Inspiration
Modern enterprise teams face a double-edged sword: critical technical knowledge is trapped inside isolated departmental silos, yet legal and security teams are rightly terrified of data leakage from commercial LLM APIs. Furthermore, as documentation evolves across cross-functional teams, employees struggle to verify whether internal guides have been altered or compromised.
We built Alexandria to resolve this tension. Named after the ancient library, Alexandria is designed as a secure, zero-trust knowledge architecture that satisfies strict corporate security policies while unlocking AI productivity by offering zero data leakage, dynamic Role-Based Access Control (RBAC), and immutable cryptographic document verification.
What it does
Alexandria eliminates internal data silos by combining privacy-first AI search with blockchain-backed document governance.
Departmental Routing & Silo Elimination: Employees ask questions through a Next.js chat interface, which routes unanswered queries to the relevant departmental channel (e.g.,
#engineering-discrepancies). When a team member responds, Alexandria ingests the resolved Q&A back into the vector store, so the AI continuously learns from internal knowledge exchange.Role-Based RAG (RBAC Filtering): Authenticated via Microsoft Entra ID or Auth0 JWT tokens, every query passes through a privilege filter before retrieval, so restricted content never reaches the model's context window:
- Developer Role: Surfaces raw API endpoints, git commits, and technical specifications. $$\text{Context} \leftarrow \text{Filter}(\text{VectorStore},\ \text{Role} = \text{Senior Eng})$$
- Support Rep Role: Excludes internal code and returns only customer-approved playbooks. $$\text{Context} \leftarrow \text{Filter}(\text{VectorStore},\ \text{Role} = \text{Support Rep})$$
Zero Data Leakage: Inference runs on local models (Llama 3 or Mistral via Ollama) or inside Azure Confidential Containers, so raw documents never leave the enterprise virtual private cloud (VPC).
Cryptographic Tamper Detection: When a senior employee approves a document update, Alexandria computes a SHA-256 hash binding the content to its author and approval time: $$H = \mathrm{SHA256}\left(\text{Document Content} \parallel \text{Author ID} \parallel \text{Timestamp}\right)$$
This hash is anchored on Solana Devnet. During LLM generation, Alexandria recomputes Current_Hash and compares it against the on-chain Solana_Hash. If Current_Hash ≠ Solana_Hash, the response is flagged with a "Tamper / Unverified Source" warning.
How we built it
- Frontend UI: Next.js and Tailwind CSS providing real-time channel pings, role switching, and dynamic blockchain audit logs.
- Core Backend & RBAC: Python FastAPI hosted on Azure App Service, validating JWT privilege levels from Microsoft Entra ID / Auth0.
- Private Vector Search & AI Engine: ChromaDB / Azure AI Search for vector embeddings, connected to Ollama (Llama 3 8B / Mistral 7B) running locally or in Azure Confidential Compute.
- On-Chain Audit Ledger: An Anchor smart contract deployed on Solana Devnet (@solana/web3.js) to record and verify 32-byte document hashes asynchronously.
Challenges we ran into
- Dynamic RBAC Vector Filtering: Executing dynamic post- and pre-filtering based on token permissions without increasing vector retrieval latency required fine-tuning our FastAPI middleware pipeline.
- Asynchronous Web2 / Web3 Integration: Validating SHA-256 hashes against Solana state accounts without delaying the initial stream of LLM tokens required decoupling the cryptographic verification pipeline into worker threads.
- Confidential Environment Parity: Setting up local Ollama models while building Azure Confidential Container manifests for enterprise production required careful memory and hardware optimization.
Accomplishments that we're proud of
- Zero-Trust AI Architecture: Built an end-to-end system on 100% free or hackathon-tier stacks that proves enterprise AI does not have to choose between privacy and utility.
- Immutable Document Provenance: Successfully integrated Solana Devnet as a zero-cost cryptographic audit layer for internal enterprise documents.
- Contextual Safety: Engineered seamless role-based filtering so support representatives and senior engineers automatically receive distinct, security-appropriate RAG context from the same knowledge base.
What we learned
- Security Interposition in RAG: Placing token-authorization layers directly between vector retrieval and context injection is essential for zero-trust enterprise AI.
- O(1) Blockchain Utility: Storing lightweight SHA-256 hashes rather than full raw text on-chain provides maximal cryptographic verification with minimal transaction costs and low latency.
- Open-Source Model Sovereignty: Local 7B/8B parameter models running inside confidential boundaries deliver enterprise-grade performance without third-party API exposure.
What's next for Alexandria
- Automated Peer Review Workflows: Allowing junior engineers to propose doc edits directly within the UI, triggering multi-signature Solana transactions upon senior approval.
- Cross-Cloud Confidential Compute: Expanding Azure Confidential Container deployment templates to AWS Nitro Enclaves and GCP Confidential VMs.
- Automated Audit Reports: Generating compliance-ready PDF reports verifying that all enterprise AI responses were derived from cryptographically unaltered documentation.

Log in or sign up for Devpost to join the conversation.