11 model stages. One truthful CV.

First Landed uses a staged paid-audit methodology with adversarial review and named models. At R5, Cannot trace claims must be cut and Needs proof claims may survive only as marked blanks.

A paid audit runs 11 model stages, R0 through R9b, then R10: a deterministic assembly step that calls no model. R9b is the Code Red pass, a final re-review of the finished CV and cover letter that hunts for any claim the earlier stages let through without a source. It is the last model stage, so an audit that a blocking safety gate stops earlier goes straight to R10 and never reaches it.

The pipeline

The free scan is one model call, not a run through this list. The Get-Ready Pack and the Active Search Pack run every stage below, with R5 as the hard veto and R9b as the closing Code Red re-review, unless a blocking gate ends the run early and hands what exists to R10.

R0 - Reading

Reads your CV and the JD, then writes down your strongest evidence themes, the requirements the JD actually names, and the obvious mismatches between the two.

R1 - Angle generation

Proposes exactly three candidate angles for how this CV could defend this JD. Each angle is one sentence, followed by the evidence it rests on.

R2 - Angle critique

Runs on the attacker route and attacks all three angles: the missing evidence, the overclaim risk, and what a senior reviewer would push back on.

R3 - Match scoring

Scores the strongest angle from 0 to 100 against the requirements the JD names, shows the weighted math instead of hiding it, and lands on Apply, Stretch, Skip, or Needs more evidence.

R4 - Risky claim attack

Attacker route again. Goes through your CV claim by claim, names what an interviewer would attack, and ranks the top risks by severity.

R5 - Fact-Checker veto

Labels every material claim as exactly one of Defensible, Needs proof, or Cannot trace, working only from your CV, the JD, and the earlier stages. Cannot trace claims must be cut. Needs proof claims may survive only as a [NEEDS PROOF: ...] blank. It runs at temperature 0.1, the lowest setting we use.

R6 - Full CV rewrite

Rewrites your CV to one page against the JD, using only what R5 marked Defensible plus the blanks R5 allowed. It may not introduce a company, employer, title, certificate, licence, degree, or number that is absent from your source CV, and it may not spell out an abbreviation you left short.

R7 - Verdict and missing evidence

Scores the rewritten CV as Apply, Stretch, Skip, or Needs more evidence, with a 0 to 100 number and the reasoning, then lists three to five pieces of evidence to gather before you apply.

R8 - Cover letter

For English, the draft targets 250 to 350 whitespace-delimited words, with a hard maximum of 380. Simplified and Traditional Chinese target 450 to 650 non-whitespace Unicode code points, with a hard maximum of 750. The # Cover Letter H1 is excluded from the count; the greeting and sign-off are included. A shorter draft is allowed when evidence is thin and is never padded. It cites two or three anchors from the rewritten CV, and every fact must already be in that CV.

R9 - Cover letter attack and bullet attack map

Attacker route. Uses up to three available risky bullets from R4 without inventing missing bullets. For each one, it gives three likely questions a senior reviewer would ask and one instruction for the smallest evidence artifact to bring, based only on the claims you chose to make.

R9b - Code Red pass

This final safety stage runs in English. It re-reads the finished CV and cover letter against your original material and the R5 labels. It can return only an exact quoted cut, which code applies deterministically; it never rewrites a claim. If it cannot quote or locate an issue exactly, release is blocked. It is the last model stage, so an audit stopped earlier by a blocking gate never reaches it.

R10 - Deliverable assembly

No model call at all. Code reads R9b's veto table, deletes the claims R9b marked cut from the CV and the cover letter, drops interview-prep lines that quoted a claim the deterministic trace gate had already removed, strips internal identifiers and stage codes, and appends one fixed no-guarantee note. Apart from that note it writes nothing of its own.

Models we actually run

No hidden routing and no aspirational tiers: this is the default configuration in the engine code, read on 2026-09-01. Stages carry a defender or an attacker route label, but a route is a job description, not a second vendor. With DeepSeek as the provider both routes resolve to the same model pin. Only R6 and R8 leave it.

We used to print a per-scan and per-audit infrastructure cost here. We have removed it: the price table our code uses to estimate cost still points at the retired OpenRouter route, so any figure we printed from it would be wrong, and fixing the table is a code change, not a copy change. Customer pricing is in Singapore dollars (S$).

Free fit scan

One streamed call

deepseek-v4-flash (direct API)

One request over your CV against one JD, streamed back as it is written, at temperature 0.1 and capped at 2,200 output tokens. Three runs on 2026-09-04 against one synthetic CV finished in 11 to 14 seconds each. That is three runs on one input, not a service level.

Paid deep audit

The default pin for every stage

deepseek-v4-flash (direct API)

Both the defender and the attacker route resolve to this one model. Only R6 and R8 can leave it, and only when a Moonshot key is configured. Thinking mode is sent as disabled, so these stages are billed as plain completions rather than as reasoning.

Writer stages (R6 CV rewrite, R8 cover letter)

R6 and R8

kimi-k3 (Moonshot direct API)

The CV rewrite and cover letter stages are the only ones that leave the main provider, and only when a Moonshot key is configured. Without one they run on deepseek-v4-flash like every other stage. If a Moonshot call comes back empty or with a status code we treat as retryable, that stage retries once on the main provider.

Fallback

per-stage failover

qwen (Alibaba DashScope)

When a DeepSeek stage call returns an empty completion, or HTTP 400, 401, 402, 403, 408, 409, 429, 500, 502, 503 or 504, that stage retries once on Qwen, when a Qwen key is configured. A network-level failure such as a dropped connection or a DNS error is not on that list: the run fails instead of failing over. We would rather tell you that than claim an outage cannot touch us.

Why this matters for you: the honesty comes from the pipeline, not the model brand. The same block of hard rules is appended to nine of the eleven stage prompts, including "do not invent employers, titles, dates, credentials, metrics, or scope"; the two remaining stage prompts, R8 and R9, carry their own equivalent rule. The R5 gate is parsed and enforced in code before R6 is allowed to start. And after R6 and R8 a pass with no model in it re-reads the output and checks each claim against your CV, the JD and the R5 labels. None of that depends on which vendor answers the call.

Fact-Checker veto, in detail

The most common failure mode of LLM-written CVs is fabrication: invented internships, inflated metrics, AUM that did not exist. R5 is the stage that exists to stop this, and the stages after it are not allowed to route around it.

R5 reads every material claim in your CV and in the earlier stage outputs and gives it exactly one of three labels:

  • Defensible: the claim traces back to material you supplied. The rewrite may use it.
  • Needs proof: it may well be true, but you have not evidenced it. It may survive only as a [NEEDS PROOF: ...] blank for you to fill from your own records.
  • Cannot trace: nothing you gave us supports it. The rewrite must cut it.

There is a fourth rule that catches the case students worry about most. If every duty and every result attached to one employer comes back Needs proof or Cannot trace, R5 labels that employer name and job title Needs proof as well. A role with no defensible substance under it does not get presented as established fact.

The gate is enforced in code, not by asking the model nicely. R5's labels are parsed out of its table and pasted into the rewrite prompt as an explicit veto list, and if R5 produced no parseable labels the run raises r5_labels_missing_before_r6 and the rewrite never starts. After the CV and the cover letter are written, a pass with no model in it re-extracts the claims from both and checks each one against your CV, the JD and the R5 labels; anything it cannot place is cut, or it stops the release. R9b then re-reads the finished documents and records an explicit veto for each claim it cannot ground, and R10 applies those cuts without calling a model.

Failed claims are not softened, and there is no pool of alternative drafts to swap in: there is one CV being written, and the claim comes out of it. That is why outputs often end up shorter than what a one-shot LLM would hand you.

The three rewrite controls

This section describes the free scan, not the paid deep audit. Most free scans end by rewriting one weak bullet from your CV. Three named controls on the scan page decide how that one rewrite is written: JD language, rewrite ambition, and writing style. Each owns one concern and has three settings. They are three separate choices, not a style slider, because that is what the engine actually reads.

What each control does:

  • JD language: keep your own vocabulary and ordering, fold the JD's key terms into your ordering, or lead with the JD's priorities. At every setting the JD's words are borrowed only where your evidence genuinely matches them.
  • Rewrite ambition: keep the source verb strength and propose nothing extra, use the strongest verb your evidence supports with one or two proof blanks, or propose the strongest shape your evidence could reach once you supply the missing parts.
  • Writing style: preserve your register and sentence rhythm, tighten to short verb-first clauses, or move to complete sentences in an institutional register.

Precedence inside the rewrite is fixed and not yours to move: the evidence rules first, then JD language, then ambition, then style. A control does not win an argument against the evidence rules.

What the instructions say no setting may do:

  • Reach the rest of the scan: the controls are scoped to the example rewrite alone. Verdict, fit score, score breakdown, missing evidence, risky claims and next step are meant to be produced without them.
  • Upgrade your role: "partnered with" is not to become "designed and ran"; "supported" is not to become "owned"; "contributed to" is not to become "led".
  • Import the JD's requirements: a requirement in the JD is not to be written up as something you have done.
What a control can and cannot do: the settings choose a shape, not a fact. Anything your CV does not state should either be left out entirely (Minimal changes) or written as an explicit [NEEDS PROOF: ...] blank for you to fill from your own records (Balanced and Strongest shape). These are instructions to one model call, not a mechanical gate, so read the rewrite against your CV before you use it. A blank you cannot fill is the honest answer, and it is the answer this scan exists to give you.

What we are still working on

Honest limitations as of 2026-09:

  • First-person evidence loop: intake form still misses some categories, including volunteer leadership. We are iterating on the field set.
  • Chinese output on the free scan: when you scan from a Chinese page we send an explicit instruction to answer in Simplified or Traditional Chinese. The eight section headings, and product labels such as Apply, Stretch, Skip and [NEEDS PROOF: ...], stay in English by design. The model does not always comply with the rest: a scan can still come back partly or entirely in English. We ship English, Simplified Chinese and Traditional Chinese. There is no Cantonese output.
  • Deliverable language: Your CV and cover-letter draft use your selected language where supported; some names, specialist terms and records may remain as supplied. Facts stay linked to your original CV. AI-translated wording is checked against recorded numbers, dates, levels and listed qualifiers, then reviewed by another AI model. These checks do not prove identical meaning. Open ‘Original’ to compare. Headings, proof markers, the final safety check and system guidance remain in English.
  • Supported rewrite: Improve supported education, role and activity wording with reviewed templates, and translate supported facts into your selected language. Original wording remains where a supported change is unavailable. We do not add achievements, upgrade responsibility or infer completed qualifications. You can compare changed records with the original CV.
  • Original-language fallback: Some records remain in their original language because a supported translation was unavailable. Review the highlighted records before submitting.