💡 Inspiration Corporate legal teams are drowning in administrative overhead. Every day, highly trained professionals spend hours manually reviewing 50-page third-party vendor contracts just to verify standard clauses like Governing Law, Liability Caps, and Indemnification. This manual review creates massive bottlenecks and introduces the risk of human error when checking third-party paper against internal company playbooks.
I built The Contract Playbook Deviation Auditor to completely automate this workflow. I wanted to prove that by combining the cognitive reasoning of LLMs with a deterministic rules engine, legal review can be instantaneous, scalable, and fully automated.
🛠️ How we built it The application is a fully decoupled, cloud-native architecture designed for speed and scalability:
The AI Engine (Extraction): When a user uploads a PDF, the backend uses UglyToad.PdfPig to extract the raw text. It then calls the native Google Gemini 2.5 Flash REST API using a highly specific prompt to parse the unstructured legal language into strict JSON data points.
The Rules Engine (Evaluation): The extracted JSON is passed into a .NET 8 Minimal API backend. Instead of relying on AI to make the final compliance decisions (which risks hallucination), the C# backend evaluates the extracted clauses deterministically against a hardcoded SQLite database containing the corporate playbook rules.
The Frontend (Presentation): The user interacts with a sleek, responsive React + Vite dashboard styled with Tailwind CSS, which displays the final risk scorecard.
Deployment: The backend is containerized via Docker and hosted on Render, while the frontend is deployed on Vercel via edge networks.
🚧 Challenges we ran into Building a production-ready cloud application in a hackathon weekend presented several major hurdles:
Cloud Database Costs & Complexity: Initially, I designed the backend around SQL Server. However, realizing the high cost and complexity of hosting SQL Server in the cloud for a free hackathon demo, I pivoted the architecture entirely to SQLite. This allowed the database to be generated dynamically on startup within the container, making the app 100% ephemeral and free to host.
Docker File Permissions: Deploying to Render introduced severe UnauthorizedAccessException crashes because Render runs containers as a restricted app user, while my SQLite database needed write access. I had to rewrite the Dockerfile and adjust the local folder mounting permissions to secure the deployment.
AI Provider Traffic Spikes: During testing, the API crashed with a 503 Service Unavailable error because the Gemini 3.6 Flash model was experiencing peak demand. I quickly engineered a workaround to dynamically route requests to the gemini-2.5-flash model, ensuring the live demo remained stable and functional for the judges.
Cross-Origin Security (CORS): Connecting a Vercel edge frontend to a Render backend container triggered strict browser security blocks. I resolved this by explicitly configuring permissive CORS policies (AllowAll) in the .NET middleware.
🏆 Accomplishments that we're proud of Zero AI Hallucination in Scoring: By decoupling the AI extraction (Gemini) from the compliance evaluation (C# + SQLite), the app guarantees that the final risk score is 100% deterministic and legally reliable.
End-to-End Cloud Deployment: Successfully deploying a fully functional, containerized full-stack application with a live AI integration entirely on free cloud tiers.
Bulletproof Edge-Case Handling: Writing robust backend logic to gracefully handle contracts that completely omit critical clauses (like Governing Law) without crashing the C# evaluation engine.
📚 What we learned Prompt Engineering for Strict Schemas: I learned how to constrain an LLM's output to strictly adhere to a pre-defined JSON schema, ensuring the C# backend could serialize the data without failure.
Cloud Infrastructure Debugging: Diagnosing Docker permission structures, navigating Git LFS hook bypasses (--no-verify), and reading remote server logs taught me how to operate in a real-world DevOps environment.
🚀 What's next for The Contract Playbook Deviation Auditor If selected for the LexHack Builders Fellowship, the next phase of development includes:
Multi-Document Processing: Allowing legal teams to upload and audit batches of contracts simultaneously.
Dynamic Rule Builder: Adding an administrative UI so legal departments can edit the SQLite playbook rules without altering the codebase.
In-Line Redlining: Upgrading the AI engine to not only flag the deviations but suggest exact, compliant replacement text directly within the PDF.
Log in or sign up for Devpost to join the conversation.