Skip to content
LiveSaaSYargıtay · Regional Courts · Constitutional Court

CestaLex

AI-assisted case-law research platform for the Turkish courts

Role
Co-founder · Backend architecture
Period
2026 —
Status
Live
Links
Visit site ↗

By the numbers

3
isolation layers
3
high-court corpora
0
manual invoicing steps
SHA-256
chained audit log

Overview

A case-law research platform for law firms, covering Yargıtay, the regional courts of appeal and the Constitutional Court, with semantic search, a streaming AI assistant and a document editor.

  • Multi-tenant architecture: each law firm's data is isolated from the others in three independent layers, including PostgreSQL Row-Level Security.
  • JWT/OAuth sessions, UYAP e-signature for legally binding actions, plus 2FA and role-based access for privileged operations.
  • Transactional outbox over Kafka for lossless event delivery between services; a SHA-256 chained, tamper-evident audit log.
  • Semantic search built on Qdrant and Gemini, with a streaming RAG assistant.
  • Subscription payments through iyzico, automatic e-arşiv invoicing through Paraşüt; deployed with CI/CD on Kubernetes and Coolify.

01

Problem

CestaLex is a SaaS product serving many law firms on the same infrastructure. Each firm's client files and research history must be strictly separated from the others. Relying only on query filters in application code is not a sufficient guarantee: a single missing filter could leak data.

On top of that, the legal domain asks for two more things: legally binding actions (UYAP e-signature) and a record of every change that cannot be rewritten after the fact.

02

Approach

Isolation lives in three independent layers rather than one place: tenant identity bound to the request context, mandatory tenant scoping in the service layer, and PostgreSQL Row-Level Security policies at the bottom. Even if both upper layers are bypassed, the database refuses to return the wrong row.

Inter-service communication uses the transactional outbox pattern: the event is written in the same transaction as the business data, then relayed to Kafka. A service dying mid-write no longer loses a state transition.

The audit log is hash-chained with SHA-256; each entry carries the digest of the previous one. A retroactive edit breaks the chain and becomes detectable.

On the search side, judgments are embedded into Qdrant, a Gemini-backed microservice answers semantic queries, and the RAG assistant streams its response. The document editor versions files on S3-compatible storage and exports PDF, Word and UDF.

03

Architecture

  1. Client
    • React SPA
    • Belge editörü
  2. Edge
    • Nginx
    • JWT / OAuth2
    • UYAP e-imza
    • 2FA · RBAC
  3. Services
    • Core API
    • Arama servisi
    • RAG asistanı
    • Fatura (Paraşüt)
  4. Events
    • Outbox
    • Kafka
    • Denetim zinciri
  5. Data
    • PostgreSQL + RLS
    • Redis
    • Qdrant
    • S3
  6. Deployment
    • Docker
    • Kubernetes
    • Coolify
    • CI/CD
↓ Data flows top to bottom

04

Key decisions

  1. 01

    Row-Level Security as the last line of defence

    RLS policies apply the tenant filter at the database level on every query. The performance cost is low, and a bug in application code can no longer leak data.

  2. 02

    Outbox: write the event first, publish second

    Publishing straight to Kafka leaves a 'written but never published' window. The outbox table closes it; a relay process drains the queue.

  3. 03

    Keep model calls off the request path

    The AI assistant is its own microservice; long model calls never block the main API and the answer streams down to the user.

Outcome

The platform is in production serving law firms. The payment flow runs from subscription to a valid e-arşiv invoice through the Paraşüt integration with no manual step, and multi-repo CI/CD brought an enterprise release down to a single pipeline run.

What I learned

“Tying security requirements such as data isolation to the database layer rather than application code is both safer and easier to maintain. That was the most important architectural decision in this project.”

Related projects

  • SaaS
    Live

    CestaLaw

    Research platform for European Court of Human Rights case law

    Sister product to CestaLex, focused on European Court of Human Rights case law and expanding toward wider European jurisdictions.

    1
    shared platform foundation
    2
    distinct jurisdictions
    • Java
    • Spring Boot
    • React
    • Kafka
    • Redis
    • Docker
  • Backend
    In development

    TradeHub

    Barter marketplace with a two-sided confirmation protocol

    A barter marketplace. With no escrow, trust between two strangers is built through a two-sided confirmation protocol.

    2
    phase confirmation protocol
    5+
    microservices
    • Java
    • Spring Boot
    • PostgreSQL
    • Kafka
    • Redis
    • Docker
    Open
  • Backend
    Private repo

    Taskify

    Five microservices, sub-20ms real-time synchronization

    Task management across five decoupled microservices, with Redis and Kafka syncing state between active users at sub-20ms latency.

    5
    microservices
    <20ms
    sync latency
    • Java
    • Spring Boot
    • Redis
    • Kafka
    • PostgreSQL
    • Docker
    Open