Production SaaS
Rezzie: AI-assisted resume editing with a truth boundary
A resume-tailoring product built around grounded edits, review before export, and durable user workflows.

Overview
Rezzie helps a candidate tailor a resume to a role while treating their resume as the source of record. The product imports resume and job information, produces an editable draft, and keeps the candidate in control of what changes before export. It also includes saved resumes and drafts, billing, and a Chrome side panel that can pass a public job description into the same account workflow.
The product goal is useful emphasis, not invented experience: generated text must stay inside the facts the candidate supplied or explicitly trusted.
The problem
Resume tools can optimize for matching terms while quietly introducing unsupported numbers, credentials, employers, or responsibilities. A generated document is only useful if a person can compare it with their source material, understand what changed, and decide what to keep.
The engineering problem was to make that truth boundary part of the product flow, while supporting real document formats, authentication, stored work, and paid usage.
Architecture
- 01Web + extensionGuided tailoring and review flows
- 02FastAPIAuth, services, provider interface
- 03Claude + servicesGrounded generation and document safety
- 04SQLite + StripeSaved work and server-side entitlements
The web application is built with React and TypeScript; a Chrome Manifest V3 extension shares its authentication and API contracts. A FastAPI service handles Firebase token verification, resume and document workflows, LLM provider access, credit entitlements, and persistence. The deployed web assets are served through Cloudflare Workers, while the API runs in Docker on self-hosted infrastructure behind a Cloudflare Tunnel.
Engineering decisions
Ground generated content in user-owned sources
Resume facts remain the boundary for tailoring. The API validates structured provider responses and checks quantitative claims against source material; unsupported numbers are removed or rejected rather than quietly accepted. Trusted Sources are limited to sources the candidate owns and are fetched with bounded, SSRF-safe retrieval. Proposed source-backed edits remain reviewable and reversible.
Keep model providers behind an interface
The API uses an LLMProvider boundary for model calls. Provider credentials are request-scoped when a candidate supplies a key; managed credentials are used only after server-side entitlement checks. Credentials and sensitive resume content are not written into application logs.
Treat imports and billing as backend responsibilities
Document extraction, malware scanning, rate limits, and paid entitlements run on the server. Stripe webhook state is authoritative for credit grants and renewals, and webhook handling is idempotent. URL imports apply host checks, size bounds, timeouts, and redirect limits.
Technical challenge and solution
The hard part was connecting flexible language generation to durable, structured document workflows without confusing a polished response with a supported claim. Rezzie combines schema-validated generation, deterministic safety checks, user-scoped records, and an editor where changes can be reviewed before export. PDF, DOCX, and text exports follow the same saved draft rather than a separate browser-only path.
The extension avoids maintaining a second backend. It extracts the job description and uses the existing authenticated API and account workflow.
What I built
I built the web experience, FastAPI services, provider boundary, structured tailoring and review flow, document import/export, Firebase authentication, Stripe credit ledger and webhooks, persistent resume and draft records, and the Chrome extension integration.
Engineering takeaways
- Truth constraints need deterministic checks and a review interface, not just careful prompt wording.
- An AI feature becomes a product when identity, persistence, documents, billing, and recovery are part of the same workflow.
- A browser extension is easier to secure and maintain when it reuses the web product's API and user model.
Stack
React, TypeScript, Vite, Tailwind CSS, Python, FastAPI, SQLAlchemy, Alembic, SQLite, Firebase Authentication, Anthropic Claude, Stripe, ClamAV, Cloudflare Workers, Docker, and a Chrome Manifest V3 extension.
Stack
- TypeScript
- Python
- FastAPI
- Firebase
- SQLite
- Stripe