# Spring AI Secure RAG

Adrien Murillo — Murillo Consulting

Tenant-isolated RAG with verified citations and deterministic abstention.

Shows that authorization must filter retrieval before any content can enter model context.

## Architecture
Identity → ACL filter → VectorStore → Cited answer

Immutable server filter, idempotent ingestion, score threshold, server-built citations and a negative cross-tenant test.

mvn verify and the container build reproduce the contract without an external model key.

The in-memory index and header identity are explicitly limited to the local demonstration.

[GitHub](https://github.com/murillo-consulting/spring-ai-secure-rag)



## Navigation
- [Independent engineer and trainer.](/en/profil)
- [Engineering services.](/en/services)
- [Selected work.](/en/realisations)
- [Open-source projects.](/en/projets)
- [Guides to put into practice.](/en/ressources)
- [Let’s discuss your project.](/en/contact)
- [From scope to handover.](/en/approche)
- [Real contexts. Real constraints.](/en/secteurs)
- [Learn by making decisions.](/en/lab)
- [Legal notice](/en/mentions-legales)
- [Privacy](/en/confidentialite)
- [Train your teams. Through practice.](/en/formation)

[Contact](mailto:contact@adrien-murillo.com)
