io.github.stephenballot-ai/legacy-shield

AI 与智能体

by stephenballot-ai

为 AI agents 提供零知识加密保险库,支持持久化加密存储,数据托管于 EU,兼顾安全与合规。

什么是 io.github.stephenballot-ai/legacy-shield

为 AI agents 提供零知识加密保险库,支持持久化加密存储,数据托管于 EU,兼顾安全与合规。

README

Legacy Shield

Secure digital vault for critical documents with emergency access. 100% European hosting.

Legacy Shield is a privacy-first document vault designed for storing your most critical files—passports, wills, insurance policies, property deeds—with built-in emergency access for loved ones. Unlike general cloud storage, Legacy Shield uses client-side encryption and European-exclusive infrastructure to ensure maximum privacy and security.

🌟 Key Features

  • 🔐 Zero-Knowledge Encryption: Files encrypted in your browser before upload
  • 🚨 Emergency Access: Loved ones can access your vault with unlock phrase (read-only)
  • 🇪🇺 European Data Sovereignty: 100% EU infrastructure (hosted on Hetzner, Germany)
  • 📱 Document Viewer: View PDFs, images, and documents in-browser
  • 🏷️ Smart Organization: Categories, tags, favorites, expiration tracking
  • ✅ GDPR Native: Privacy-first design, compliant by default
  • 🛡️ Powered by BitAtlas: Uses the BitAtlas zero-knowledge encryption layer for all file storage and key management.

🏗️ Architecture

Monorepo Structure:

code
legacy-shield/
├── packages/
│   ├── web/          # Next.js frontend (React + TypeScript)
│   ├── api/          # Express backend (Node.js + TypeScript)
│   └── shared/       # Shared types and utilities
├── infrastructure/   # Deployment configs
├── docker-compose.yml
├── product-spec.md   # Product specification
└── architecture-spec.md  # Technical architecture

Tech Stack:

  • Frontend: Next.js 14, TypeScript, TailwindCSS, Web Crypto API
  • Backend: Node.js, Express, Prisma ORM, PostgreSQL
  • Storage: Hetzner Object Storage (S3-compatible)
  • Hosting: Hetzner Cloud (Germany)
  • Payments: Stripe

🚀 Quick Start

Prerequisites

  • Node.js 20+ and npm 10+
  • Docker and Docker Compose
  • Git

1. Clone and Install

bash
cd /Users/stephenballot/Documents/LegacyShield
npm install

2. Start Infrastructure

bash
# Start PostgreSQL, Redis, and MinIO (local S3)
docker compose up -d

# Verify services are running
docker ps

Note: You can also use npm run docker:dev as a shortcut.

3. Configure Environment

bash
# Copy example environment file
cp .env.example .env

# Edit .env with your values (defaults work for local development)

4. Initialize Database

bash
cd packages/api

# Generate Prisma Client
npm run db:generate

# Run database migrations
DATABASE_URL="postgresql://legacyshield:devpassword@localhost:5432/legacyshield_dev" npm run db:migrate

# Optional: seed with test data
npm run db:seed

cd ../..

Note: The DATABASE_URL must be provided because Prisma doesn't automatically read the root .env file. See GETTING_STARTED.md for details.

5. Start Development Servers

bash
# Start both frontend and backend
npm run dev

# Or start individually:
npm run dev:web    # Frontend at http://localhost:3000
npm run dev:api    # Backend at http://localhost:4000

6. Access the Application

📚 Development

Available Scripts

bash
# Development
npm run dev              # Start all services
npm run dev:web          # Start frontend only
npm run dev:api          # Start backend only

# Building
npm run build            # Build all packages
npm run build:web        # Build frontend
npm run build:api        # Build backend

# Testing
npm run test             # Run all tests
npm run lint             # Lint all packages
npm run type-check       # TypeScript type checking

# Database
cd packages/api
npm run db:migrate       # Run migrations
npm run db:seed          # Seed database
npm run db:studio        # Open Prisma Studio
npm run db:reset         # Reset database

# Docker
docker compose up -d     # Start Docker services
docker compose down      # Stop Docker services
docker compose logs -f   # View Docker logs

Tip: For detailed setup instructions, see GETTING_STARTED.md

Project Structure

code
packages/
├── web/                          # Frontend (Next.js)
│   ├── src/
│   │   ├── app/                  # Next.js App Router
│   │   │   ├── (auth)/           # Auth pages (login, register)
│   │   │   ├── (dashboard)/      # Protected dashboard pages
│   │   │   └── emergency-access/ # Public emergency portal
│   │   ├── components/           # React components
│   │   ├── lib/
│   │   │   ├── crypto/           # Client-side encryption
│   │   │   ├── api/              # API client
│   │   │   └── utils/            # Utilities
│   │   ├── hooks/                # Custom React hooks
│   │   ├── store/                # Zustand stores
│   │   └── types/                # TypeScript types
│   └── package.json
│
├── api/                          # Backend (Express)
│   ├── src/
│   │   ├── routes/               # API routes
│   │   ├── middleware/           # Express middleware
│   │   ├── services/             # Business logic
│   │   ├── models/               # Data models
│   │   ├── jobs/                 # Background jobs
│   │   ├── utils/                # Utilities
│   │   └── server.ts             # Main server file
│   ├── prisma/
│   │   ├── schema.prisma         # Database schema
│   │   └── migrations/           # Database migrations
│   └── package.json
│
└── shared/                       # Shared code
    ├── src/
    │   ├── types/                # Shared TypeScript types
    │   ├── constants/            # Shared constants
    │   └── utils/                # Shared utilities
    └── package.json

🔒 Security

Legacy Shield implements a zero-knowledge architecture:

  1. Client-side encryption: All files encrypted in browser before upload
  2. Key derivation: Master key derived from password using PBKDF2 (100k iterations)
  3. Per-file keys: Each file encrypted with unique AES-256-GCM key
  4. Dual-key system: Files encrypted with both owner key and emergency key
  5. No plaintext storage: Server never sees unencrypted files or keys
  6. 2FA mandatory: Two-factor authentication required for all users

Encryption Flow

code
Password → PBKDF2 → Master Key → Encrypts file keys → AES-256-GCM → Encrypted file
                                                                           ↓
                                                              Hetzner Object Storage (Germany)

🇪🇺 European Data Sovereignty

All infrastructure is hosted exclusively in the European Union:

  • Compute: Hetzner Cloud (Falkenstein, Germany)
  • Database: Hetzner Managed PostgreSQL (Germany)
  • Storage: Hetzner Object Storage (Germany)
  • Backups: Automated backups to Nuremberg, Germany

Your data never leaves European soil and is protected by:

  • GDPR (General Data Protection Regulation)
  • German BDSG (Federal Data Protection Act)
  • No US CLOUD Act jurisdiction

📖 Documentation

🧪 Testing

bash
# Run all tests
npm run test

# Run tests for specific package
npm run test --workspace=web
npm run test --workspace=api

# Run tests in watch mode
npm run test:watch --workspace=web

# Run e2e tests
npm run test:e2e

🚀 Deployment

Production Deployment (Hetzner Cloud)

  1. Infrastructure Setup: See infrastructure/README.md
  2. Environment Variables: Configure production .env with real credentials
  3. Database Migration: Run migrations on production database
  4. Deploy: Use GitHub Actions or manual deployment
bash
# Build for production
npm run build

# Deploy to Hetzner (manual)
# See infrastructure/deploy.sh

CI/CD

GitHub Actions workflow automatically:

  • Runs tests on every PR
  • Builds and deploys to staging on develop branch
  • Builds and deploys to production on main branch

🤝 Contributing

This is a private project. For the development team:

  1. Create feature branch: git checkout -b feature/your-feature
  2. Make changes and commit: git commit -m "Add your feature"
  3. Push branch: git push origin feature/your-feature
  4. Create Pull Request on GitHub

Code Standards

  • TypeScript: Strict mode enabled
  • Linting: ESLint with Airbnb config
  • Formatting: Prettier (automatic on commit)
  • Commits: Conventional commits format

📊 Pricing

  • Free Tier: 15 documents, 1 emergency contact
  • Pro Tier: $10/month or $500 lifetime
    • 100 documents
    • 5 emergency contacts
    • Advanced features (expiration tracking, sharing, audit logs)

📄 License

Copyright © 2026 Legacy Shield. All rights reserved.

This is proprietary software. Unauthorized copying or distribution is prohibited.

🆘 Support


Built with ❤️ in Europe. Your data, your privacy, your legacy.

常见问题

io.github.stephenballot-ai/legacy-shield 是什么?

为 AI agents 提供零知识加密保险库,支持持久化加密存储,数据托管于 EU,兼顾安全与合规。

相关 Skills

Claude接口

by anthropics

Universal
热门

面向接入 Claude API、Anthropic SDK 或 Agent SDK 的开发场景,自动识别项目语言并给出对应示例与默认配置,快速搭建 LLM 应用。

想把Claude能力接进应用或智能体,用claude-api上手快、兼容Anthropic与Agent SDK,集成路径清晰又省心

AI 与智能体
未扫描176.4k

多智能体架构

by alirezarezvani

Universal
热门

聚焦多智能体系统架构设计,梳理 Supervisor、Swarm、分层和 Pipeline 等模式,覆盖角色定义、通信协作与性能评估,适合规划稳健可扩展的 AI agent 编排方案。

帮你系统解决多智能体应用的架构设计与协同编排难题,适合构建复杂 AI 工作流,成熟度高、社区认可也很亮眼。

AI 与智能体
未扫描26.0k

RAG架构师

by alirezarezvani

Universal
热门

聚焦生产级RAG系统设计与优化,覆盖文档切块、检索链路、索引构建、召回评估等关键环节,适合搭建可扩展、高准确率的知识库问答与检索增强应用。

面向RAG落地,把知识库、向量检索和生成链路系统串联起来,做架构设计时更清晰,也更少踩坑。

AI 与智能体
未扫描26.0k

相关 MCP Server

知识图谱记忆

编辑精选

by Anthropic

热门

Memory 是一个基于本地知识图谱的持久化记忆系统,让 AI 记住长期上下文。

帮 AI 和智能体补上“记不住”的短板,用本地知识图谱沉淀长期上下文,连续对话更聪明,数据也更可控。

AI 与智能体
89.7k

顺序思维

编辑精选

by Anthropic

热门

Sequential Thinking 是让 AI 通过动态思维链解决复杂问题的参考服务器。

这个服务器展示了如何让 Claude 像人类一样逐步推理,适合开发者学习 MCP 的思维链实现。但注意它只是个参考示例,别指望直接用在生产环境里。

AI 与智能体
89.2k

by deusdata

热门

持久化的代码库知识图谱,可跨会话保留上下文,在 session 重启或上下文压缩后仍能继续使用。

专治 AI 编程助手“会话失忆”,把代码库沉淀为持久知识图谱,重启或压缩上下文后也能无缝续上开发状态。

AI 与智能体
37.3k

评论