Inspiration

Modern enterprise teams face a double-edged sword: critical technical knowledge is trapped inside isolated departmental silos, yet legal and security teams are rightly terrified of data leakage from commercial LLM APIs. Furthermore, as documentation evolves across cross-functional teams, employees struggle to verify whether internal guides have been altered or compromised.

We built Alexandria to resolve this tension. Named after the ancient library, Alexandria is designed as a secure, zero-trust knowledge architecture that satisfies strict corporate security policies while unlocking AI productivity by offering zero data leakage, dynamic Role-Based Access Control (RBAC), and immutable cryptographic document verification.

What it does

Alexandria eliminates internal data silos by combining privacy-first AI search with blockchain-backed document governance.

  • Departmental Routing & Silo Elimination: Employees ask questions through a Next.js chat interface, which routes unanswered queries to the relevant departmental channel (e.g., #engineering-discrepancies). When a team member responds, Alexandria ingests the resolved Q&A back into the vector store, so the AI continuously learns from internal knowledge exchange.

  • Role-Based RAG (RBAC Filtering): Authenticated via Microsoft Entra ID or Auth0 JWT tokens, every query passes through a privilege filter before retrieval, so restricted content never reaches the model's context window:

    • Developer Role: Surfaces raw API endpoints, git commits, and technical specifications. $$\text{Context} \leftarrow \text{Filter}(\text{VectorStore},\ \text{Role} = \text{Senior Eng})$$
    • Support Rep Role: Excludes internal code and returns only customer-approved playbooks. $$\text{Context} \leftarrow \text{Filter}(\text{VectorStore},\ \text{Role} = \text{Support Rep})$$
  • Zero Data Leakage: Inference runs on local models (Llama 3 or Mistral via Ollama) or inside Azure Confidential Containers, so raw documents never leave the enterprise virtual private cloud (VPC).

  • Cryptographic Tamper Detection: When a senior employee approves a document update, Alexandria computes a SHA-256 hash binding the content to its author and approval time: $$H = \mathrm{SHA256}\left(\text{Document Content} \parallel \text{Author ID} \parallel \text{Timestamp}\right)$$

This hash is anchored on Solana Devnet. During LLM generation, Alexandria recomputes Current_Hash and compares it against the on-chain Solana_Hash. If Current_Hash ≠ Solana_Hash, the response is flagged with a "Tamper / Unverified Source" warning.

How we built it

  • Frontend UI: Next.js and Tailwind CSS providing real-time channel pings, role switching, and dynamic blockchain audit logs.
  • Core Backend & RBAC: Python FastAPI hosted on Azure App Service, validating JWT privilege levels from Microsoft Entra ID / Auth0.
  • Private Vector Search & AI Engine: ChromaDB / Azure AI Search for vector embeddings, connected to Ollama (Llama 3 8B / Mistral 7B) running locally or in Azure Confidential Compute.
  • On-Chain Audit Ledger: An Anchor smart contract deployed on Solana Devnet (@solana/web3.js) to record and verify 32-byte document hashes asynchronously.

Challenges we ran into

  • Dynamic RBAC Vector Filtering: Executing dynamic post- and pre-filtering based on token permissions without increasing vector retrieval latency required fine-tuning our FastAPI middleware pipeline.
  • Asynchronous Web2 / Web3 Integration: Validating SHA-256 hashes against Solana state accounts without delaying the initial stream of LLM tokens required decoupling the cryptographic verification pipeline into worker threads.
  • Confidential Environment Parity: Setting up local Ollama models while building Azure Confidential Container manifests for enterprise production required careful memory and hardware optimization.

Accomplishments that we're proud of

  • Zero-Trust AI Architecture: Built an end-to-end system on 100% free or hackathon-tier stacks that proves enterprise AI does not have to choose between privacy and utility.
  • Immutable Document Provenance: Successfully integrated Solana Devnet as a zero-cost cryptographic audit layer for internal enterprise documents.
  • Contextual Safety: Engineered seamless role-based filtering so support representatives and senior engineers automatically receive distinct, security-appropriate RAG context from the same knowledge base.

What we learned

  • Security Interposition in RAG: Placing token-authorization layers directly between vector retrieval and context injection is essential for zero-trust enterprise AI.
  • O(1) Blockchain Utility: Storing lightweight SHA-256 hashes rather than full raw text on-chain provides maximal cryptographic verification with minimal transaction costs and low latency.
  • Open-Source Model Sovereignty: Local 7B/8B parameter models running inside confidential boundaries deliver enterprise-grade performance without third-party API exposure.

What's next for Alexandria

  • Automated Peer Review Workflows: Allowing junior engineers to propose doc edits directly within the UI, triggering multi-signature Solana transactions upon senior approval.
  • Cross-Cloud Confidential Compute: Expanding Azure Confidential Container deployment templates to AWS Nitro Enclaves and GCP Confidential VMs.
  • Automated Audit Reports: Generating compliance-ready PDF reports verifying that all enterprise AI responses were derived from cryptographically unaltered documentation.

Built With

Share this project:

Updates

Submission history