我们发现了什么
sujalmallick/probity-ai。它读取发票,与你自己的记录(供应商、已验证的银行账户、历史发票、采购订单)以及外部来源进行比对,并向你展示它发现的每一个问题的证据。
- 来源:GitHub(发现于 2026-10-06)
- 证据等级:D · 发现产品或需求信号,暂未获得可核验的商业证据。
- 商业模式:待核验
- 主题:独立产品
- 初筛评分:16/100 · 收录 1 次
证据,比故事更重要。
规则清洗与初筛,未经人工商业核验。原文语境、实际客户和付费情况仍需自行验证。
引用与数字披露
来源类型(原作者自述/第三方测算/媒体转引)需采集端标注,本版尚未落字段。
- 作者
- 未标注
- 抓取日期
- 来源类型
- 未标注
- 币种
- 未标注
- 口径
- 未标注
- 披露主体
- 未标注
- 披露日期
- 未标注
中文辅助译文(节选·触顶截断)
Probity
付款前的证据。
小企业每天都需支付发票,而任何一处银行账户的变更或发票被仿造都可能让它们付出惨痛代价。Probity 会在你付款之前调查每一张发票:它读取发票内容,将其与你自己的记录(供应商、已核实的银行账户、历史发票、采购订单)以及外部来源进行比对,并向你展示它所发现的每一项疑虑的证据。一个纯代码的风险引擎会把已核实的发现转化为评分。低风险发票可自动放行;任何异常发票都会被保留,由人工依据具体原因作出决定。
AI 可以进行调查,但不能更改风险评分。智能体负责寻找信号,每一项主张都需要证据,由代码计算评分,最终由人来决定是否付款。
在线试用:https://probity-3xgk.onrender.com。 使用邮箱注册即可获得你自己的空白工作区。由于部署在免费托管平台上,在一段静默时间后首次访问可能需要约一分钟来唤醒服务。
适用对象
- 财务人员(会计):上传发票,维护供应商列表与历史发票,并修正识别错误的字段。
- 审批人:审阅被保留的发票,附理由地批准或驳回,并通过已有记录中的渠道与供应商核实变更。
- 供应商:无需登录。他们可能收到一封简短、中立的邮件,被要求确认某些细节——这封邮件只有在审批人批准之后才会发送。
一张真实发票的处理流程
1. 上传。会计上传 PDF 发票或邮件发票。Probity 读取其中的字段:供应商、GSTIN、发票号、日期、金额和银行账户。 2. 调查。智能体会在多项内容中进行核查,包括: - 这是我们认识的供应商吗? - 这是我们为其核实过的银行账户吗? - 这个价格对这家供应商而言是否正常? - 我们是否见过这张发票? - 它是否与采购订单匹配? - 发件人的网站域名有多久的历史? - 是否有公开的相关信息? 3. 核实。每一项发现都必须指向证据:发票数值以及与其比较的记录。缺乏证据的发现会被丢弃。 4. 评分。纯代码将已核实的发现汇总为一个 0 到 100 的评分:LOW、MEDIUM、HIGH 或 CRITICAL。 5. 放行/保留。如果所有核查都通过,发票即被放行。如果存在任何异常,或某项必需的核查未能核实,则该发票会被保留,由人工处理,并能清晰看到原因。 6. 决策。审批人可以批准、驳回、要求供应商确认,或要求进行更深入的调查。Probity 只会建议;它既不会付款,也不会指控任何人。 7. 记忆。处理结果会被记录,该供应商的下一张发票在核查时便会参考这段历史。
设计规则
- AI 负责调查;纯代码负责计算风险评分。风险引擎不接受 AI 输入,也无法通过文本来更改数字。
- 每一项主张都需要证据。没有证据就没有主张。未经核实的发现计零分。
- "无法核实"绝不等同于"没问题"。当某项核查无法运行(缺少关键信息、无历史记录、网络故障)时,Probity 会如实说明,不加分,并在该核查为必需时保留发票。它从不伪造结果。
- 系统绝不进行任何付款。它只提供建议,由人来决定。
- 始终由人来做决定,任何并非明确低风险的事项均如此。涉及大额或关键风险的案件需要两名审批人。
- 供应商的回复在经审批人通过已有记录中的渠道(已知电话号码、银行函件、当面确认)确认之前,一律视为未核实。绝不会通过邮件本身的细节来确认。
- 中立的措辞。Probity 报告的是异常情况并建议保留。它从不使用"欺诈"一词。
架构
flowchart LR
W[Web 应用
React + Vite] -->|/api/v1| A[API
FastAPI]
A --> G[智能体
LangGraph]
G --> R[风险引擎
纯代码]
A --> DB[(PostgreSQL
行级安全)]
G --> DB
A -.-> C[Clerk
登录]
G -.-> L[AI:Claude
或 Gemini]
G -.-> T[Tavily
网页搜索]
G -.-> RD[RDAP
域名年龄]
A -.-> E[Resend
邮件]智能体按顺序为:文档读取器 → 规划器 → 供应商调查员 + 交易分析师 → 网络研究员(按需启用)→ 证据核验员 → 风险引擎 → 案件分析师 → 策略把关。详见:docs/Architecture.md。
快速开始
你需要准备 Git、Python 3.12+、Node 22、Docker Desktop、一个 AI 密钥(Anthropic 或 Google Gemini)以及一个免费的 Clerk 开发应用。在 Windows 上:
git clone -b real-data https://github.com/sujalmallick/probity-ai.git
cd probity-ai
powershell -ExecutionPolicy Bypass -File scripts\dev.ps1-b real-data 很关键:该分支包含当前的代码(参见分支与部署)。首次运行会完成初始化,并提示你需要添加哪些密钥。添加后再执行一遍,然后打开 http://localhost:5180。
完整分步指南(Windows、macOS、Linux):docs/SETUP.md。获取密钥:docs/API_KEYS.md。 部署:线上应用运行在 Render + Neon 上(infra/render/README.md)。还有 Docker + Cloudflare 的替代方案:infra/cloudflare/README.md。
当前状态
Probity 是一个黑客松原型。它已能在真实数据上端到端运行,但尚未经过生产环境的审计。
已可用的功能
- 上传基于文本的 PDF、邮件发票(.eml)以及文本文件。- 完整的智能体流水线,包含"无法核实"的处理逻辑,以及当 AI 不可用时的标注式降级方案。- 风险评分,每一分都有证据支撑;自动放行规则;审批流程(含双人审批案件)以及书面理由。- 供应商列表,包含已核实的银行账户、域名和联系方式;支持通过 CSV 导入供应商、历史发票和采购订单。- 中立的供应商邮件(Resend,测试期间使用白名单)、供应商回复以及带外确认。- 角色(查看者、会计、审批人、所有者)、案件记忆、审计日志、PDF/JSON 导出,以及数据库中的工作区隔离。- 可选择 AI 提供商:Anthropic Claude(默认)或 Google Gemini。- 通过 CSV 导入或单条添加(API)的方式维护历史发票和采购订单。会计添加的记录只有在审批人批准后才会纳入比较。- 无需重型病毒扫描的上传安全机制:每个 PDF 在存储前都会去除所有活动内容(JavaScript、嵌入文件、自动操作)后重写;带有敌意内容的 PDF 会被拒绝。仍可添加 ClamAV(CLAMAV_HOST)。- 按工作区每日和按案件为单位的使用限额(调查次数、AI token、网页搜索、上传大小)。达到上限时,任务会干净地中止并指明所触达的限额。- 每个案件都有逐智能体的追踪记录,以及自动合理性检查(评分 = 已核实分数,没有无证据的分数,没有"全部通过"却没有进行搜索……);任何问题都会使发票被保留。失败的案件可以从头重试。
python -m probity.check会对每项集成进行实际测试,包括一次数据库的创建/读取/更新/删除往返验证;python -m probity.sanity会重新检查已存储的案件。- 在你自己的标注发票上运行 Probity 并获取报告:benchmark/real/README.md。- 生产环境的 Docker 堆栈(API、worker、scheduler、web、Cloudflare Tunnel;文件存储使用 R2):参见 infra/cloudflare/README.md。
已规划 / 暂不支持的功能 - 扫描版 PDF 和照片:目前会被拒绝,尚无 OCR 支持。 - GST 注册信息核验:没有免费的官方 API。Probity 仅检查 GSTIN 的格式与校验和,并将注册状态显示为"无法核实"。你可以手动记录你在 GST 门户上看到的内容,并标注为"人工录入"。 - 除 Resend 之外的邮件服务商(不支持 SMTP);供应商回复中的退信与自动回复处理。 - 部分 API 功能的界面:批准历史发票与采购订单、单条添加、逐智能体追踪、失败案件重试、通知、发票风险策略。各项的 API 已就绪(docs/API_CONTRACT.md)。 - 前端测试与代码检查工具(linter)。 - 案件超过保留期(默认 8 年;所有者可列出)后的自动清理。参见 docs/PRIVACY.md。
已知局限 - 如果没有已批准的历史记录、已核实的银行账户以及 Tavily 密钥,许多核查会返回"无法核实",因此新工作区中大多数发票都会被保留。 - 非 INR 发票会被保留,因为价格无法比较。 - 后台 worker(Redis + Celery)是可选的。默认情况下调查在 API 进程内运行,对于单台机器而言这已经足够。 - 在没有 ClamAV 的情况下,一份与已知恶意软件匹配但不含活动内容的 PDF 会被存储(经过清理),而非被标记为恶意软件。
完整列表:docs/FEATURES.md。
分支与部署
| 分支 | 说明 |
|---|---|
real-data | 当前代码,同时也是线上运行的版本。Render 在每次该分支收到推送时都会自动重新构建并部署 https://probity-3xgk.onrender.com。 |
main | 早于 real-data 工作的旧版快照。未部署。未来会与 real-data 同步更新。 |
your branch → pull request into real-data → tests pass, review → merge → Render deploys → live in a few minutes- 在你电脑上修改文件永远不会影响线上站点。只有推送到 GitHub 上的
real-data提交才会生效。 - 推送到任何其他分支都是安全的。包括你自己的分支和
main;这些分支不会被部署。 - 不要直接推送到
real-data。请在自己的分支上工作并发起 pull request,以便先运行测试。
托管方式:
- Render(免费方案)运行一项 Web 服务:即 API,并在同一地址上承载构建好的 Web 应用。它由 render.yaml 和 infra/render.Dockerfile 配置完成。
- Neon 负责存储 PostgreSQL 数据库和已上传的发票文件。
- Clerk 负责登录。
- 线上设置和密钥均在 Render 的仪表板中配置,绝不出现在代码仓库中。
分步设置:infra/render/README.md。
文档
| 文档 | 用途 |
|---|---|
| docs/SETUP.md | 分步安装与运行,并附排错指南 |
| docs/API_KEYS.md | 每个密钥与服务:必需或可选、费用、配置位置 |
| docs/FEATURES.md | 已可用、部分可用、已规划的功能,以及可参与的工作方向 |
| docs/Architecture.md | 代码组织方式,面向贡献者 |
| docs/Guardrails.md | 安全规则及其执行方式 |
| docs/DECISIONS.md | 设计决策与当前的限制 |
| docs/API_CONTRACT.md | Web 应用所使用的 API |
| infra/render/README.md | 如何免费部署线上应用(Render + Neon) |
| infra/cloudflare/README.md | 替代方案:在 Cloudflare(Tunnel、R2)后部署 Docker 堆栈 |
| benchmark/real/README.md | 在你自己的标注发票上运行 Probity |
| docs/SECURITY_HANDOVER.md | 安全审查修复了哪些内容、保护它们的测试,以及仍未解决的问题 |
| docs/FAILURE_AUDIT.md | 失败、卡住案件与错误的处理方式 |
| docs/README.md | 全部文档索引,包括最初的设计文档 |
| docs/PRD.md | 最初的产品需求(部分内容描述的是早期的演示版本) |
贡献
欢迎朋友和新手参与。请从 CONTRIBUTING.md 开始:其中包含入门任务、工作流程,以及发起 pull request 前需要运行的检查。Pull request 合并至 real-data。如需私下报告安全问题,请参见 SECURITY.md。
许可证
Probity 以 MIT 许可证开源。只要你保留版权声明和许可证声明,你可以使用、复制、修改和分享本项目。
……(正文超出本站单页篇幅上限,此处截断;完整表述请见下方原文入口。)
译文由上游机器翻译生成,可能有误;判断请以英文原文为准。
英文原文(来源本站未改写)
Probity
Evidence before payment.
Small businesses pay invoices every day, and a single changed bank account or copied invoice can cost them dearly. Probity investigates each invoice before you pay it. It reads the invoice, compares it with your own records (vendors, verified bank accounts, past invoices, purchase orders) and with outside sources, and shows you the evidence for every concern it finds. A pure-code risk engine turns verified findings into a score. Low-risk invoices can be cleared automatically; anything unusual is held for a person to decide, with the reasons.
The AI can investigate, but it cannot change the risk score. Agents find signals, every claim needs evidence, code computes the
score, and a human decides the payment.
Try it live: https://probity-3xgk.onrender.com. Sign up with your email and you get your own empty workspace. It's on free hosting, so the first visit after a quiet spell can take about a minute to wake up.
Who it's for
- The accounts person (accountant): uploads invoices, keeps the vendor list and past invoices up to date, and fixes misread fields.
- The approver: reviews held invoices, approves or rejects with a reason, and confirms changes with the vendor through a channel already on file.
- The vendor: never logs in. They may get a short, neutral email asking them to confirm details, sent only after an approver approves it.
How a real invoice flows
1. Upload. The accountant uploads a PDF or an emailed invoice.Probity reads the fields: vendor, GSTIN, invoice number, dates, amounts and bank account. 2. Investigate. Agents check, among other things: - Is this a vendor we know?- Is this the bank account we verified for them?- Is the price normal for them?- Have we seen this invoice before?- Does it match the purchase order?- How old is the sender's web domain?- Is there anything public about them?3. Verify. Every finding must point to evidence: the invoice value and the record it was compared with.
Findings without evidence are dropped. 4. Score. Pure code adds up the verified findings into a 0 to 100 score: LOW, MEDIUM, HIGH or CRITICAL. 5. Gate. If everything checked out, the invoice is cleared.If anything is unusual, or a required check could not be verified, it's held for a person, who sees exactly why. 6. Decide. The approver approves, rejects, asks the vendor to confirm, or asks for a deeper investigation.Probity recommends;it never pays and never accuses anyone. 7. Remember. The outcome is saved, and the vendor's next invoice is checked with that history in mind.
Design rules
- The AI investigates;pure code computes the risk score. The risk engine has no AI input and no way for text to change a number. - Every claim needs evidence. No evidence means no claim.Unverified findings add zero points. - "Could not verify" is never "fine". When a check can't run (missing key, no history, network failure), Probity says so, adds no points, and holds the invoice if the check was required.It never invents a result. - The system never pays anything. It recommends;people decide. - A human always decides anything that isn't clearly low-risk.
Large or critical cases need two approvers. - Vendor replies stay unverified until an approver confirms them through a channel already on file (a known phone number, a bank letter, in person), never through details from the email itself. - Neutral wording. Probity reports anomalies and recommends a hold.It never calls anything "fraud".
Architecture
flowchart LR
W[Web app
React + Vite] -->|/api/v1| A[API
FastAPI]
A --> G[Agents
LangGraph]
G --> R[Risk engine
pure code]
A --> DB[(PostgreSQL
row-level security)]
G --> DB
A -.-> C[Clerk
sign-in]
G -.-> L[AI: Claude
or Gemini]
G -.-> T[Tavily
web search]
G -.-> RD[RDAP
domain age]
A -.-> E[Resend
email]Agents in order: document reader → planner → vendor investigator + transaction analyst → web researcher (when needed) → evidence verifier → risk engine → case analyst → policy gate. Details: docs/Architecture.md.
Quick start
You need Git, Python 3.12+, Node 22, Docker Desktop, an AI key (Anthropic, or Google Gemini) and a free Clerk development app. On Windows:
git clone -b real-data https://github.com/sujalmallick/probity-ai.git
cd probity-ai
powershell -ExecutionPolicy Bypass -File scripts\dev.ps1-b real-data matters: that branch has the current code (see Branches and deployment). The first run
sets things up and tells you which keys to add. Add them and run it again, then open http://localhost:5180.
Full step-by-step guide (Windows, macOS, Linux): docs/SETUP.md. Getting the keys: docs/API_KEYS.md. Deploying: the live app runs on Render + Neon (infra/render/README.md). There's also a Docker + Cloudflare alternative: infra/cloudflare/README.md.
Current status
Probity is a hackathon prototype. It works end to end on real data, but it hasn't been audited for production use.
Working - Upload text-based PDFs, emailed invoices (.eml) and text files. - The full agent pipeline, with "could not verify" handling and labelled fallbacks when the AI is unavailable. - The risk score with evidence for every point, auto-clear rules, approvals (including two-approver cases) and written reasons. - Vendor list with verified bank accounts, domains and contacts;
CSV import of vendors, past invoices and purchase orders. - Neutral vendor emails (Resend, allowlist while testing), vendor replies, out-of-band confirmation. - Roles (viewer, accountant, approver, owner), case memory, audit log, PDF/JSON export, and workspace isolation in the database. - A choice of AI provider: Anthropic Claude (default) or Google Gemini. - Past invoices and purchase orders by CSV import or one at a time (API).Records an accountant adds count in comparisons only after an approver approves them. - Upload safety without a heavy virus scanner: every PDF is rewritten without active content (JavaScript, embedded files, auto-actions) before it's stored;
hostile PDFs are refused.ClamAV can still be added (CLAMAV_HOST).
- Usage limits per workspace per day and per case (investigations, AI tokens, web searches, upload size).Hitting one stops the work
cleanly and names the limit.
- A per-agent trace for every case and automatic sanity checks (score = verified points, no point without evidence, no "all clear"
without a search…);any problem holds the invoice.Failed cases can be retried from the start.
- python -m probity.check tests every integration for real, including a database create/read/update/delete round trip;
python -m probity.sanity re-checks stored cases.
- Run Probity on your own labelled invoices and get a report: benchmark/real/README.md.
- A production Docker stack (API, worker, scheduler, web, Cloudflare Tunnel;R2 for files): see infra/cloudflare/README.md.
Planned / not yet supported - Scanned PDFs and photos: refused today.There's no OCR. - GST registry verification: there's no free official API.Probity checks the GSTIN's format and checksum only, and shows the registry status as "could not verify".You can record what you saw on the GST portal by hand;it's labelled "Entered manually". - Email providers other than Resend (no SMTP);bounce and out-of-office handling for vendor replies. - Screens for some API features: approving past invoices and POs, adding single ones, the per-agent trace, retrying a failed case, notifications, the invoice-risk policy.
The API for each is in place (docs/API_CONTRACT.md). - Frontend tests and a linter. - Automatic deletion of cases past the retention period (8 years by default;an owner can list them).See docs/PRIVACY.md.
Known limitations - Without approved history, verified bank accounts and a Tavily key, many checks say "could not verify", so a new workspace holds most invoices. - Non-INR invoices are held, because prices can't be compared. - A background worker (Redis + Celery) is optional. By default investigations run inside the API process, which is fine for one machine. - Without ClamAV, a PDF that matches known malware but has no active parts is stored (cleaned) rather than named as malware.
Full list: docs/FEATURES.md.
Branches and deployment
| Branch | What it is |
|---|---|
real-data | The current code, and what's live. Render rebuilds and deploys https://probity-3xgk.onrender.com automatically on every push to this branch. |
main | An older snapshot from before the real-data work. Not deployed. It will be brought up to date with real-data. |
your branch → pull request into real-data → tests pass, review → merge → Render deploys → live in a few minutes- Changing files on your computer never changes the live site. Only a commit pushed to
real-dataon GitHub does. - Pushing to any other branch is safe. That includes your own branch and
main; nothing is deployed. - Don't push straight to
real-data. Work on your own branch and open a pull request, so the tests run first.
How it's hosted:
- Render (free plan) runs one web service: the API, plus the built web app on the same address. It's set up by render.yaml and
infra/render.Dockerfile.
- Neon holds the PostgreSQL database and the uploaded invoice files.
- Clerk handles sign-in.
- The live settings and keys are set in Render's dashboard, never in the repo.
Step-by-step setup: infra/render/README.md.
Documentation
| Doc | What it's for |
|---|---|
| docs/SETUP.md | Install and run it, step by step, with troubleshooting |
| docs/API_KEYS.md | Every key and service: required or optional, cost, where it goes |
| docs/FEATURES.md | What works, what's partial, what's planned, plus ideas to work on |
| docs/Architecture.md | How the code is organised, for contributors |
| docs/Guardrails.md | The safety rules and how they're enforced |
| docs/DECISIONS.md | Design decisions and current limits |
| docs/API_CONTRACT.md | The API the web app uses |
| infra/render/README.md | How the live app is deployed for free (Render + Neon) |
| infra/cloudflare/README.md | Alternative: deploying the Docker stack behind Cloudflare (Tunnel, R2) |
| benchmark/real/README.md | Running Probity on your own labelled invoices |
| docs/SECURITY_HANDOVER.md | What the security review fixed, the tests that guard it, what's still open |
| docs/FAILURE_AUDIT.md | How failures, stuck cases and errors are handled |
| docs/README.md | Index of every doc, including the original design docs |
| docs/PRD.md | The original product requirements (some parts describe the earlier demo version) |
Contributing
Friends and newcomers are welcome. Start with CONTRIBUTING.md: it has starter tasks, the workflow, and the checks to
run before a pull request. Pull requests go into real-data. To report a security problem privately, see SECURITY.md.
License
Probity is open source under the MIT License. You can use, copy, change and share it, as long as you keep the copyright and license noti
... (truncated at the site's per-page length limit; see the source link below for the full text.)
这条还缺什么证据?
下面每条都由本条已有字段推出(等级、理由、商业模式、来源次数、是否演示), 本站不生成推测性结论;通用验证方法放在方法论页。
- 可核验的收入或付费证据查官网定价页与付费口径;第三方数据源(如 GetLatka)只作旁证,需标注来源与时点。
- 商业模式未定确认按席位/按用量/授权还是开源托管版收费;开源项目另查 LICENSE 与是否存在付费版。
- 只有单一来源找一手站点或其他渠道是否重复出现同一产品;社区热帖数量不等于商业进展。
通用验证清单(谁有这个问题/谁愿意付费/一个人能交付哪一小步)见我们的筛选方法。