??????????????????????????????????????????????????????????????
? PRESENTATION ?
? ???????????????????? ???????????????????? ?
? ? Blazor Server ??????????? REST API ? ?
? ? (Interactive) ? ? (Stateless) ? ?
? ???????????????????? ???????????????????? ?
??????????????????????????????????????????????????????????????
??????????????????????????????????????????????????????????????
? APPLICATION ?
? Business Logic ? Interfaces ? DTOs ? Validators ?
??????????????????????????????????????????????????????????????
??????????????????????????????????????????????????????????????
? INFRASTRUCTURE ?
? Agents ? Scoring ? Integrations ? Pipeline ? OCR ? ML ?
??????????????????????????????????????????????????????????????
??????????????????????????????????????????????????????????????
? DOMAIN ?
? Entities ? Value Objects ? Enums ? Domain Rules ?
??????????????????????????????????????????????????????????????
??????????????????????????????????????????????????????????????
? DATA / EXTERNAL ?
? PostgreSQL ? OpenAI-compatible LLM ? Tesseract ? External APIs ?
??????????????????????????????????????????????????????????????
INPUT ? COLLECTION ? ANALYSIS ? SCORING ? DECISION ? REVIEW ? MONITOR
? ? ? ? ? ? ?
? ? ? ? ? ? ?
? ? ? ? ? ? ?
???????? ???????? ???????? ???????? ???????? ???????? ????????
?Credit? ? CRC ? ?Agents? ? ML ? ?Rules ? ?Human ? ?Early ?
?Request???11 APIs??? AI ???Score ??? F1-F5???Review???Warn ?
???????? ???????? ???????? ???????? ???????? ???????? ????????
? ? ? ? ? ? ?
?????????????????????????????????????????????????????????????????
?
?
[Immutable Audit Log]
???????????????????????????????????????????????????????????????
? 1. INTAKE & ORCHESTRATION ?
? ? CreditRequestIntakeService ?
? ? CreditDecisionPipeline ?
? ? IberianMarketPolicy (PT/ES routing) ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 2. DATA COLLECTION (13 sources) ?
? Regulatory: CRC (PT) | CIRBE (ES) ?
? Financial: Orbis | SABI | Moody's EDF ?
? Banking: Yapily (Open Banking) ?
? Risk: World-Check | ESG ?
? Judicial: Citius (PT) ?
? Other: IES | Creditsafe ?
? ?
? Pattern: IDataProvider ? Stub/Production + Manual ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 3. AI AGENTS (6 specialized) ?
? ? BehavioralCollectionAgent (CRC/CIRBE) ?
? ? FinancialCollectionAgent (Orbis/SABI/Moody's) ?
? ? IncomeCollectionAgent (Yapily) ?
? ? LegalStructureCollectionAgent (Company data) ?
? ? SectorMacroCollectionAgent (Economic context) ?
? ? SanctionsAmlCollectionAgent (WorldCheck/ESG/Citius) ?
? ?
? Output: 50+ normalized features ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 4. ML SCORING ENGINE ?
? ? Model Registry (versioning + approval) ?
? ? ONNX Runtime OR baseline profiles ?
? ? SHAP values (explainability) ?
? ? Segment-specific models (Consumer/SME/Corporate) ?
? ?
? Output: Score (0-1000) + PD + Rating + SHAP ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 5. SOLVENCY ASSESSMENT (F1-F5) ?
? F1: High risk blocks (PD, incidents, sanctions) ?
? F2: Income/capacity checks ?
? F3: Structural issues ?
? F4: Market/sector risks ?
? F5: Model governance (PSI, approval) ?
? ?
? Output: APPROVE | DECLINE | REFER + justification ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 6. NARRATIVE AI (OpenAI-compatible, on-prem) ?
? ? POST /v1/chat/completions (vLLM/CM) ?
? ? Llm:* or optional ContextMemory gateway ?
? ? Temperature: 0.1 (deterministic) ?
? ? Grounding check (anti-hallucination) ?
? ?
? Output: 500-800 word report in Portuguese ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 7. DOCUMENT PROCESSING (OCR + AI) - NEW! ?
? ? TesseractOcrService (text extraction) ?
? ? LlmDocumentParsingService ? INarrativeLlmClient ?
? ? Support: PDF, PNG, JPG, TIFF ?
? ? 11 source types (CRC, Citius, etc.) ?
? ?
? Upload ? OCR ? LLM Parse ? Structured fields ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 8. MANUAL DATA ENTRY (Robust Fallback) ?
? ? ManualDataEntryService ?
? ? ManualDataEntryPolicy (field definitions) ?
? ? Triggered on: API failure | empty | incomplete ?
? ? UI forms + Document upload integration ?
? ?
? Pipeline resumes after manual entry ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 9. AUDIT & COMPLIANCE ?
? ? AuditLogService (immutable hash chain) ?
? ? SHA-256 linking ?
? ? Every action logged ?
? ? F1-F5 compliance enforcement ?
? ? Human review mandatory (MinReviewDurationMs) ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 10. MODEL RISK MANAGEMENT (MRM) ?
? ? ModelRegistryService (versioning) ?
? ? ModelBacktestingService (validation) ?
? ? ModelDriftMonitor (PSI continuous) ?
? ? ModelPromotionGate (thresholds) ?
? ?
? Metrics: AUC, Gini, Brier, PSI, PD calibration ?
???????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????
? 11. EARLY WARNING SYSTEM ?
? ? EarlyWarningBatchHostedService (60 min) ?
? ? Re-consult CRC/CIRBE for approved credits ?
? ? Re-score with current model ?
? ? Detect: incidents, PD increase, PSI drift ?
? ? Alert: LOW | MEDIUM | HIGH | CRITICAL ?
? ?
? Continuous post-approval monitoring ?
???????????????????????????????????????????????????????????????
- Domain at the center (agnostic)
- Application defines contracts (interfaces)
- Infrastructure implements (external dependencies)
- Presentation consumes Application
- Every component injected via DI
- Easy substitution (Stub ? Production)
- Maximum testability
- Clear unidirectional flow
- Each phase independent
- Rollback/retry per phase
- Audit at each transition
- API fails ? Manual data entry
- LLM fails ? Skip narrative
- Model unavailable ? Baseline scoring
- Never completely blocks
- F1-F5 gates mandatory
- Immutable audit log (hash chain)
- Human review mandatory
- SHAP explainability always
- OpenAI-compatible local LLM (vLLM/etc.); optional ContextMemory ? not cloud SaaS LLM
- Tesseract local (not cloud OCR)
- PostgreSQL local
- Zero data leakage
| Layer | Technology | Version |
|---|---|---|
| Runtime | .NET | 9.0 |
| Web UI | Blazor Server | 9.0 |
| API | ASP.NET Core | 9.0 |
| Database | PostgreSQL | 9.0+ |
| ORM | Entity Framework Core | 9.0 |
| ML Runtime | ML.NET + ONNX | 1.21 |
| LLM | OpenAI-compatible /v1 (qwen3.5:9b) |
Local / CM |
| OCR | Tesseract | 5.2 |
| Image Processing | ImageSharp | 3.1 |
| PdfSharpCore | 1.3 | |
| Charts | ApexCharts + MudBlazor | Latest |
| Auth | ASP.NET Identity + Entra | 9.0 |
| Telemetry | App Insights (optional) | - |
- Repository Pattern - EF Core DbContext
- Strategy Pattern - IDataProvider implementations
- Factory Pattern - Agent creation
- Observer Pattern - Early Warning monitoring
- Chain of Responsibility - Solvency rules F1-F5
- Builder Pattern - Feature vector construction
- Facade Pattern - CreditDecisionPipeline
- Template Method - Collection agents base
- Singleton - Model Registry
- Dependency Injection - Entire system
- Average latency: 8.5s (full pipeline)
- Throughput: 50-100 requests/hour
- DB connection pool: 100 connections
- Memory: ~512MB per instance
- Target uptime: 99.9%
- Failover: Manual data entry
- Health checks:
/healthendpoint - Graceful degradation: Stubs in dev
- Horizontal: Stateless API (load balancer ready)
- Vertical: Blazor SignalR (WebSockets)
- Database: PostgreSQL read replicas
- Caching: In-memory (session state)
- Auth: Identity + Entra ID
- Authorization: Claims-based policies
- Data at rest: PostgreSQL encryption
- Data in transit: HTTPS/TLS 1.3
- Audit: Immutable hash chain
- Secrets: Azure Key Vault (production)
- Tests: 95 integration tests
- Coverage: >80% (critical pipeline)
- Documentation: Docs/ folder
- Code standards: EditorConfig + analyzers
- Versioning: Semantic (Major.Minor.Patch)
- Logs: Structured (JSON)
- Metrics: Performance counters
- Tracing: Correlation IDs
- Alerts: Early Warning + Drift
- Dashboards: MudBlazor charts
# Web
cd src/CreditAI.Web
dotnet run
# ? http://localhost:5188
# API
cd src/CreditAI.API
dotnet run
# ? https://localhost:7257# Multi-stage build
FROM mcr.microsoft.com/dotnet/sdk:9.0 AS build
WORKDIR /src
COPY . .
RUN dotnet publish -c Release -o /app
FROM mcr.microsoft.com/dotnet/aspnet:9.0
RUN apt-get update && apt-get install -y \
tesseract-ocr tesseract-ocr-por
WORKDIR /app
COPY --from=build /app .
EXPOSE 80 443
ENTRYPOINT ["dotnet", "CreditAI.API.dll"]# Create migration
dotnet ef migrations add MigrationName -p src/CreditAI.Infrastructure
# Apply to database
dotnet ef database update -p src/CreditAI.Infrastructure- Complete Pipeline - Technical details of each phase
- Integrations - Data provider configuration
- Document Processing - OCR + AI parsing
- Compliance F1-F5 - Regulatory rules
- Model Registry - ML model management
Specialized component that collects and normalizes data from a specific area (behavioral, financial, etc.). Implements ICollectionAgent.
Set of 50+ normalized numerical variables that feed the ML scoring model. Built from data collected by agents.
Deterministic compliance gates that evaluate specific risks. Block automatic decisions if triggered.
Fallback system that allows manual data entry when API integrations fail. Keeps pipeline always functional.
Shapley values that explain the contribution of each feature to the final score. Critical for explainability and compliance.
ML model versioning and governance system. Only approved models (passing quality gates) can be used in production.
Post-approval monitoring system that re-evaluates approved credits periodically, detecting early deterioration.
Immutable log where each entry contains the hash of the previous entry, ensuring integrity and detecting tampering.
CreditAI v1.0 - AI-Powered Credit Analysis System
Built with .NET 9, Blazor, PostgreSQL, OpenAI-compatible LLM and ML.NET