ALT-AI (AffectLog's Trustworthy AI) is a dataset-first Trustworthy-AI assessment
platform. This document describes the processing pipeline (how a dataset flows
through the assessment) and the deployed runtime (the services that actually
run), and records how the two map onto each other. For the formal deliverable-level
design see design-document.md; for the area-by-area
conformance record see design-conformance.md.
CSV / JSON / JSONL / Parquet
↓
[Ingest Layer] ← Polars lazy scanning, streaming chunks
↓
[SecurityLayer] ← PII detection, HMAC-SHA256 pseudonymisation
↓
[Transform Layer] ← CSV→xAPI JSONL, Becomino template inference
↓
[Profiling Layer] ← Schema, descriptive, temporal, sparsity, entropy
↓
[Metrics Layer] ← Gini, Coverage@K, fairness, representation
↓
[Compliance Layer] ← JSON-LD, Data Card, Model Card, SOP, GDPR inventory
↓
[Recipe Runner] ← YAML-driven pipeline orchestration
↓
[FastAPI Backend] ← OpenAPI 3.1 REST API
↓
[React Dashboard] ← Vite + TypeScript frontend
AFFECTLOG_ALLOW_RAW_IDENTIFIERS=false, AFFECTLOG_PSEUDONYMIZE=true).config_hash, audit_manifest.json, and deterministic IDs.| Component | Module | Purpose |
|---|---|---|
ModelAdapter |
src/affectlog/models/ |
Standardized ML model interface |
ExplanationGenerator |
src/affectlog/explanations/ |
SHAP + permutation importance |
ResultsProcessor |
src/affectlog/reports/ |
Dashboard payload, markdown, CSV |
SecurityLayer |
src/affectlog/privacy/ |
PII detection + pseudonymisation |
PDCClient |
src/affectlog/pdc/ |
Prometheus-X connector (mock + real) |
See classDiagram-v1.1.png and
sequenceDiagram-v1.1.png for the UML class and
sequence diagrams (rendered PNGs; no editable source is currently tracked).
The reference self-hosted deployment is defined in
docker-compose.yml. The services that actually run:
| Service | Image / build | Exposed port | Internal | Health check | Persistence |
|---|---|---|---|---|---|
postgres |
postgres:16-alpine |
5432 |
5432 | pg_isready |
volume postgres_data |
redis |
redis:7-alpine |
— | 6379 | redis-cli ping |
volume redis_data |
api |
build Dockerfile |
8000 |
8000 | curl /healthz |
bind mounts ./data, ./runs, ./configs |
worker |
build Dockerfile.worker |
— | — | — (Celery) | bind mounts ./data, ./runs, ./configs |
frontend |
build Dockerfile.frontend |
3000 → 80 |
80 | — | — |
mailpit |
axllent/mailpit |
8025 (UI), 1025 (SMTP) |
— | — | — (dev email sink) |
Notes:
api and worker start only after postgres and
redis report healthy (depends_on: condition: service_healthy);
frontend depends on api.AFFECTLOG_EMAIL_SEND_ENABLED=false
by default. It is not a production mail service.data/, runs/
and configs/ are host bind mounts in the reference stack..env
(make dev, make seed, make create-admin). The database URL and password
pepper come from that one .env, so host and runtime always match.api container against the
Compose Postgres, using the container's environment. Bootstrap (RBAC seed +
admin creation) must therefore run inside the api container
(make docker-bootstrap) — see the authentication boundary below.AFFECTLOG_PASSWORD_PEPPER) used to
compute it. An authentication record created under a different database or a
different pepper is not portable to the running API.api container so it uses
the same AFFECTLOG_DATABASE_URL and AFFECTLOG_PASSWORD_PEPPER as the server.
Running it on the host — where those differ — is the classic cause of a
"created admin but Invalid credentials" login failure.make seed,
make create-admin), correct because host and runtime share one .env..env (git-ignored) or an external secret manager;
Compose fails fast if POSTGRES_PASSWORD is unset. Secrets must not be logged
or committed.Four distinct deployment contexts, in increasing order of hardening:
.env, no containers required; fastest
inner loop.docker-compose.yml.
It is a working, security-conscious starting point (fail-fast on missing DB
password, pseudonymisation on, raw exports off, dev cookies), but it is not by
itself a complete production-hardening specification.A production deployment of the self-hosted stack must additionally address, as applicable:
AFFECTLOG_COOKIE_SECURE=true) and a
trusted-origin / CORS allow-list scoped to real hostnames;.env defaults) with rotation;The reference Compose stack does not claim to provide all of the above; it provides a reproducible baseline that a deploying institution hardens.
Source flows through three stages, each with a distinct role. No stage auto-pushes to the next.
roy-saurabh/edge_affectlog
│ validated development promotion (reviewed PR)
▼
roy-saurabh/t-ai-affectlog ← AffectLog production / release repo
│ reviewed public upstream promotion (cross-repo PR)
▼
Prometheus-X-association/t-ai-affectlog ← official consortium source of record
main branch is permitted.
Official upstream changes arrive as a reviewable pull request.