CASE STUDY · DDDECKS.AI

Production architecture for
DDDecks.ai.

DDDecks.ai is the full-stack product architecture behind an AI-assisted investor-deck workflow. It combines a SvelteKit frontend with a FastAPI backend, persistence, migrations, vector search, agent orchestration, observability and production safety controls.

SvelteKit FastAPI PostgreSQL pgvector LangChain LangGraph OpenTelemetry

THE PRODUCT DECISION

Reduce scope to the core upload-to-deck lifecycle.

V2 was deliberately narrowed to the customer journey that mattered most: authentication, uploading source material and moving through the Instant Deck generation lifecycle. Historical admin and non-MVP surfaces were removed from the active product direction to reduce drift and make the core workflow easier to harden.

FULL-STACK ARCHITECTURE

Frontend and backend separated cleanly.

  • SvelteKit customer-facing application with Node deployment support.
  • FastAPI backend for product APIs, workers, persistence and orchestration.
  • SQLAlchemy + Alembic migrations for relational data.
  • PostgreSQL and pgvector for structured records and vector retrieval.
  • Zod and Pydantic schemas to keep frontend/backend contracts explicit.

AI + DOCUMENT PIPELINE

Built for more than prompt-in, text-out generation.

  • PDF processing with PyMuPDF.
  • Image handling with Pillow.
  • Sentence-transformers and pgvector for embedding-based retrieval.
  • LangChain and LangGraph for multi-step AI workflow orchestration.
  • HTML/CSS parsing and Playwright support for rendering and validation flows.
  • Object-storage support through boto3 for generated or uploaded artifacts.

PRODUCTION HARDENING

Operational safeguards built into the backend.

  • Canonical JSON error payloads across HTTP and validation failures.
  • Request IDs for traceability across services.
  • OpenTelemetry instrumentation for production observability.
  • Strict CORS configuration and security headers.
  • Request-body size limits.
  • Automatic redaction of secret-bearing capability URLs from logs.
  • Unhandled exceptions recorded into failure-ticket workflows.
  • Startup protection against duplicate API method/path registrations that could silently shadow handlers.

SECURITY DESIGN

Secrets and capability URLs treated as sensitive infrastructure.

The backend avoids leaking opaque share/render tokens into access logs, applies no-store caching rules to API responses, sets strict browser security headers, and separates authenticated product routes behind resource-access checks. These controls show a production mindset beyond basic feature implementation.

WHAT THIS DEMONSTRATES

AI product engineering plus platform discipline.

DDDecks.ai demonstrates how to take an AI product from a broad experimental codebase toward a smaller, safer, observable and deployable system. It combines AI workflow design, document processing, vector infrastructure, frontend/backend contract discipline, security controls and operational tooling in one product architecture.

Need an AI product hardened for real users, data and production workflows?

Discuss your product →