Case study

Evidella

An internal knowledge application for drafting security questionnaire and RFP answers from approved company documents, with citations and human review.

Evidella logo
Core stack
Python · FastAPI · PostgreSQL · Qdrant · TypeScript

Problem

Reusable answers need traceable sources

Security and sales teams repeatedly answer the same questions, while approved wording is scattered across policies, previous questionnaires and product documents. A plausible answer without a source creates review and compliance risk.

My work

Retrieval, workflow and access control

I implemented document ingestion, background processing, hybrid retrieval, cited answer generation, organisation-scoped APIs, review states, audit records, the TypeScript interface and automated tests.

Implementation

From document to reviewed answer

Documents are validated and stored, then split and processed by a Python worker. Qdrant supplies semantic candidates; PostgreSQL full-text search recovers exact policy language. FastAPI returns source excerpts with each draft. Approval and access control remain application state, not model output.

  1. 01Validate and store documents
  2. 02Process sections asynchronously
  3. 03Retrieve relevant source chunks
  4. 04Draft with citations
  5. 05Review, approve or request a source

Hybrid retrieval

Semantic and exact search

Qdrant vector search is combined with PostgreSQL full-text ranking so exact policy language is not lost to semantic similarity alone. Thresholds and source limits make the behaviour tunable, but they also require dataset-specific evaluation.

Application controls

Access and approval stay outside the model

Keycloak authenticates users; PostgreSQL records their organisation and role. Queries remain organisation-scoped, while approval states and audit records are ordinary application data. This adds workflow steps, but a model response cannot bypass access control or approve itself.

Failure handling

Insufficient source material

If the retrieved documents do not support an answer, Evidella returns an explicit missing-source result instead of completing the draft. A human can supply the document and run retrieval again; no answer is approved automatically.

Verification

Retrieval and permission checks

  • Backend tests for retrieval, processing, uploads and access control
  • Unauthorised and cross-organisation access cases
  • TypeScript interface tests and API-boundary tests
  • A versioned 50-case demo retrieval evaluation gate