AI finds the risk. LexProof proves what happened.
Judge login (read-only, changes disabled): https://www.lexproofsolutions.com/login with [email protected] / [password]
No-login demo: https://www.lexproofsolutions.com/public-verify/tamper
Executive briefing
The market friction
Legal and procurement teams now use AI to review contracts, but AI output leaves no proof. When a finding, a redline or an approval is questioned months later, by an auditor, a regulator, a counterparty or a court, the only record is an audit log inside the vendor's own system. The team has to say "trust our database." Meanwhile, AI review raises a governance question every General Counsel and CPO now faces: who approved what the AI suggested, and can we show the record wasn't changed afterwards?
The solution
LexProof is a SaaS platform for verifiable contract operations:
- AI review: Gemini analyses each contract against a review policy and produces findings and proposed redlines. Scanned PDFs are handled with OCR.
- Enforced human approval: nothing changes until a different person approves. Separation of duties is enforced on the server and applies to admins too; break-glass needs a written reason and is recorded.
- Legal Passport: each contract gets one record combining the contract, policy, AI analysis, human decisions and evidence, sealed with a SHA-256 fingerprint.
- Independent verification: the fingerprint is anchored on a public blockchain (Ethereum Sepolia today). Anyone can re-check it in their own browser, with no login and without trusting LexProof's servers. Change one character and the verdict flips from VERIFIED to ROOT MISMATCH in under a second.
- Continuous monitoring: a Chainlink CRE workflow re-checks stored evidence against the on-chain anchors every 10 minutes and flags any mismatch (demonstrated in CRE simulation against the live API).
Also included: Ask Lexi (an assistant that answers only from verified findings, with citations), a counterparty review portal with no account needed, a Board Report, and an exportable evidence pack.
The architecture
- Frontend: Next.js + TypeScript on Vercel.
- API: Python FastAPI on Google Cloud Run (us-central1), keyless service-account auth, secrets in Secret Manager.
- Data: Firebase Auth + Firestore; multi-tenant organisations with membership-based roles (admin, contract owner, reviewer, approver, auditor). Full data model in the README.
- AI: Google Gemini via Vertex AI; review policies versioned and included in the sealed record.
- Proof layer: Solidity registries (OpenZeppelin 5), source-verified on Etherscan. Only 32-byte fingerprints go on chain, never contract text or personal data.
- Monitoring: Chainlink CRE workflow (TypeScript SDK).
- Quality: 1,000+ backend tests passing, Playwright end-to-end tests, read-only judge account enforced server-side.
Security and governance by design: tenant isolation, role checks on every endpoint, server-enforced separation of duties, audit trail, read-only accounts, no contract data on chain, and a visible "not legal advice" disclaimer.
The target cohort
- Primary: in-house legal and procurement teams at mid-market and enterprise companies (50–5,000 employees) that review supplier and customer contracts at volume and answer to auditors or boards.
- Secondary: law firms and outside counsel who need to show clients exactly what was reviewed and approved.
- Wedge: procurement teams running SAP Ariba, Coupa or a CLM. LexProof sits beside those systems as a trust layer, not a replacement (integrations on the roadmap). The founder brings 25+ years of SAP Ariba and source-to-pay experience to this segment.
Monetization (fiscal architecture)
Model: per-workspace, multi-tier subscription with a monthly contract allowance, plus metered overage. Blockchain anchoring costs are included, so customers never hold or handle crypto.
| Plan | Price | Includes |
|---|---|---|
| Public Verify | Free | Anyone can verify a passport (drives adoption: every counterparty and auditor who verifies sees LexProof) |
| Trial | Free, 14 days | 10 contracts, 2 users |
| Starter | $149/mo ($119/mo billed yearly) | 3 users, 30 contracts/mo |
| Team | $499/mo ($399/mo billed yearly) | 10 users, 150 contracts/mo, approval workflows, RBAC, anchor monitoring |
| Enterprise | from $1,500/mo | Unlimited users, 1,000+ contracts/mo, SSO, custom review playbooks, mainnet option, SLA |
- Overage: $2 per extra contract (Starter), $1.50 (Team).
- Design partners: 40% off year one in exchange for a case study.
- Unit economics: estimated AI cost is about $0.30 per contract (to be validated from Cloud Billing during pilots), so even at full Starter usage the AI cost is roughly $9 of a $149 plan. Anchoring is batched: one on-chain transaction can cover many fingerprints.
- Growth loop: the free public verifier is shared with every counterparty, auditor and board member who checks a passport, each one a potential buyer.
- Expansion revenue: contract volume grows into higher tiers; Enterprise adds SSO, playbooks and integrations.
How we built it
Solo build, started 27 August 2026. FastAPI backend and Next.js frontend developed in parallel, with the proof layer (fingerprints, registries, public verifier) designed first so every later feature produces verifiable evidence. Deployed to Vercel and Google Cloud Run; contracts deployed and source-verified on Sepolia; Chainlink CRE workflow simulated against the live production API (5 of 5 items verified) and a tamper drill (mismatch detected, alert raised).
Challenges
- Making verification truly independent: the browser recomputes the fingerprint and reads the chain directly instead of asking our API "is this valid?"
- Enforcing separation of duties on the server, including for admins, without making approvals painful.
- Keeping AI output stable enough to seal: policies and analysis are versioned so the sealed record is reproducible.
Accomplishments
- A live, public Tamper Test that anyone can run in seconds.
- Enforced human approval with a full audit trail.
- 1,000+ automated backend tests and a read-only judge account.
What we learned
Buyers don't want "blockchain"; they want to be able to show an auditor that nothing changed. Hiding the chain behind a plain VERIFIED / ROOT MISMATCH verdict, with no wallets or tokens for users, is what makes it usable.
What's next
Design-partner pilots with procurement and legal teams; passkey-signed approvals; mainnet or L2 anchoring through a gas-sponsoring relayer; live Chainlink CRE deployment with alerting; SAP Ariba and Coupa integrations; Stripe billing.
Honest limitations
Anchoring runs on the Ethereum Sepolia testnet during the hackathon. "Tamper-evident" means any change is detectable, not that changes are impossible. LexProof provides AI-assisted analysis for information only, not legal advice.
Log in or sign up for Devpost to join the conversation.