Technical Whitepaper

FastFiller Security Architecture

Published: September 30, 2026 · Technical Specification v1.0.0

1. Zero-Middleman Threat Model

Traditional autofill extensions operate a cloud proxy: form labels, candidate resumes, and personal identification information (PII) leave the user's browser, travel to an intermediate server, and are forwarded to third-party language models. This introduces critical threat vectors:

  • Interception or logging of sensitive resumes and PII on proxy servers.
  • Subpoena or leak exposure from centralized vendor databases.
  • Cloud proxy downtime halting form-filling capabilities.

FastFiller's Architectural Countermeasure: FastFiller eliminates the proxy server entirely. FastFiller operates zero backend application servers, zero telemetry collectors, and zero proxy middleware. The extension is 100% self-contained within your local Chrome runtime.

2. Data at Rest: Chrome Sandbox Isolation

All user profiles, candidate templates, custom system prompts, and BYOK credentials reside exclusively in chrome.storage.local.

Security Guarantees:

Chrome strictly isolates extension storage under the same-origin policy. Visited web pages, third-party scripts, and cross-site frames have zero access to read or inspect FastFiller's local storage.

Host Protection Boundary:

Because storage is managed by Chrome's local database without custom encryption layers, local physical security depends on host device protections (operating system user account isolation, FileVault on macOS, BitLocker on Windows, or LUKS on Linux).

3. Data in Transit: Direct Provider Routing

When form analysis occurs, network requests follow one of three strictly defined pathways:

Web Session AI (ChatGPT & DeepSeek):

Queries route directly from the local browser extension to chatgpt.com/backend-api or chat.deepseek.com/api using the user's active session. Requests are protected by standard TLS 1.3 encryption. No credentials or session cookies are ever sent to FastFiller or any secondary party.

Direct BYOK APIs:

Outbound API calls travel directly from your browser to Google AI Studio, Anthropic, OpenAI, Groq, or OpenRouter over authenticated TLS/HTTPS. Keys are sent only in the authorization header to the target provider.

Local Offline Ollama:

Payloads travel over loopback TCP (http://127.0.0.1:11434) without exiting your computer's network interface. Zero packets are broadcast over the internet.

4. Automated PII & Payment Field Filtering

To prevent accidental exfiltration of high-risk credentials, FastFiller's DOM scanner enforces hardcoded exclusion rules before constructing prompts:

  • Password Fields: Inputs with type="password" are excluded from form-filling scans.
  • Payment & Card Security: Credit card numbers, expiration dates, and CVV/CVC codes are skipped and never sent to language model prompts.
  • Pre-Fill Dry-Run Gating: Form values are never injected silently. The interactive Dry-Run modal allows users to review, edit, or uncheck any individual field before confirming injection.

5. Manifest V3 Scoped Permissions

FastFiller complies with Chrome Manifest V3 and requests only the minimal permissions necessary for functionality:

Permission Justification
activeTab Required to detect form inputs and inject values only when the user explicitly triggers FastFiller.
scripting Executes DOM mapping and synthetic change events into the active page when requested.
storage Saves local candidate templates, configurations, and API keys inside chrome.storage.local.
tabs Enables Web Session AI communication with the active ChatGPT or DeepSeek tab.