-
-
LexGuard: AI contract risk analysis built in Rust. Argon2id hashing, SHA-256 sessions, per-IP rate limiting.
-
Registration enforces 12+ char passwords, rejects duplicate emails, hashes with Argon2id before first write.
-
Fresh account, zero data. Clean dashboard state — proves onboarding works without seeded or fake data.
-
Live dashboard: 3 contracts, 2 pending reminders, 3 AI analyses, aggregated from Postgres in real time.
-
Contract list never leaks raw_text or other users' data. Ownership is enforced in SQL, not just the UI.
-
Reminders follow a 7/3/1/0-day schedule per obligation. Regeneration is idempotent, no duplicate spam.
-
Discord channel connected. Webhook secrets are encrypted at rest with ChaCha20-Poly1305, never logged.
-
Profile is read-only by design. No endpoint ever exposes another user's ID, email, or contract data.
-
Sessions are opaque tokens hashed with SHA-256 server-side. Logout revokes the session, not just the cookie.
-
Mutual Service Agreement: 0/100 Low. The AI reports "no material risks found," not a false "this is safe."
-
Consulting Agreement: 70/100 High. Three named risks, each traced back to the exact clause that caused it.
-
Every risk quotes real contract text, fuzzy-matched against the source to catch AI hallucination before it ships.
-
Employment Agreement: 90/100 Critical, 11 risks. Same Groq model, same prompt, genuinely different verdict.
-
Top risk: a 50-year global non-compete, scored 90/100 Critical, with the exact clause quoted as evidence.
Inspiration
Contracts hide critical deadlines and one-sided clauses in dense legal language. Missing a termination notice or an unfavorable liability clause can cost real money — but most people and small businesses can't afford a lawyer to review every agreement. We wanted an AI tool that flags risky clauses with evidence, not just a vague "this looks risky."
What it does
LexGuard lets you upload a contract (paste text, PDF, or a photo via OCR) and automatically:
- Detects and scores risks (e.g. asymmetric liability caps, one-sided termination notice, unilateral amendment rights)
- Extracts obligations with responsible party and due dates
- Backs every finding with an exact quote from the contract as evidence
- Schedules automated reminders (7/3/1/0 days before deadlines) delivered via Discord/webhooks
How we built it
- Backend: Rust + Axum, PostgreSQL with SQLx migrations
- Frontend: Leptos compiled to WebAssembly
- AI: OpenAI-compatible chat completion (served via Groq) for contract analysis
- Security: Argon2id password hashing, opaque session tokens, ChaCha20-Poly1305 encrypted webhook credentials, SSRF protection on outbound webhooks
- A background worker handles reminder delivery with retries and crash recovery
- Fully containerized with Docker, 333+ automated tests
AI disclosure
Two separate uses of AI here: the app itself uses AI at runtime (an OpenAI-compatible provider — Groq/OpenAI/Gemini — for contract risk analysis and image OCR, described above). Separately, as the developer, I used Gemini and DeepSeek for coding assistance and Claude for code review, security hardening, and architectural feedback while building this solo in 8 days. All architecture, integration, testing, and final review were mine. Full day-by-day disclosure: DEVELOPMENT_PROCESS.md.
Challenges we ran into
LLM outputs are non-deterministic — the same contract could get slightly different risk scores across runs. We built a fuzzy evidence-verification system that checks AI-cited evidence against the original contract text (exact match or 70% token overlap) to catch hallucinated citations before showing them to the user.
What we learned
Building trust into AI outputs matters more than raw accuracy — surfacing verifiable evidence for every claim, and being transparent about known limitations, is what makes an AI legal tool usable.
What's next
Jurisdiction-aware analysis, contract-type-specific risk models, and support for more AI providers.
Built With
- api
- argon2id
- axum
- chacha20-poly1305
- discord
- docker
- groq
- leptos
- openai
- postgresql
- rust
- sqlx
- webassembly
- webhook
Log in or sign up for Devpost to join the conversation.