CASE STUDY · DDDECKS.AI
Production architecture for
DDDecks.ai.
DDDecks.ai is the full-stack product architecture behind an AI-assisted investor-deck workflow. It combines a SvelteKit frontend with a FastAPI backend, persistence, migrations, vector search, agent orchestration, observability and production safety controls.
THE PRODUCT DECISION
Reduce scope to the core upload-to-deck lifecycle.
V2 was deliberately narrowed to the customer journey that mattered most: authentication, uploading source material and moving through the Instant Deck generation lifecycle. Historical admin and non-MVP surfaces were removed from the active product direction to reduce drift and make the core workflow easier to harden.
FULL-STACK ARCHITECTURE
Frontend and backend separated cleanly.
- SvelteKit customer-facing application with Node deployment support.
- FastAPI backend for product APIs, workers, persistence and orchestration.
- SQLAlchemy + Alembic migrations for relational data.
- PostgreSQL and pgvector for structured records and vector retrieval.
- Zod and Pydantic schemas to keep frontend/backend contracts explicit.
AI + DOCUMENT PIPELINE
Built for more than prompt-in, text-out generation.
- PDF processing with PyMuPDF.
- Image handling with Pillow.
- Sentence-transformers and pgvector for embedding-based retrieval.
- LangChain and LangGraph for multi-step AI workflow orchestration.
- HTML/CSS parsing and Playwright support for rendering and validation flows.
- Object-storage support through boto3 for generated or uploaded artifacts.
PRODUCTION HARDENING
Operational safeguards built into the backend.
- Canonical JSON error payloads across HTTP and validation failures.
- Request IDs for traceability across services.
- OpenTelemetry instrumentation for production observability.
- Strict CORS configuration and security headers.
- Request-body size limits.
- Automatic redaction of secret-bearing capability URLs from logs.
- Unhandled exceptions recorded into failure-ticket workflows.
- Startup protection against duplicate API method/path registrations that could silently shadow handlers.
SECURITY DESIGN
Secrets and capability URLs treated as sensitive infrastructure.
The backend avoids leaking opaque share/render tokens into access logs, applies no-store caching rules to API responses, sets strict browser security headers, and separates authenticated product routes behind resource-access checks. These controls show a production mindset beyond basic feature implementation.
WHAT THIS DEMONSTRATES
AI product engineering plus platform discipline.
DDDecks.ai demonstrates how to take an AI product from a broad experimental codebase toward a smaller, safer, observable and deployable system. It combines AI workflow design, document processing, vector infrastructure, frontend/backend contract discipline, security controls and operational tooling in one product architecture.