910) |\n| **eIDAS 2.0 (2024/1183)** | [EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183) |\n\n### High-risk chapter — article quick map (prototype levers)\n\n| Article | Navigator | Gist | Prototype lever |\n|--------|-----------|------|-----------------|\n| **9** | [Art. 9](https://artificialintelligenceact.eu/article/9/) | Risk management | Policies, kill-switch, delegation limits |\n| **10** | [Art. 10](https://artificialintelligenceact.eu/article/10/) | Data governance | *Here:* integrity/provenance via crypto |\n| **11** | [Art. 11](https://artificialintelligenceact.eu/article/11/) | Technical documentation | Exports, metadata |\n| **12** | [Art. 12](https://artificialintelligenceact.eu/article/12/) | Record-keeping | Hash-chained audit, signed events |\n| **13** | [Art. 13](https://artificialintelligenceact.eu/article/13/) | Transparency to deployers | Agent identity / capabilities in UI/API |\n| **14** | [Art. 14](https://artificialintelligenceact.eu/article/14/) | Human oversight | Approvals, escalation |\n| **15** | [Art. 15](https://artificialintelligenceact.eu/article/15/) | Robustness / security | Verification endpoints, signals |\n\n**Deployer discussion only:** [Art. 26](https://artificialintelligenceact.eu/article/26/), [Art. 27](https://artificialintelligenceact.eu/article/27/) — not a claim this repo satisfies them.\n\n### Annex III → sectors (condensed)\n\nHigh-risk categories under [**Art. 6(2)**](https://artificialintelligenceact.eu/article/6/) — see [Annex III navigator](https://artificialintelligenceact.eu/annex/3) and [EUR-Lex Annex III](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689): (1) Biometrics, (2) Critical infrastructure, (3) Education, (4) Employment, (5) Essential services \u0026 benefits, (6) Law enforcement, (7) Migration/border, (8) Justice \u0026 democratic processes.\n\n### Sector matrix (illustrative — not classification advice)\n\n| Sector | Typical agentic actions | Touchpoints (links) | Prototype-style response |\n|--------|-------------------------|---------------------|--------------------------|\n| **Healthcare** | Triage, notes, orders | [Annex III(5)(d)](https://artificialintelligenceact.eu/annex/3); [MDR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32017R0745); [IVDR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32017R0746); [GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679) | Human gate; signed evidence; audit |\n| **Life \u0026 health insurance** | Underwriting, claims | [Annex III(5)(c)](https://artificialintelligenceact.eu/annex/3) | Human binds; policies |\n| **Banking \u0026 credit** | Credit, KYC | [Annex III(5)(b)](https://artificialintelligenceact.eu/annex/3) | Threshold approval; exports |\n| **Payments \u0026 treasury** | Pay, FX | [PSD2](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32015L2366); [AML overview (Commission)](https://finance.ec.europa.eu/financial-crime/anti-money-laundering-and-countering-financing-terrorism_en); AI Act if **5(b)** | Governance gate; demo **PaymentIntent** |\n| **Legal \u0026 dispute** | Drafts, discovery | [Annex III(8)(a)](https://artificialintelligenceact.eu/annex/3) | Delegation; human sign-off · **[OpenCourt](docs/vision/scenarios/opencourt.md)** |\n| **HR \u0026 talent** | Screening | [Annex III(4)](https://artificialintelligenceact.eu/annex/3) | Escalation; audit |\n| **Education** | Grading | [Annex III(3)](https://artificialintelligenceact.eu/annex/3) | Roles; review · **[School Compass](docs/vision/scenarios/school-compass.md)** |\n| **Critical infrastructure** | Control suggestions | [Annex III(2)](https://artificialintelligenceact.eu/annex/3) | Dual-control patterns |\n| **Public benefits** | Eligibility | [Annex III(5)(a)](https://artificialintelligenceact.eu/annex/3) | Records; FRIA-aware design · **[Bürokratt Kit](docs/vision/scenarios/burokratt-kit.md)** |\n| **Law enforcement** | Case support | [Annex III(6)](https://artificialintelligenceact.eu/annex/3) | Sensitive; audit narrative only where appropriate |\n| **Migration \u0026 border** | Checks | [Annex III(7)](https://artificialintelligenceact.eu/annex/3) | High sensitivity |\n| **Political / civic** | Targeting | [Annex III(8)(b)](https://artificialintelligenceact.eu/annex/3); [GPAI — navigator](https://artificialintelligenceact.eu/section/4/) | Demo boundaries |\n| **Biometric / emotion** | Inference | [**Art. 5**](https://artificialintelligenceact.eu/article/5/) · [Annex III](https://artificialintelligenceact.eu/annex/3) | Default off; legal review |\n| **Citizen × AI (cross-cutting)** | Personal AI accountability | [Art. 14](https://artificialintelligenceact.eu/article/14/); [eIDAS 2.0](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183) | EUDI Wallet × EATF; Verifiable Credential receipt · **[Citizen Receipts](docs/vision/scenarios/citizen-receipts.md)** |\n\n---\n\n## Documentation\n\n| You are… | Start here |\n|----------|------------|\n| **User** | [Trust \u0026 demo](docs/README.md#users) |\n| **Developer** | [API \u0026 setup](docs/README.md#developers) |\n| **Partner** | [Integrations](docs/README.md#partners) |\n| **Delegation UI** | [Builder quick start](docs/features/delegation-builder.md#quick-start) |\n| **Research (Article 01 plan \u0026 bibliography)** | [docs/research/README.md](docs/research/README.md) |\n| **Reference scenarios (4)** | [OpenCourt](docs/vision/scenarios/opencourt.md) · [Bürokratt Kit](docs/vision/scenarios/burokratt-kit.md) · [School Compass](docs/vision/scenarios/school-compass.md) · [Citizen Receipts](docs/vision/scenarios/citizen-receipts.md) |\n| **Open Kratt manifest spec** | [docs/specs/kratt-manifest.md](docs/specs/kratt-manifest.md) · [JSON Schema](docs/specs/kratt-manifest.schema.json) |\n| **RIA / Bürokratt pilot pitch** | [docs/partners/ria-pilot.md](docs/partners/ria-pilot.md) |\n\nFull index: [docs/README.md](docs/README.md).\n\n---\n\n## Quick start\n\n```bash\ngit clone https://github.com/sapsan14/aletheia-ai.git \u0026\u0026 cd aletheia-ai\ncp .env.example .env\nopenssl genpkey -algorithm RSA -out ai.key -pkeyopt rsa_keygen_bits:4096\n# In .env set: AI_ALETHEIA_SIGNING_KEY_PATH=./ai.key\n```\n\n```bash\ncd backend \u0026\u0026 mvn spring-boot:run\n```\n\n```bash\ncd frontend \u0026\u0026 cp .env.example .env.local \u0026\u0026 npm install \u0026\u0026 npm run dev\n```\n\n- Backend: http://localhost:8080 (see `backend` config if your port differs)  \n- Frontend: http://localhost:3000  \n- Set `OPENAI_API_KEY` in `.env` for the AI demo. Set `NEXT_PUBLIC_API_URL` to your backend URL in `frontend/.env.local`.\n\nMore: [docs/README.md](docs/README.md) → Developers.\n\n---\n\n## Demo accounts (development mode)\n\n`demo@aletheia.ai` / `Demo123!` — **tenant-scoped ADMIN** on each of **demo-healthcare**, **demo-fintech**, **demo-legal** (one membership row per tenant). NOT SUPER_ADMIN — V208 migration intentionally downgraded this account because SUPER_ADMIN combined with X-Tenant-Id pivoting under the `demo` profile enabled cross-tenant access. See [`backend/.../db/seeding/DemoBaselineRecovery.java`](backend/src/main/java/ai/aletheia/db/seeding/DemoBaselineRecovery.java) and [`DemoBaselineRecoveryTest.java`](backend/src/test/java/ai/aletheia/db/seeding/DemoBaselineRecoveryTest.java) for the guard. Per-tenant admins: `admin@demo-{healthcare,fintech,legal}.local` / `Demo123!`. Full detail: [database seeding](docs/developers/en/database-seeding.md).\n\n---\n\n## License\n\nMIT. See [LICENSE](LICENSE). Authorship: [docs/README.md#authorship](docs/README.md#authorship).\n\n---\n\n*Validate legal URLs against your source of record. This README is the **canonical project pitch** for the repository.*\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsapsan14%2Faletheia-ai","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsapsan14%2Faletheia-ai","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsapsan14%2Faletheia-ai/lists"}