Open Source · AI-Assisted · Multi-Sector

Three AI agents review every document.
Before humans ever see it.

VEGA is an open-source compliance platform for public institutions. One codebase covers healthcare, municipalities, pharmacies, social care — any regulated sector, any EU country.

See the platform Read the research
Zenodo DOI: 10.5281/zenodo.21213874 Published methodology on Medium EUPL licensed
80+
KGR review cycles
9
Industry verticals
3
Independent AI reviewers
14
Governance documents
5
Legislative country groups
Compliance in public institutions is broken
Hospitals, municipalities, and social care centers manage hundreds of regulatory documents manually. When laws change, nobody knows which documents are affected.

Without VEGA

  • Documents scattered across filing cabinets and shared drives
  • No automated check when legislation changes
  • Compliance audits take weeks of manual cross-referencing
  • Single expert leaves — institutional knowledge lost
  • No audit trail — "who approved this and when?"

With VEGA

  • Every document digitized, OCR-verified, version-tracked
  • AI cross-references new legislation against your documents
  • Three AI reviewers independently assess every change
  • Full audit trail: who reviewed, who approved, why
  • Works offline — no internet required for core functions
Five steps. Zero shortcuts.
Every document passes through a fixed pipeline. Steps cannot be skipped, reordered, or removed. This is enforced at the architecture level, not by policy.
📤
Upload
Scan or import
🔍
OCR
Text extraction
Verification
Human review
KGR Council
3 AI reviewers
🏆
Approved
Audit trail locked
Three AI agents. Fixed roles. No groupthink.
Every significant change goes through a structured multi-AI review. Roles are fixed, AI providers are swappable. No single AI can approve alone.
🧐
Skeptic
Default: Kimi
Adversarial verification. Tries to break the proposal. Legal risk assessment.
🔭
Optimist
Default: Gemini
Structural coherence. Constructive assessment. Architecture alignment.
Arbiter
Default: Claude
Risk analysis synthesis. Casts third vote. Resolves disagreements.
Unanimous APPROVE = implement. Unanimous REJECT = blocked. Split = rebuttal round.
AI providers are interchangeable. The protocol is permanent.
KGR reviewed this website.
The Platform Specification you see on this site went through KGR review before publication. Here's what three AI agents caught that the author missed.
Round
R80
Review cycle #80
R1 Verdict
CONDITIONAL
3/3 conditional approve
Issues found
8
3 critical, 3 medium, 2 low
What each reviewer caught:
🧐 Skeptic (Kimi) CRITICAL
No contributor license. Open-source project without a CLA or DCO is a legal minefield — who owns the copyright on contributed code? Added DCO requirement.
🧐 Skeptic (Kimi) CRITICAL
No liability disclaimer. A legal-tech platform without "not legal advice" exposes the maintainer to personal liability if a module misinterprets legislation. Added AS-IS clause and indemnification.
🧐 Skeptic (Kimi) POLITICAL
"Balkan group with Yugoslav heritage" is politically toxic in Croatia and Serbia. Would kill community adoption before it starts. Renamed to "Southeast Europe" with explicit EU/non-EU separation.
🔭 Optimist (Gemini) STRUCTURAL
Confirmed microkernel architecture as correct pattern. Validated that ES5/standalone HTML constraint is structurally necessary for air-gapped hospital networks, not just a preference.
Arbiter (Claude) SYNTHESIS
"Immutable" contradicts open-source. If nothing can ever change, how do you patch a security bug? Added emergency KGR exception for security-only patches within 24 hours.
Arbiter (Claude) SYNTHESIS
No GDPR data retention policy. Platform claims "Data Isolation" but didn't specify who is Data Controller, how long data is kept, or how to handle deletion requests. Fixed.
The pattern across 80+ reviews:
KGR almost never rejects an idea outright. It improves it —
catching legal gaps a developer misses, political risks an architect ignores,
and structural contradictions that only surface under adversarial pressure.

This page exists because KGR reviewed it first.
Every module has a protection tier
Core governance is immutable. Domain-specific modules are open for community contributions. Four tiers, clear rules.
KGR CouncilIMMUTABLE
Multi-AI review protocol. Three independent reviewers with fixed adversarial roles. The immune system of the platform.
Document PipelineIMMUTABLE
Upload → OCR → Verification → KGR → Approved. Steps cannot be skipped or reordered.
Compliance HubGUARDED
Cross-references documents against legislation. Detects compliance gaps when laws change. KGR review required for changes.
Legal NetworkGUARDED
Maps relationships between laws, regulations, and internal documents. Traces which law mandates which document.
Domain ManagerCOMMUNITY
Configure new sectors and countries. Add legislation, organizational units, and document types via JSON configuration.
Dashboard & AnalyticsCOMMUNITY
Compliance entropy tracking, document health scores, anomaly detection. Open for community contributions.
Document GeneratorCOMMUNITY
Generate compliant document templates. Sector-specific, contributed by domain experts in each country.
Themes & DocsFREE
Visual themes, CSS customization, tutorials, translations. No formal review needed. Open contribution.
One codebase. Nine verticals. Any country.
Legislation is configuration, not code. Adding a new country or sector means adding a JSON entry — not rewriting a module.
🏥
Healthcare
Hospitals, clinics
💊
Pharmacies
Drug regulation
🏛
Municipalities
Local government
🏠
Social Care
Elder & disability
🎓
Education
Schools, kindergartens
🏭
ISO Companies
9001, 27001, 14001
🏢
Community Health
Public health centers
🤝
NGOs
Non-profits
🌍
EU Compliance
GDPR, AI Act, EHDS
🇸🇮 Slovenia
🇩🇪 Germany
🇦🇹 Austria
🇨🇿 Czechia
🇭🇷 Croatia
🇷🇸 Serbia
🇪🇸 Spain
🇫🇷 France
🇮🇹 Italy
🇸🇪 Sweden
🇬🇧 United Kingdom
🇵🇱 Poland

Countries with similar legislation share modules. Five groups: DACH+SI+V4 · Balkan · Romance · Nordic · Anglo-Saxon

Not a pitch. A methodology.
VEGA's governance protocol is published, peer-reviewable, and has 80+ documented review cycles with full audit trails.
📄

KGR Methodology Paper

Multi-agent adversarial review protocol for high-stakes AI-assisted decision systems. Published on Zenodo, pending arXiv endorsement.

📝

"AI Blocks Its Own Owner"

How three AI agents prevented bad decisions in a live governance system. Case study published on Medium.

📖

VEGA Testament v1.3

Tier 5 governance constitution. 14 clauses defining immutable principles, evidence hierarchy, and portability.

📊

80+ Review Cycles

Every review logged: hypothesis, evidence, three independent verdicts, rebuttal rounds. Full audit trail.

Seven rules every contribution must follow
P1 GOVERNANCE IMMUNITY
KGR protocol, evidence hierarchy, and Testament are immutable. No contribution may change, bypass, or redefine governance.
P2 DATA ISOLATION
Every instance has fully isolated data. No module may read another instance's documents without explicit permission.
P3 PIPELINE INTEGRITY
The document flow is fixed. Steps cannot be skipped or reordered. New steps may only be inserted between existing ones.
P4 AI AGNOSTICISM
No dependency on a single AI provider. Roles are fixed, providers are swappable without code changes.
P5 LEGISLATION AS CONFIG
Laws live in domain_config.json, never in code. New law = new config entry, never a new if/else.
P6 OFFLINE FIRST
All modules work without internet. Only AI calls require API access. Documents and pipeline work locally.
P7 AUDITABILITY
Every decision is traceable: who, when, why. No module may delete or overwrite audit trails.

Build compliance infrastructure
for your country

Add your legislation as configuration. Contribute modules for your sector. Join a language-specific development forum.

View on GitHub Try KGR Demo
🇬🇧 English 🇩🇪 Deutsch 🇪🇸 Español 🇫🇷 Français 🇸🇮 Slovenščina