VerityAI is a secure, citation-first enterprise knowledge platform. Organizations can ingest private documents, search their knowledge base, and receive grounded answers with an auditable evidence trail.
- FastAPI application with versioned routes and OpenAPI documentation
- organization-aware user model and role-based access control
- secure password hashing and short-lived JWT access tokens
- PDF, DOCX, TXT, and Markdown ingestion with safe tenant storage
- text extraction, overlapping chunks, ranked retrieval, and page-level citations
- evidence-only answers with explicit refusal when support is absent
- polished responsive React workspace for onboarding, uploads, questions, sources, people, collections, settings, and audit activity
- collection curation, pending teammate invitations, profile management, organization settings, and password rotation
- global document and evidence search with safe destructive-action confirmations
- organization-scoped audit trail
- PostgreSQL/pgvector production persistence and SQLite zero-setup development
- Alembic migrations, health/readiness endpoints, CORS, request IDs, and security headers
- Docker Compose deployment with PostgreSQL, Redis, FastAPI, Nginx, and React
- CI quality gates for linting, tests, coverage, and frontend builds
docker compose up --buildOpen http://localhost:8080. The API documentation is available at http://localhost:8000/docs.
The Compose defaults are intended only for local development. Copy .env.example to .env and replace credentials before using a shared or production environment.
cd backend
python -m venv .venv
.venv\Scripts\Activate.ps1
pip install -e ".[dev]"
Copy-Item ..\.env.example ..\.env
uvicorn app.main:app --reloadIn a second terminal:
cd frontend
npm install
npm run devOpen http://localhost:5173 and use http://localhost:8000/docs for the API.
cd backend
pytest
cd ../frontend
npm run lint
npm testcd backend
ruff check app tests
ruff format --check app tests alembic
pytest --cov=app --cov-fail-under=85
cd ../frontend
npm run build
cd ..
docker compose config --quiet
docker compose build backend frontendBrowser -> Nginx/React -> FastAPI -> PostgreSQL + pgvector
| -> tenant file storage
+ -> Redis (background-work foundation)
The local answer provider is intentionally deterministic and extractive: it proves retrieval, authorization, citation, and refusal behavior without requiring a paid API key. The provider boundary is designed for a later grounded LLM generator while preserving the same evidence contract.
backend/ FastAPI API, persistence, migrations, and tests
frontend/ React/Vite product interface and client tests
docs/ Architecture, security, evaluation, and demo material
.github/ GitHub Actions quality gates
VerityAI is a portfolio-grade reference implementation, not a certified production security product. Review SECURITY.md and docs/security.md before any public deployment. Never commit .env, uploaded documents, access tokens, or real company data.
- pgvector embeddings and PostgreSQL full-text hybrid retrieval
- queued ingestion workers and object storage
- configurable grounded LLM providers and answer streaming
- versioned evaluation datasets and an evaluation dashboard
- invitation acceptance/email delivery, collection-level permissions, SSO, and SCIM
- malware scanning, distributed rate limits, and production observability
See architecture, security, and evaluation for the engineering decisions and release standards.
See CONTRIBUTING.md for the local workflow and quality gates. This project is available under the MIT License.