← Missions

Senior FastAPI + React team needed: secure estate-financial workpaper platform — $8,000 fixed price

Budget: $8000.0 FIXED / ⭐ 1.00 (1) USA

python, react-js, amazon-web-services, payment-gateway-integration

Qualifications préférées

  • Expérience : Expert
Senior FastAPI + React team needed: secure estate-financial workpaper platform — $8,000 fixed price Contract: Fixed price — $8,000 total Team requirement: Exactly two named people: a senior technical lead and an implementer Engagement: Remote Schedule: State a realistic delivery schedule in your proposal What you will build The AI Executor is a production web application for executors and solo legal/accounting professionals. Customers upload financial records they already possess. The application creates source-linked financial workpapers, compares references across records, identifies evidence that needs follow-up, and delivers a professional PDF and transaction-level CSV. This is an evidence and reconciliation product—not legal, probate, investment, ownership, or tax advice. It must report only matched, possible match, and unmatched reference evidence. It must never call an account a “hidden asset,” decide ownership, decide an estate or legal issue, or make a tax conclusion. The owner supplies written specifications, prototypes, public site, fixtures, owner-console frontend, and typed owner-console contract. The contractor builds, integrates, tests, deploys, and hands off the system. The owner pays all cloud, API, and SaaS charges. Required team model This is not a solo engagement or a rotating agency bench. Name the senior lead and the implementer in the proposal and before signing. The senior lead personally owns architecture, database schema, RLS, reconciliation, encryption, authentication, payment state machine, approval snapshot, and owner-console aggregation. The implementer builds the React workflows, Uppy upload experience, correction UX, facility workflow, outputs, transactional email, and product wiring. The senior lead reviews all work and remains responsible for the delivered system. Substitution requires written approval. Frozen architecture — no substitutions Use this architecture exactly: Backend: Python 3.11 and FastAPI Frontend: React SPA with Vite Database: Supabase Postgres with server-enforced Row Level Security Identity: Clerk using Supabase’s native Clerk provider Document storage: private AWS S3 only, presigned access only, and seven-day source-document deletion Uploads: Uppy S3 uploads Jobs: pgmq plus a Render background worker; no Redis Hosting: Render Payments: Stripe only Email: Resend PDFs: WeasyPrint Malware/security monitoring: ClamAV plus AWS GuardDuty Bot protection: Cloudflare Turnstile Error monitoring: Sentry Team with aggressive PII scrubbing Uptime/status/worker monitoring: Better Stack Public-site policy tooling: owner-supplied Termly Pro+; integrate the owner/counsel-approved privacy and terms content only, never lead consent Document reading and extraction boundary Azure Document Intelligence v4.0 is the only production document-reading and extraction vendor. Use: Azure Read for scanned or image-only records; Azure custom classification for document-family routing and mixed-document splitting; Azure prebuilt prebuilt-tax.us.1099INT, prebuilt-tax.us.1099DIV, prebuilt-tax.us.1099B, prebuilt-tax.us.1099R, and prebuilt-tax.us.1099Combo models; and Azure custom and generative extraction for the other launch document families. OpenAI, Anthropic, and every other LLM or vendor are prohibited from receiving customer documents or extracted customer data. Do not introduce another OCR, document-extraction, hosted reconciliation, hosted matching, hosted sharing, or hosted deduplication vendor. Python performs every delivered calculation and every final match decision in integer cents, with a $0.00 tolerance. Azure output is extraction input only; it never decides a financial conclusion, reconciliation result, or final record match. Approved local libraries Use these approved libraries rather than rebuilding their functions, and preserve required license notices: OCRmyPDF with pypdfium2 plus pikepdf/qpdf for repair, page handling, DPI/readability checks, deskew, normalization, and compression; do not introduce Ghostscript or its AGPL dependency. pgTAP for Postgres and RLS tests. Pandera for extraction validation. react-jsonschema-form for schema-driven field correction. Splink, under its MIT license, locally and only for candidate scoring. Maintained free-email and disposable-domain lists for recipient screening. Do not use Supabase Storage, Redis, Retool, a hosted PDF renderer, merchant of record, carrier API, hosted sharing/reconciliation/deduplication vendors, or embedded encrypted payload/regeneration products. Launch records and evidence rules Support customer-supplied records in these launch families: Checking and savings statements. Credit-card statements. Taxable individual/joint brokerage, cash-management, mutual-fund, managed/advisory, transfer-agent/direct-registration, and inherited taxable accounts. Traditional, Roth, rollover, inherited/beneficiary, SEP, and SIMPLE IRAs. 401(k), 403(b), governmental 457(b), TSP, defined-contribution, and profit-sharing plans. 1099-INT, 1099-DIV, 1099-B, and 1099-R. Customer-supplied consumer credit reports. Prior-year tax returns are optional supporting uploads only. Do not interpret them and do not try to separate a joint return. For investment and retirement records, capture source-linked printed facts such as account identity/title/type, periods, values where printed, holdings, cash, contributions, transfers, distributions, withdrawals, fees, linked-bank references, and printed beneficiary/TOD wording. Pensions, annuities, and complex/private assets may be recognized factually only: no valuation and no ownership conclusion. For credit reports, extract discovery evidence only: institution, masked account reference, printed account type/status, open/close dates, collections, aliases, inquiries, and source provenance. Do not obtain credit reports, pull credit, score creditworthiness, or contact institutions. Upload window, quality, and page limits For every statement-based account, request all of the following: The 12 most recent consecutive statements; The statement containing the date of death; and At least two full months before the month of death. If the 12 recent statements do not cover the date-of-death or two-full-month requirement, request the missing older statements. Use standard resolution and document-quality limits. Explain quality issues clearly, show the file name and page number, never silently discard pages, and let a customer remove or replace failed documents. The consumer workpaper includes up to 200 accepted pages. Customers see page counts, never byte-based pricing. Accepted pages Consumer workpaper price 1–200 $499 201–300 $548 301–400 $597 401–500 $646 501–600 $824 601–700 $873 701–800 $922 801–900 $971 901–1,000 $1,020 Each started 100-page block after page 200 adds $49. Apply one $129 large-matter fee above 500 pages. The absolute maximum is 1,000 pages. Matters from 501–1,000 pages run through overnight processing. Stop before the cap and request a smaller or separate matter rather than losing pages. For overnight matters, show a queued status and expected processing window, send a completion or action-required email, and use bounded retries with an owner-visible failure path. Processing, verification, and correction Build the local intake pipeline for PDF repair/normalization, duplicate and blank-page detection, page counting, DPI/readability checks, and malware checks. Before payment authorization, run local preflight only—no paid Azure processing. After authorization, classify, split, read, extract, and validate records using Azure and the approved local components. Preserve page and line provenance for each extracted field. Use versioned schemas per document family, shared by Pandera validation and the correction UI. Flag low-confidence fields. Do not automatically train on customer documents. Maintain a versioned layout registry keyed by institution, document family, and layout fingerprint. Any layout-specific instruction requires a fixture and regression test. Unfamiliar layouts must fail safely rather than produce an unsupported workpaper. Verification must include appropriate independent checks: date ordering, signs, running-balance continuity, and family-specific structure. Checking and savings reconciliation must reach exactly $0.00. For cards, investment, and retirement statements, perform independent checks when independent printed totals exist; otherwise label the result extracted, not fully reconciled. For 1099s and credit reports, perform completeness and provenance checks rather than pretending they are bank reconciliations. Never derive a printed total from the extracted transactions and compare it to itself. Provide field-level correction. Every change must be append-only, retaining original and corrected values, editor, timestamp, and source page. Approval creates an immutable approved snapshot that is the only source for final outputs. Cross-document account discovery Build a normalized, source-linked reference for each supported record: institution, document family, printed account type, masked identifier, printed holder name, period, file, page, and line. Compare evidence across the supplied set, including: transfers and deposits between accounts; distributions into banks; credit-card payments; institution and account clues; credit inquiries; and 1099 payers and account references. Return only matched, possible match, and unmatched reference results, with evidence and missing-document requests where appropriate. Do not decide ownership, legal issues, or tax treatment. Splink may rank candidate pairs locally. A deterministic Python rule or human review must make the final decision and record why; a probabilistic score never creates a delivered match. The executor or professional must be able to confirm, reject, leave unresolved, or annotate a possible match. Preserve the original result and audit every review action. Products, payments, and fulfillment Launch products Build these launch products: Product Price Consumer estate workpaper $499 base, subject to the page table above Consumer/client white-glove handling $149 Firm evidence PDF $349 Firm transaction CSV $349 Firm PDF + CSV bundle $499 Firm client-upload link $39 Maryland executor lead Configurable Stripe price Use Stripe catalog lookup keys; do not hardcode product prices in pages or components. Consumer checkout must not display firm-only or deferred products. All prices are tax-exclusive. Maryland-only tax is configurable by product and customer type, stored separately on each order, and buyer state is required. The local database is the system of record. Create one Stripe adapter/import module and reconcile charges, refunds, and disputes into local tables for the supplied owner-console contract. Authorize first, read second, capture last For paid processing orders, implement this idempotent state machine: Upload to temporary encrypted holding. Run local preflight only. Authorize the full total, including tax, through a Stripe PaymentIntent with manual capture. Only after authorization, run paid Azure extraction, cross-document processing, and deterministic verification. Finalize the billable page count before capture. Capture once, only after processing succeeds for the customer-approved set. If processing fails, cancel without capture and allow removal/replacement of failed records. If an authorization expires, require explicit customer reauthorization; never attempt delivery on an expired hold. Model authorization, capture, cancellation, expiration, and payment failure separately and idempotently. Respect Stripe’s one-capture constraint. No receipt or revenue entry exists until capture. White-glove/mail-in handling The $149 white-glove handling fee is separate from document processing. Build a minimal restricted facility workflow, with no carrier API: The customer requests pickup, provides an estimated page range and payment method, and is not charged merely for scheduling. Facility staff use their existing shipping process and enter carrier/tracking details. After verified carrier possession, an authorized facility user takes the idempotent Package picked up action. That action charges the $149 handling fee. The fee becomes nonrefundable upon carrier possession. The facility receives and scans copies, records the actual accepted page count, and sends the processing price for customer approval. The customer-approved processing amount then follows the manual-authorize/capture flow above. Mail-in instructions must request legible copies only, never originals. Prefer standard black-and-white or grayscale copies; request color only where color carries information. A firm’s $39 client-upload link offers secure digital upload or this existing individual white-glove path; the individual pays the $149 fee and the matter remains associated with the firm. Do not build a separate firm mail-in workflow. Delivery, sharing, and revenue acquisition Application surfaces A consumer portal for intake, upload, order status, payment, delivery and sharing. A single-user firm dashboard for client matters, source-linked review, correction, approval and delivery. A restricted facility screen only for pickup confirmation, tracking reference, accepted page count and customer price approval. A thin authenticated backend for the supplied owner-console frontend and typed contract, using version-controlled Postgres aggregation views. Outputs Deliver source-linked account inventory, workpaper PDF, transaction-level CSV, transfer/disbursement schedules, and schedules for possible matches, unmatched references, missing periods, and unreadable evidence. Unapproved drafts carry a For Attorney Review watermark. Firm branding is text-only; no logo uploads. Secure sharing with attorneys and CPAs Build a secure share flow, not public download links: The executor selects Attorney or Accountant and enters the recipient’s exact email address. Block known consumer and disposable domains using the approved local lists; require a professional/firm-controlled domain. Require an exact-email OTP before access. Let the executor select which completed outputs to share. Source documents are excluded by default and require explicit selection. Issue short-lived presigned URLs only after authorization checks. Track Draft, Sent, Opened, Downloaded, Expired, and Revoked status with timestamps. Allow resend, revoke, and history viewing. Retention is unchanged by sharing; do not create permanent duplicate files. Show the firm-account or paid-product call to action only after the recipient completes access; it must never block or condition access to shared files. No public links, no SMS, and no tracking pixels. A newly verified professional account receives two free professional credits, once per account. Use a transactional Postgres ledger so concurrent requests cannot spend the same credit twice. Eligible products are driven by Stripe metadata. After credits are exhausted, show normal paid checkout; never charge automatically. Maryland executor leads Build the consented Maryland lead sale feature, but it must stay disabled until written counsel approval is recorded. Consent for lead contact/sale is separate from sharing consent. The executor chooses attorney and/or accountant contact permission. Store the consent-document version and exact text hash shown to the executor, with append-only audit history. A consented lead may be sold to no more than three verified professionals. Do not include financial records, source documents, reports, account numbers, or transaction data in a lead. Use a configurable Stripe product for the sale. Include global and per-state default-deny switches with enabled state, written-counsel-approval date, approved-terms version, and maximum buyer count. Block all sales unless the global switch and Maryland switch are enabled and the Maryland written-counsel-approval date is present. Every non-Maryland state remains disabled. Enforce the buyer cap and permitted purchase in one database transaction. Security, privacy, operations, and acceptance Security is part of the build, not a future enhancement: AES-256-GCM envelope encryption for documents and protected payloads. RLS keyed to Clerk identity, with pgTAP tests proving tenant isolation, owner-only access, restricted facility access, and professional-share scope. Append-only audit events for consent, PII access, sharing, revisions, payment-sensitive actions, and deletion. Private S3, presigned URLs, and seven-day source-document deletion. Clerk email/password identity with email-code sign-in, rate limits/lockout, session refresh/revocation, and self-service recovery. Signed, time-limited paid-delivery recovery links so a completed purchase remains accessible if the customer's normal account session is unavailable. Cloudflare Turnstile on public upload, verification, sharing, and lead-purchase forms. Transactional Postgres counters for per-email OTP attempts and lead/credit actions that must remain correct under concurrent requests. No SMS, passkeys, or remembered-device feature. Resend on a dedicated transactional subdomain with SPF, DKIM, and DMARC. Email is plain, has no tracking pixels, and logs bounce/complaint events for the owner. Sentry Team scrubs document content, account identifiers, and PII before transmission. Better Stack monitors application uptime, status, and overnight-worker heartbeats. Document enabled backup plan, recovery point objective, restore procedure, and a completed security review before production acceptance. Explicitly deferred or out of scope Do not include these items in the build: Probate form population, including Maryland probate forms. Other states’ lead or probate products. Firm volume discounts. Passkeys or remembered devices. Support bot. Separate firm mail-in workflow. Multi-user firms, seats, or invitations. Firm logo uploads. Bar API verification. Automatic credit pulls. Native mobile apps. SMS. Carrier API or automated tracking integration. Supabase Storage, Redis, Retool, hosted PDF rendering, merchant of record, hosted file-sharing/reconciliation/deduplication services, or embedded encrypted payload/regeneration. Fixed-price milestones The complete contract is $8,000 fixed price and has exactly five milestones: Milestone Amount Acceptance outcome 1. Architecture $800 Architecture, schema, RLS model, document contracts, fixture plan, threat model, and delivery schedule approved before implementation. 2. Foundation $1,800 Clerk/Supabase identity, migrations and pgTAP RLS tests, private S3, audit log, pgmq worker, upload/preflight, monitoring, and Stripe adapter work end to end. 3. Extraction and verification $2,200 All launch families work against supplied fixtures; bank reconciliation reaches $0.00; provenance, safe layout failure, verification, and cross-document evidence pass acceptance. 4. Revenue and delivery $2,000 Consumer and firm flows, corrections/snapshots, PDF/CSV, secure sharing, credit ledger, disabled-by-default Maryland controls, mail-in operations, page pricing/tax, and owner console pass acceptance. 5. Production acceptance holdback $1,200 Production deployment, backup/restore documentation, security-review remediation, full regression suite, handoff, and one week of bug support for scope defects. The final milestone is an acceptance holdback. Additions after architecture acceptance require a written change order; omissions or defects against this posting do not. Milestone acceptance and evidence requirements A milestone is not complete merely because it has been demonstrated or described as finished. Payment is released only after the applicable acceptance outcome is met, the required evidence is delivered, and the owner provides written acceptance through Upwork. Every milestone submission must include: A requirement-by-requirement completion checklist. The relevant commit hash and release tag in an owner-controlled repository. A working staging URL when the milestone includes executable software. CI and automated-test results that the owner can inspect. Updated migrations, schemas, fixtures, configuration examples, and operating documentation. A list of known defects, limitations, failed tests, and unresolved decisions. A milestone may not be represented as complete while concealing a known material defect. A short recorded demonstration or live walkthrough of the required workflows and failure cases. Written senior-lead review and sign-off. The owner may test the submission directly or use an independent technical reviewer. Failed acceptance items remain part of the fixed-price milestone and are not change orders unless they result from a new requirement approved after architecture acceptance. Milestone 1 acceptance checklist: Architecture Architecture diagram identifies every application, worker, datastore, queue, processor, trust boundary, and external service. Database schema, migrations plan, Clerk-to-Supabase identity mapping, and local order system of record are defined. RLS access matrix covers consumer, firm, owner, restricted facility, worker/service, and professional-share access. State machines cover matters, uploads, preflight, payment authorization/capture/expiry, processing, corrections, approval, delivery, sharing, credits, mail-in, and lead controls. Structured field contracts and validation rules exist for every launch document family. Owner-reviewable fixture plan includes expected values, difficult layouts, cross-document examples, unreadable pages, joint or unclear evidence, and safe-failure cases. Threat model covers unauthorized matter access, document leakage, share-link misuse, OTP abuse, duplicate capture, credit double-spend, lead-cap races, deletion failures, and compromised workers. Delivery schedule, dependencies, assumptions, and exclusions are explicit. No implementation begins until the owner approves this milestone in writing. Milestone 2 acceptance checklist: Foundation Clerk authentication protects every nonpublic route and server endpoint. Supabase RLS and pgTAP tests prove permitted access and denied cross-user, cross-firm, facility, share-recipient, and owner-access cases. Private S3 uploads use short-lived presigned access and cannot be listed or downloaded publicly. Uppy upload, local malware/file-integrity/page-count/text-layer/image-resolution preflight, and page-specific error reporting work end to end. The system enforces the 1,000-page maximum before paid document reading. pgmq processing survives worker interruption, records retries, and exposes dead-letter or action-required failures. Append-only audit events are generated for sensitive access and state changes. Stripe test mode supports manual authorization without immediate capture, idempotency, cancellation, expiry, and reauthorization foundations. Sentry, worker health, queue health, and operational alerts receive test events. Negative tests include unauthorized matter access, corrupt files, malware test files, duplicate requests, worker interruption, and expired authorization. Milestone 3 acceptance checklist: Extraction and verification Owner-approved fixtures are frozen before the extraction and reconciliation implementation is accepted. All launch document families pass their approved fixtures, including 1099-INT, 1099-DIV, 1099-B, and 1099-R. Every delivered value retains source-document, page, and evidence provenance. AI and OCR read or structure evidence but do not perform delivered arithmetic or decide account matches. Deterministic Python calculations use integer cents, and bank reconciliation reaches exactly $0.00 where the fixture is reconcilable. Cross-document discovery produces matched, possible-match, and unmatched-reference states using deterministic rules. Joint, spouse-linked, ambiguous, or legally uncertain evidence is routed to professional review rather than classified as estate property. Unfamiliar, incomplete, or unreadable layouts fail safely without silent page skipping or invented values. Regression results include expected values, actual values, pass/fail status, and any approved tolerances. Screenshots alone are not acceptance evidence. Milestone 4 acceptance checklist: Revenue and delivery End-to-end consumer purchase passes for the $499 base product, every approved page tier, the greater-than-500-page fee, and the 1,000-page stop. End-to-end firm purchases pass for the $349 PDF, $349 CSV, $499 bundle, and $39 client-upload link. The payment sequence is proven in test mode: temporary upload, local preflight, manual authorization, paid extraction, final accepted-page approval when required, successful output, and one idempotent capture. Processing failure cancels without capture; expired authorizations require reauthorization; repeated requests cannot duplicate a charge. Per-field correction history preserves original value, replacement value, evidence, actor, time, and immutable approved snapshot. PDF and CSV outputs pass content, provenance, language, and download tests. Attorney/CPA sharing passes professional-domain screening, exact-email OTP, selected-output authorization, source-documents-off default, expiration, resend, revoke, opened/downloaded history, and audit tests. Two professional credits are granted and spent through an atomic ledger; concurrent requests cannot overspend or duplicate a grant; paid checkout requires affirmative action after credits are exhausted. White-glove service passes request, restricted facility access, carrier/tracking entry, authorized pickup confirmation, one idempotent $149 charge, actual accepted-page count, and processing-price approval. Maryland lead controls remain default-deny and cannot activate without the global switch, Maryland switch, counsel-approval date, exact consent record, verified buyer, and three-buyer maximum. Owner-console totals reconcile to the local order ledger and distinguish authorization from captured revenue, tax, processor fees, refunds, disputes, credits, mail-in revenue, and lead revenue. Negative tests cover wrong or expired OTPs, revoked links, duplicate clicks, concurrent credit spend, fourth lead buyer, failed extraction, capture retry, and facility double-charge attempts. Milestone 5 acceptance checklist: Production acceptance holdback Production deployment, domains, HTTPS, email authentication, secrets, environment separation, and least-privilege service access are configured. The complete regression suite passes against the production release candidate. Critical and high-severity findings from the required security review are remediated and retested. Backup and restore are demonstrated into a clean environment; documentation alone is not sufficient. Seven-day document deletion, deletion-failure alerting, audit preservation, and recovery-access boundaries pass acceptance. Owner-controlled accounts, repositories, cloud resources, domains, billing access, deployment keys, and recovery methods are transferred or verified. Deployment, rollback, restore, queue recovery, payment recovery, deletion, facility, sharing, credit, and lead-control runbooks are delivered. No critical or high-severity scope defect remains open at release. Handoff is complete, and the included one-week bug-support period covers defects against the accepted scope. The $1,200 holdback is released only after final acceptance and completion of the included defect-support obligation. If an acceptance test fails, the contractor must correct the defect and resubmit the milestone with updated evidence. The owner will provide a written defect list and will not unreasonably withhold acceptance after every contractual requirement has passed. What to include in your proposal A complete proposal must: Name both people and identify the senior lead. State a realistic schedule. Identify the single highest-risk part of the work and explain why. Explicitly accept the complete $8,000 fixed-price scope and all five milestone amounts. List any exclusions clearly; do not silently omit required work. Confirm the senior lead will personally own architecture, schema, RLS, reconciliation, crypto, auth, payment, approval, and owner aggregation—and review all work. Confirm use of the frozen architecture, Azure-only document boundary, approved local libraries, and one week of bug support. The senior lead must be available for a technical screen covering deterministic reconciliation, Clerk-to-Supabase RLS, Stripe manual capture, private uploads and queued processing, secure professional sharing/credit ledger, facility pickup charging, and Maryland consent/buyer-cap controls.
Ouvrir sur Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Connexion