-
Notifications
You must be signed in to change notification settings - Fork 1
Project Overview
SecondLayer is a comprehensive Ukrainian legal tech platform operated by LLC "Lex AI" (TOV "Leks EiAi"). It provides AI-powered legal document analysis, semantic search over court decisions, legislation retrieval, business registry lookups, and ECHR practice search. The platform leverages a modular architecture based on the Model Context Protocol (MCP) to integrate diverse legal data sources.
The platform is structured as a TypeScript monorepo with multiple specialized MCP servers, a React-based web frontend, a Flutter mobile app, and shared packages. It serves legal professionals -- attorneys, law firms, and legal departments -- through a unified interface for AI-assisted legal research, document management, consultations, and billing.
| Capability | Description |
|---|---|
| AI Legal Analysis | Document analysis using Claude (AWS Bedrock) and OpenAI with hallucination guards |
| Court Decisions Search | Semantic, full-text, and hybrid search across Ukrainian court decisions (EDRSR) |
| Legislation | Full-text retrieval and article-level sectioning of Ukrainian legislation via Rada API |
| Business Registries | Entity search, beneficiary lookup, debtor registry (OpenReyestr / data.gov.ua) |
| ECHR Practice | European Court of Human Rights case law search (HUDOC) |
| Open Data Registries | Sanctions, corruption register, patents, trademarks, lawyers, judges, court experts, public spending, NBU banks, wage debtors, and more |
| Document Vault | Encrypted document storage with AI-powered analysis |
| Consultations | Client-attorney consultation management with E2E encryption and dispute resolution |
| Billing | Monobank payments, dual UAH/USD balance, B2B invoicing, referral program |
| OSINT | Credentials, ransomware victims, sanctions, Interpol, CVE, domain/IP reputation, corporate registries, media mentions |
| Procedural Tools | Deadline calculation, monetary claims, procedural checklists, norm search |
| Workflow Memory | Persistent cross-session memory for workflow continuity |
| Multi-platform | Web app (React 19) + Mobile app (Flutter) |
| Authentication | Google OAuth, Authentik (OIDC), Diia national digital identity, password, WebAuthn |
| Internationalization | Ukrainian (primary), English, Spanish locales with geo-based auto-detection |
| Spain Legal Tools | BOE legislation and AEPD data protection resolutions (experimental) |
SecondLayer uses a distributed architecture with multiple backend services orchestrated through an MCP-based unified gateway exposing 95+ tools.
All MCP servers support three transport modes:
- MCP stdio -- Standard MCP protocol for Claude Desktop / Cursor integration
-
HTTP API -- REST endpoints (
POST /api/tools/:toolName) for web/mobile apps - SSE -- Server-Sent Events streaming for long-running operations and remote MCP
| Component | Description |
|---|---|
mcp_backend |
Primary server -- court decisions, legislation, document analysis, vault, ECHR, legal acts, OSINT, procedural tools, workflows |
mcp_rada |
Parliament data -- deputies, bills, legislation texts, voting records |
mcp_openreyestr |
State registries -- business entities, beneficiaries, debtors |
lexwebapp |
Web frontend -- React 19, Vite 8, TailwindCSS, Zustand 5 |
mobile |
Mobile app -- Flutter |
packages/shared |
Shared TypeScript types, LLM managers, utilities |
services/edrsr-fulltext-worker |
Background worker for EDRSR full-text indexing (Python) |
services/opendata-importers |
Open data import workers |
opendata-sync |
Open data synchronization service |
platform |
Marketing/landing site |
deployment |
Docker Compose configs, Nginx, deploy scripts |
scripts |
Data import scripts (HUDOC, EDRSR, OpenData, RADA), utilities |
graph TD
User([User]) --> WebApp[lexwebapp - React 19]
User --> Mobile[Mobile - Flutter]
WebApp --> Nginx[Nginx Reverse Proxy]
Mobile --> Nginx
subgraph Backend[Backend Services]
Nginx --> MCPBack[mcp_backend :3000]
Nginx --> MCPRada[mcp_rada :3001]
Nginx --> MCPOpen[mcp_openreyestr :3005]
end
MCPBack --> PG[(PostgreSQL 15)]
MCPBack --> Qdrant[(Qdrant Vector DB)]
MCPBack --> Redis[(Redis 7)]
MCPBack --> Bedrock[AWS Bedrock / Claude]
MCPBack --> OpenAI[OpenAI API]
MCPBack --> RadaAPI[Rada API]
MCPRada --> RadaAPI
MCPOpen --> DataGov[data.gov.ua]
MCPBack --> Monobank[Monobank Payments]
MCPBack --> Diia[Diia Auth]
MCPBack --> Authentik[Authentik OIDC]
| Layer | Technology |
|---|---|
| Runtime | Node.js 20+, TypeScript 5.3-5.5 |
| AI | Anthropic Claude via AWS Bedrock (primary), OpenAI GPT-4o (fallback/embeddings) |
| Databases | PostgreSQL 15 (with PgBouncer), Redis 7, Qdrant (vectors) |
| Frontend | React 19, Vite 8, TailwindCSS 3, Zustand 5, TanStack Query 5 |
| Mobile | Flutter, Dart |
| Auth | Google OAuth, Authentik (OIDC), Diia, password, WebAuthn |
| Payments | Monobank acquiring (UAH/USD) |
| Infrastructure | Docker Compose, Nginx, Cloudflare |
| CI/CD | GitHub Actions, self-hosted runner, blue-green deploy |
| Framework | Express.js, MCP SDK (@modelcontextprotocol/sdk) |
| Environment | URL | Notes |
|---|---|---|
| Local | http://localhost:5173 |
Docker Compose with hot-reload |
| Production | https://legal.org.ua |
Blue-green deploy via CI/CD |
Note: There is no staging environment. Only local and production.
| Service | Purpose |
|---|---|
| QueryPlanner | Classifies user intent, selects optimal search strategy |
| EmbeddingService | Vector embeddings via OpenAI text-embedding-ada-002 |
| SemanticSectionizer | Breaks documents into logical articles/parts |
| HallucinationGuard | Prevents AI from generating unsupported claims |
| CitationValidator | Validates legal citations against source documents |
| LegislationService | Legislation text retrieval with intelligent sectioning |
| VaultService | Secure document storage and retrieval |
| CostTracker | Per-request API cost tracking (OpenAI, Bedrock, external APIs) |
| WorkflowMemoryService | Persistent cross-session workflow memory with push/pull sync |
| ModelSelector | Budget-aware model selection (quick/standard/deep) |
| ConsultationService | Client-attorney consultations with E2E encryption |
| DiiaService | Diia digital identity integration |
| AuthentikService | OIDC authentication via Authentik |
| OAuthService | Google OAuth handling |
| WebAuthnService | Passwordless authentication via WebAuthn |
The platform exposes 95+ tools across multiple categories:
- Court Decisions -- search, full-text retrieval, hybrid/semantic search, case patterns, party history (EDRSR)
- Legislation -- lookup, article-level section retrieval, monitoring for changes
- Document Analysis -- AI analysis, batch processing, classification, data analysis
- Vault -- encrypted storage, document management
- ECHR -- European Court of Human Rights practice search and retrieval
- Legal Acts -- regulatory acts, KMU resolutions, EDRNPA search
- Court Sessions -- schedule lookup, bulk ingestion
- Procedural -- deadline calculation, monetary claims, checklists, norm search, pro/contra practice comparison
- Legal Advice -- precedent search, citation graphs, similar reasoning, answer formatting
- Rada -- deputies, bills, legislation texts, voting records
- OpenReyestr -- business entities, beneficiaries, debtors, bankruptcy, enforcement proceedings
- Open Data -- judges, discipline, VKKS evaluations, invalid passports, terrorism list, NBU banks
- OSINT -- credentials, ransomware, sanctions, Interpol, World Bank debarment, CVE, IP/domain reputation, corporate registries, media, GitHub leaks
- Public Spending -- spending.gov.ua data search
- Spain -- BOE/AEPD Spanish legal data (experimental)
- Workflow Memory -- persistent memory, reconciliation, push sync
- Import Management -- import sources, start/status/cancel imports
- Nextcloud -- file upload and sharing
The platform maintains several legal documents:
- Terms of Use -- general platform usage terms
- Privacy Policy -- data handling and GDPR compliance
- Public Offer -- service agreement for end users
- Attorney Offer -- specific terms for attorneys using the platform
- Developer Offer -- contractor agreement for platform developers
- API Terms of Use -- terms for third-party developers building commercial SaaS on LEX AI API
- DPA -- Data Processing Agreement
- Marketplace Rules -- rules for the legal services marketplace
- AI Transparency -- disclosure of AI usage
- AI Usage Policy -- guidelines for AI-generated content
- Refund Policy -- payment refund terms
- AUP (Acceptable Use Policy) -- user consent tracking
Latest migration: 147_load_test_results.sql (147 migration files total). Key recent additions since the initial wiki page:
- Workflow sets, import tasks, session replay (105-110)
- ZakonOnline removal, GDPR user deletion (112-113)
- Video calls and consultation E2E encryption (115-121)
- Spain legal data expansion (126-138)
- Swiss data (SECO sanctions, Kantonsblatt, court decisions, legislation) (132-135)
- EU common legal data, offshore jurisdictions, Luxembourg (128-130)
- Tool pricing adjustments (107-108, 139)
- User beta testing, AUP consents, abuse reports (140-142)
- Workflow memory with push mode and reconciliation (144-146)
- Load test results (147)