- English for source code, comments, logs, HTTP errors, UI copy intended for the repo, README, and config templates.
- Keep Portuguese regulatory acronyms where they are official (CRC, CIRBE, Banco de Portugal, BdE). Prefer GDPR (RGPD) when referring to data-protection law.
See .cursorrules. In short:
- The LLM never calculates score, PD, limit, rate, term, or decision.
INarrativeWriternever depends onIScoringEngine, providers, or external sources.Domain/Applicationdo not import LLM SDKs, EF, HTTP, or Azure.- CRC must never be cached; audit logs are append-only.
cp .env.example .env
docker compose up -d
dotnet restore CreditAI.sln
dotnet build CreditAI.sln
dotnet test tests/CreditAI.UnitTests
dotnet test tests/CreditAI.ArchitectureTests
dotnet test tests/CreditAI.IntegrationTests --filter "Category!=Postgres"# Terminal 1 — API
cd src/CreditAI.API
dotnet run
# https://localhost:7257 · ReDoc: /redoc
# Terminal 2 — Web
cd src/CreditAI.Web
dotnet run
# http://localhost:5188Default local login: admin@creditai.local / password from Auth:AdminPassword (see .env.example).
Prefer User Secrets or environment variables for secrets. Do not commit .env, appsettings.Development.json overrides with secrets, or certificates.
Keep docs/ in English. When adding features that touch compliance (F1–F5), update the relevant checklist and, if needed, docs/compliance/.
LLM clients must stay OpenAI-compatible (POST /v1/chat/completions) — see docs/LLM_OPENAI_COMPATIBLE.md. Do not add vendor-native chat APIs — only OpenAI-compatible /v1/chat/completions.
- Keep changes focused; match existing naming and DI patterns.
- Run unit + architecture tests before opening a PR. Run integration tests when touching pipeline, audit, or providers.
- Do not commit secrets, local OCR uploads, or generated
node_modules. - Conventional commits help release-please (
feat:,fix:,docs:, …).