{
  "schema": "provider-compliance.github-gold-mine.v1",
  "researchedAt": "2026-08-31",
  "status": "DISCOVERY_RESEARCH_ONLY",
  "sourceMethod": {
    "githubAuth": "Authenticated gh CLI REST/search session; token remained in local keyring and was not exposed",
    "evidence": ["repository metadata", "README/architecture files", "open issue receipts"],
    "baseCorpusBoundary": "Separate follow-up pass; does not alter the original 127 screened / 95 structured / 67 deep-profile counts"
  },
  "counts": {
    "curatedCandidates": 36,
    "bugReceipts": 23,
    "searchThemes": 20
  },
  "recommendation": {
    "godSourceBlueprint": "b1rdmania/legalise",
    "godSourceUrl": "https://github.com/b1rdmania/legalise",
    "deployment": "Owned VPS with custom Provider Compliance case authority; PostgreSQL, controlled object storage, bounded workers and audited model gateway",
    "bestSupplementaryProbes": [
      "Deodat-Lawson/LaunchStack",
      "NakliTechie/docket",
      "zealxz/regulated-workflow-demo",
      "dmitrykislov/temporal-document-approval-system",
      "JustVugg/judicex",
      "sure-scale/doc-haus",
      "ddickmann/latence",
      "CogniSwitch/KL4A",
      "dr3d/prethinker",
      "rajo69/ledgerkb",
      "YoursSarcastically/apply-for-me"
    ],
    "principle": "Borrow feature and worker patterns; never outsource case truth, evidence lineage, actor boundaries, approvals or restore semantics"
  },
  "candidates": [
    {"repo":"b1rdmania/legalise","url":"https://github.com/b1rdmania/legalise","stars":24,"license":"MIT","role":"whole-case blueprint","fit":5,"verdict":"god-source-blueprint","howItWorks":"Matter -> selected-source AI/skills -> citations -> named sign-off -> hash audit -> verifiable export","useFor":["synthetic whole-case spike","matter/document/audit translation"],"doNotUseAs":["live production dependency","proof that pgvector is needed"]},
    {"repo":"open-legal-products/mike","url":"https://github.com/open-legal-products/mike","stars":4167,"license":"AGPL-3.0","role":"legal workspace","fit":5,"verdict":"feature-reference","howItWorks":"Projects/matters -> document library -> assistant or reusable tabular-review workflow -> citation verification/Word edits","useFor":["document review UX","reusable skills","citation inspection"],"doNotUseAs":["case authority","unreviewed AGPL/Supabase/R2 fork"]},
    {"repo":"Deodat-Lawson/LaunchStack","url":"https://github.com/Deodat-Lawson/LaunchStack","stars":886,"license":"Apache-2.0","role":"AI application engine","fit":5,"verdict":"probe-substrate","howItWorks":"Ports-based engine -> host wires DB, storage, jobs, RAG and model providers -> worker processes ingestion","useFor":["ingestion/OCR/RAG/jobs","host/engine boundary"],"doNotUseAs":["published dependency yet","unreviewed external embeddings"]},
    {"repo":"NakliTechie/docket","url":"https://github.com/NakliTechie/docket","stars":0,"license":"AGPL-3.0","role":"sovereign case/portal","fit":5,"verdict":"pattern-probe","howItWorks":"Portal/email/API intake -> tenant-filtered case -> scoped staff/customer identity -> human-reviewed AI draft -> webhooks/hash audit/restore","useFor":["client portal","on-behalf-of API","audit and backup runbook"],"doNotUseAs":["Provider Compliance domain model","commercial base without AGPL review"]},
    {"repo":"zeweihan/aiworkdeck","url":"https://github.com/zeweihan/aiworkdeck","stars":79,"license":"AGPL-3.0","role":"legal document workspace","fit":5,"verdict":"feature-reference","howItWorks":"Project files -> local agent/MCP/plugins -> document editing/tracked changes -> tabular/due-diligence views -> activity/version records","useFor":["workspace UX","tracked review","plugin boundary"],"doNotUseAs":["cryptographic evidence source","unreviewed AGPL/commercial fork"]},
    {"repo":"AniketTati/draft-legal","url":"https://github.com/AniketTati/draft-legal","stars":14,"license":"AGPL-3.0","role":"contract lifecycle","fit":5,"verdict":"feature-benchmark","howItWorks":"React/Fastify/Prisma -> seven LangGraph agents -> pgvector+Elasticsearch RRF -> approvals/e-sign/obligations","useFor":["agent-per-lifecycle-step","hybrid retrieval","obligation views"],"doNotUseAs":["production default credentials","foundation without license/ops review"]},
    {"repo":"JustVugg/judicex","url":"https://github.com/JustVugg/judicex","stars":51,"license":"Apache-2.0","role":"evidence-grounded legal workspace","fit":5,"verdict":"conceptual-reference","howItWorks":"Versioned citable sources + non-citable operational notes -> fail-closed answer contract -> workflow packs -> local matter workspace","useFor":["authority taxonomy","abstain/limited answer states","workflow packs"],"doNotUseAs":["legal vocabulary unchanged","alpha SQLite production base"]},
    {"repo":"sure-scale/doc-haus","url":"https://github.com/sure-scale/doc-haus","stars":68,"license":"MIT","role":"local legal agent","fit":4,"verdict":"product-probe","howItWorks":"Private matter index -> routed Q&A/redline/research/draft agents -> cited answers or Word tracked changes -> templates/full review","useFor":["matter-private index","template scrubbing","redline UX"],"doNotUseAs":["unverified deployment dependency"]},
    {"repo":"lawflow-boop/LawLink","url":"https://github.com/lawflow-boop/LawLink","stars":86,"license":"MIT","role":"self-hosted case management","fit":4,"verdict":"case-flow-probe","howItWorks":"Intake -> conflict check -> formal case -> follow-up/finance -> archive/export on PostgreSQL/Prisma","useFor":["case states","archive/export","portal baseline"],"doNotUseAs":["mature workflow base"]},
    {"repo":"jamietso/Tabular_Review","url":"https://github.com/jamietso/Tabular_Review","stars":77,"license":"MIT","role":"bulk document review","fit":4,"verdict":"worker-ui-probe","howItWorks":"Docling converts files -> dynamic natural-language columns -> extracted cells -> source quote highlight -> analyst chat","useFor":["master-pack evidence grids","quote inspection"],"doNotUseAs":["case or approval authority"]},
    {"repo":"LexStack-AI/LexReviewer","url":"https://github.com/LexStack-AI/LexReviewer","stars":18,"license":"NOASSERTION","role":"citation-aware RAG","fit":4,"verdict":"citation-probe","howItWorks":"Unstructured chunks -> Qdrant + BM25 -> LangGraph tool selection -> streamed references/bounding boxes and linked-doc retrieval","useFor":["page-region citations","linked schedules/amendments"],"doNotUseAs":["tenant/case store","unreviewed third-party API path"]},
    {"repo":"zealxz/regulated-workflow-demo","url":"https://github.com/zealxz/regulated-workflow-demo","stars":0,"license":"MIT","role":"auditable extraction/diff","fit":5,"verdict":"fixture-pattern","howItWorks":"Local files -> canonical JSON -> evidence/change register -> review queue -> CSV/XLSX/Markdown + offline audit","useFor":["synthetic fixture","pending review queue","spreadsheet receipts"],"doNotUseAs":["OCR/production service"]},
    {"repo":"dmitrykislov/temporal-document-approval-system","url":"https://github.com/dmitrykislov/temporal-document-approval-system","stars":0,"license":"MIT","role":"durable approval","fit":4,"verdict":"durability-probe","howItWorks":"FastAPI submission -> Temporal workflow -> reviewer signal/reminder/escalation -> idempotent audit activity","useFor":["long waits","resume/escalation tests","idempotency"],"doNotUseAs":["first dependency before direct workers fail"]},
    {"repo":"s09870561-beep/document-intake-agent","url":"https://github.com/s09870561-beep/document-intake-agent","stars":0,"license":"NOASSERTION","role":"MCP intake harness","fit":5,"verdict":"synthetic-test-harness","howItWorks":"Classify -> extract -> anomaly flag -> schema validation -> pending approval -> n8n handoff","useFor":["adversarial intake fixtures","contract tests"],"doNotUseAs":["persistent production intake"]},
    {"repo":"BittnerPierre/AI-Agent-Casebook","url":"https://github.com/BittnerPierre/AI-Agent-Casebook","stars":15,"license":"Apache-2.0","role":"onboarding agent casebook","fit":4,"verdict":"learning-reference","howItWorks":"Customer onboarding ReAct/LangGraph/Agents SDK flows -> RAG -> evaluator and multi-provider model configuration","useFor":["onboarding prompt/eval shape","rejection path tests"],"doNotUseAs":["stable framework baseline"]},
    {"repo":"sharbelxyz/hermes-agent-mission-control","url":"https://github.com/sharbelxyz/hermes-agent-mission-control","stars":364,"license":"NOASSERTION","role":"agent control plane","fit":3,"verdict":"control-plane-pattern","howItWorks":"Next.js dashboard -> shared Postgres message bus -> bridge -> local agent; approval inbox, runs, memory and onboarding","useFor":["internal agent front door","approval inbox","run history"],"doNotUseAs":["client case authority"]},
    {"repo":"akashshrx/OpenSpecter","url":"https://github.com/akashshrx/OpenSpecter","stars":31,"license":"AGPL-3.0","role":"legal workspace","fit":4,"verdict":"feature-probe","howItWorks":"Projects -> versioned docs -> assistant/tabular workflows -> activity events with RLS content tables","useFor":["matter/document/workflow table comparison"],"doNotUseAs":["VPS foundation without replacing Supabase"]},
    {"repo":"el1ght/aulite","url":"https://github.com/el1ght/aulite","stars":128,"license":"BUSL-1.1","role":"AI compliance proxy","fit":3,"verdict":"safety-sidecar-probe","howItWorks":"OpenAI-compatible proxy -> deterministic policy rules/optional judge -> hash-chain SQLite audit -> PDF reports","useFor":["model egress logging","AI interaction risk rules"],"doNotUseAs":["business case audit","unreviewed licensing dependency"]},
    {"repo":"aayushus/ContractsPulse","url":"https://github.com/aayushus/ContractsPulse","stars":3,"license":"MIT","role":"contract cockpit","fit":3,"verdict":"ui-probe","howItWorks":"Svelte/FastAPI -> PDF ingestion -> risk scoring/redlines -> version verification/risk inbox/calendar","useFor":["risk inbox","version comparison"],"doNotUseAs":["default-deployment auth or model configuration"]},
    {"repo":"n8n-io/self-hosted-ai-starter-kit","url":"https://github.com/n8n-io/self-hosted-ai-starter-kit","stars":15219,"license":"Apache-2.0","role":"local AI sandbox","fit":2,"verdict":"poc-only","howItWorks":"Compose n8n + Ollama + Qdrant + PostgreSQL for local agent/RAG experiments","useFor":["VPS integration spike"],"doNotUseAs":["case authority","production architecture"]},
    {"repo":"itflow-org/itflow","url":"https://github.com/itflow-org/itflow","stars":993,"license":"GPL-3.0","role":"PSA/client portal","fit":3,"verdict":"portal-pattern","howItWorks":"Self-hosted PSA -> client/contact/vendor/document records -> tickets/billing/portal","useFor":["operations navigation","client portal concepts"],"doNotUseAs":["evidence/citation authority"]},
    {"repo":"b1rdmania/counsel-mvp","url":"https://github.com/b1rdmania/counsel-mvp","stars":1,"license":"NOASSERTION","role":"matter UX sketch","fit":4,"verdict":"module-probe","howItWorks":"Single matter workspace + persistent assistant -> research, litigation, timeline, letters and contract scanner modules","useFor":["module routing","persistent assistant UX"],"doNotUseAs":["production or multi-tenant base"]},
    {"repo":"ddickmann/latence","url":"https://github.com/ddickmann/latence","stars":11,"license":"Apache-2.0","role":"provenance RAG pipeline","fit":5,"verdict":"worker-probe","howItWorks":"Messy files -> typed stages/capability providers -> quarantine spoof/zip-bomb/oversized inputs -> PII-masked chunks, entities and cross-document edges -> Parquet corpus/graph/quality manifest","useFor":["offline ingestion","exact character/page provenance","PII quarantine","hybrid dense/BM25/KG retrieval"],"doNotUseAs":["case or approval authority","pre-1.0 production without fixture review"]},
    {"repo":"dr3d/prethinker","url":"https://github.com/dr3d/prethinker","stars":11,"license":"NOASSERTION","role":"governed knowledge compiler","fit":5,"verdict":"authority-research","howItWorks":"LLM proposes typed facts -> closed predicate/domain packs -> deterministic admission gates -> only approved facts become claim-bearing state","useFor":["anti-contamination gates","abstention boundaries","authority admission research"],"doNotUseAs":["general legal QA","product-ready parser or self-serve schema induction"]},
    {"repo":"CogniSwitch/KL4A","url":"https://github.com/CogniSwitch/KL4A","stars":7,"license":"Apache-2.0","role":"human-verified knowledge bundles","fit":5,"verdict":"knowledge-pack-probe","howItWorks":"PDF/DOCX/SOP -> obligation-shaped claims with exact byte spans -> approve/reject/edit events -> OKF bundle -> CLI/MCP agent access","useFor":["master-pack claim extraction","reviewed source spans","policy knowledge handoff"],"doNotUseAs":["tenant/case database","unreviewed verified truth"]},
    {"repo":"Detective-XH/DocGraph","url":"https://github.com/Detective-XH/DocGraph","stars":7,"license":"MIT","role":"document governance graph","fit":4,"verdict":"drift-probe","howItWorks":"Markdown/DOCX/HTML/PDF -> SQLite knowledge graph -> cross-reference, stale-policy, conflicting-claim and supersession audits","useFor":["source registry","edition/supersession drift checks","MCP read-only inspection"],"doNotUseAs":["business case authority","semantic search without tenant controls"]},
    {"repo":"rajo69/ledgerkb","url":"https://github.com/rajo69/ledgerkb","stars":6,"license":"Apache-2.0","role":"append-only evidence ledger","fit":5,"verdict":"ledger-probe","howItWorks":"Documents -> evidence-bearing assertions -> append-only position-over-time ledger -> RAG, graph, OKF wiki and change-report projections","useFor":["claim history","prompt-injection-aware retrieval","projection architecture"],"doNotUseAs":["unreviewed embedding service","replacement for case approvals"]},
    {"repo":"JustVugg/distillery","url":"https://github.com/JustVugg/distillery","stars":27,"license":"MIT","role":"grounded dataset builder","fit":4,"verdict":"eval-fixture-probe","howItWorks":"Documents -> grounded instruction examples -> quality filtering/deduplication -> provenance-carrying dataset artifacts","useFor":["synthetic onboarding/evidence evals","reproducible training fixtures"],"doNotUseAs":["live client corpus","automatic truth promotion"]},
    {"repo":"juanceresa/forensic_analysis_platform","url":"https://github.com/juanceresa/forensic_analysis_platform","stars":8,"license":"AGPL-3.0","role":"provenance-first investigation","fit":4,"verdict":"evidence-probe","howItWorks":"OCR -> entity/relation extraction -> knowledge graph -> analyst verification -> evidence-linked narrative","useFor":["chain-of-custody interaction","evidence-linked narrative review"],"doNotUseAs":["Provider Compliance domain model","AGPL base without licensing review"]},
    {"repo":"antonio0720/writing-intelligence","url":"https://github.com/antonio0720/writing-intelligence","stars":13,"license":"MIT","role":"exact-state document branches","fit":4,"verdict":"versioning-probe","howItWorks":"Branch a document -> simulate a change -> bind approval to the exact state read -> merge conflicts without inventing content","useFor":["approval-to-version binding","counterfactual review","offline verification"],"doNotUseAs":["document extraction engine","case authority"]},
    {"repo":"avelikiy/great_cto","url":"https://github.com/avelikiy/great_cto","stars":86,"license":"MIT","role":"human-gated autopilot","fit":3,"verdict":"control-pattern","howItWorks":"Intake -> gate:plan -> implementation/review/QA/security/devops -> gate:ship, with decisions and lessons memory","useFor":["agent stage gates","decision/lesson crystallisation"],"doNotUseAs":["regulated case workflow","evidence or client portal"]},
    {"repo":"alea-institute/alea-intake","url":"https://github.com/alea-institute/alea-intake","stars":2,"license":"MIT","role":"privacy-first legal intake","fit":4,"verdict":"intake-probe","howItWorks":"Privacy-first FastAPI/React legal-aid intake surface with structured applicant questions and hand-off","useFor":["minimum intake UX","data minimisation prompts"],"doNotUseAs":["Provider Compliance schema","production identity without review"]},
    {"repo":"redwoodmeridian/ep-legal-mcps","url":"https://github.com/redwoodmeridian/ep-legal-mcps","stars":3,"license":"MIT","role":"local CRM/intake MCP","fit":4,"verdict":"integration-probe","howItWorks":"Claude Code -> local MCP servers -> Lawmatics, DecisionVault and WealthCounsel CRM/client-intake/matter actions","useFor":["local connector pattern","explicit CRM action tools"],"doNotUseAs":["unreviewed client-data bridge","case authority"]},
    {"repo":"AptsNY/easydocs","url":"https://github.com/AptsNY/easydocs","stars":0,"license":"AGPL-3.0","role":"versioned Word document system","fit":4,"verdict":"document-version-probe","howItWorks":"Every save -> immutable version -> branch/merge/redline -> named approval -> client copy push-back review, with REST/MCP","useFor":["master-pack versioning","client review copy","redline/approval mechanics"],"doNotUseAs":["case/evidence authority","plain-HTTP deployment"]},
    {"repo":"YoursSarcastically/apply-for-me","url":"https://github.com/YoursSarcastically/apply-for-me","stars":17,"license":"MIT","role":"conservative application agent","fit":5,"verdict":"boundary-pattern","howItWorks":"One-time profile intake -> read full source posting -> verified field fill -> park unknowns/legal declarations -> human dashboard -> read-back submission/outcome ledger","useFor":["never-guess intake","missing-field dashboard","human declaration gates","crash-safe write-ahead state"],"doNotUseAs":["browser automation for Harrison","regulatory evidence or client case storage"]},
    {"repo":"dungnotnull/digital-forensics-process-support-agent-skill","url":"https://github.com/dungnotnull/digital-forensics-process-support-agent-skill","stars":4,"license":"MIT","role":"evidence audit harness","fit":4,"verdict":"audit-probe","howItWorks":"Crawl/inspect evidence -> evaluate integrity, chain of custody and admissibility controls against NIST/ISO 27037","useFor":["audit acceptance fixtures","chain-of-custody checks"],"doNotUseAs":["legal conclusion engine","automatic admissibility decision"]}
  ],
  "bugSweep": [
    {"repo":"b1rdmania/legalise","issue":245,"url":"https://github.com/b1rdmania/legalise/issues/245","severity":"high","finding":"pgvector is not load-bearing in the evaluation release","response":"Prove retrieval need before adding vector infrastructure"},
    {"repo":"b1rdmania/legalise","issue":9,"url":"https://github.com/b1rdmania/legalise/issues/9","severity":"high","finding":"live-matter readiness gates remain open","response":"Convert WORM/export/deletion/jobs/runbook requirements into acceptance tests"},
    {"repo":"b1rdmania/legalise","issue":241,"url":"https://github.com/b1rdmania/legalise/issues/241","severity":"medium","finding":"Ed25519/external audit anchoring deferred","response":"Define checkpoint/key custody before claiming immutable audit"},
    {"repo":"open-legal-products/mike","issue":391,"url":"https://github.com/open-legal-products/mike/issues/391","severity":"high","finding":"meaning-inverting ellipsis can pass citation verification","response":"Validate exact spans/anchors and preserve excerpts"},
    {"repo":"open-legal-products/mike","issue":8,"url":"https://github.com/open-legal-products/mike/issues/8","severity":"high","finding":"large upload 524 timeouts misdiagnosed as CORS","response":"Resumable bounded ingestion jobs with receipts"},
    {"repo":"Deodat-Lawson/LaunchStack","issue":313,"url":"https://github.com/Deodat-Lawson/LaunchStack/issues/313","severity":"high","finding":"document deletion orphans storage objects","response":"Reconciled two-phase deletion and restore test"},
    {"repo":"Deodat-Lawson/LaunchStack","issue":365,"url":"https://github.com/Deodat-Lawson/LaunchStack/issues/365","severity":"high","finding":"embeddings path sends full document text to third-party API","response":"Explicit per-job egress posture and local embeddings option"},
    {"repo":"Deodat-Lawson/LaunchStack","issue":335,"url":"https://github.com/Deodat-Lawson/LaunchStack/issues/335","severity":"medium","finding":"optional Zod fields fail native JSON schema mode","response":"Strict contracts plus deterministic repair/fallback"},
    {"repo":"nocobase/nocobase","issue":10416,"url":"https://github.com/nocobase/nocobase/issues/10416","severity":"high","finding":"stored XSS via rich-text API bypass","response":"Adversarial sanitization and no direct client-content exposure"},
    {"repo":"directus/directus","issue":28161,"url":"https://github.com/directus/directus/issues/28161","severity":"high","finding":"bulk comments can bypass authenticated-user requirement","response":"Narrow domain API with actor checks"},
    {"repo":"langgenius/dify","issue":41534,"url":"https://github.com/langgenius/dify/issues/41534","severity":"high","finding":"Swagger-tool agent can make unauthorized calls","response":"Gateway allowlists, scoped credentials and approval"},
    {"repo":"n8n-io/n8n","issue":37360,"url":"https://github.com/n8n-io/n8n/issues/37360","severity":"high","finding":"personal agent can hang indefinitely","response":"Lease, heartbeat, deadline and visible terminal state"},
    {"repo":"n8n-io/n8n","issue":37377,"url":"https://github.com/n8n-io/n8n/issues/37377","severity":"medium","finding":"MCP execute_workflow schema differs from runtime","response":"Pinned connector contract tests"},
    {"repo":"topoteretes/cognee","issue":4839,"url":"https://github.com/topoteretes/cognee/issues/4839","severity":"critical","finding":"WHERE clause drop can ingest whole table silently","response":"Tenant filter at DB boundary plus negative fixtures"},
    {"repo":"topoteretes/cognee","issue":4673,"url":"https://github.com/topoteretes/cognee/issues/4673","severity":"high","finding":"cloud add/search endpoints hang","response":"Deadlines, circuit breaker and local fallback"},
    {"repo":"langchain-ai/agent-inbox","issue":38,"url":"https://github.com/langchain-ai/agent-inbox/issues/38","severity":"high","finding":"resumption fails without checkpoint ID","response":"Durable case/job/version IDs"},
    {"repo":"langchain-ai/agent-inbox","issue":84,"url":"https://github.com/langchain-ai/agent-inbox/issues/84","severity":"high","finding":"no authentication surface","response":"Keep identity in application"},
    {"repo":"zeweihan/aiworkdeck","issue":200,"url":"https://github.com/zeweihan/aiworkdeck/issues/200","severity":"medium","finding":"load-sensitive e2e login truncates credentials","response":"Input assertion/retry at test boundary"},
    {"repo":"lawflow-boop/LawLink","issue":11,"url":"https://github.com/lawflow-boop/LawLink/issues/11","severity":"high","finding":"case-stage selection invalidates cause and blocks submission","response":"Server-side state-transition validation"},
    {"repo":"BittnerPierre/AI-Agent-Casebook","issue":141,"url":"https://github.com/BittnerPierre/AI-Agent-Casebook/issues/141","severity":"high","finding":"large PDF indexing fails under embedding rate limits","response":"Queue/chunk/rate-limit and partial-index receipts"},
    {"repo":"BittnerPierre/AI-Agent-Casebook","issue":134,"url":"https://github.com/BittnerPierre/AI-Agent-Casebook/issues/134","severity":"high","finding":"onboarding tool called with empty required fields","response":"Fail-closed tool contracts and missing-fact prompts"},
    {"repo":"BittnerPierre/AI-Agent-Casebook","issue":138,"url":"https://github.com/BittnerPierre/AI-Agent-Casebook/issues/138","severity":"high","finding":"rejected plan crashes supervisor","response":"Rejected-plan state with explicit next action"},
    {"repo":"rajo69/ledgerkb","issue":13,"url":"https://github.com/rajo69/ledgerkb/issues/13","severity":"medium","finding":"embeddings config docs disagree with code and doctor false-positives before first index; named reindex remedy does not exist","response":"Make config transitions truthful, fail closed on actual state, and test operator repair commands"}
  ],
  "acceptanceGate": ["source/license/release review", "synthetic-only probe", "negative tenant/case filter test", "source anchor and supersession test", "pending/approval/rejection resume test", "upload/delete/restore receipts", "model egress and connector contract pinning"]
}
