Building SPARK

Spark: SEO Agency Dashboard

Single pane of glass for a wholesale SEO operation.

Spark is a single-operator Agency SEO Intelligence Workbench: one tool for running many client portfolios across six disciplines — traditional search (SEO), answer-engine optimisation (AEO), generative-engine optimisation (GEO), NLP, voice search and local search. Three specialised AI worker teams share one job queue and turn briefs into client-ready deliverables that the operator reviews and emails out; the workbench serves no audience of its own.

It runs directly on a single Debian host, no containers, no version-control-driven pipeline, and is live in production at https://spark.ondigital.business/, fronted by Cloudflare, with every route behind a default-deny session gate.

At a glance

  • Status: Live, in production.
  • Current version: 0.119.0 (released 2026-08-25).
  • Audience: A single agency operator, with optional read-only colleagues. Not client-facing.
  • Disciplines: 6 : SEO, AEO, GEO, NLP, Voice Search and Local Search.
  • Licence: Proprietary. All rights reserved.

Who it serves

  • Agency operator. Runs the workbench day to day: onboards clients, drives the AI worker teams, reviews their output, and ships deliverables.
  • Read-only colleagues. Optional editor or viewer roles for occasional collaborators who need to see the queue or the audit log.
  • Managed clients. Each client’s own audience is served indirectly. The workbench emails them CSV, llms.txt, JSON-LD and voice-snippet deliverables; it never fronts a client-facing site itself.

Core capabilities

Multi-client portfolios. Every table is scoped by client, and onboarding a new client,  a URL plus a starter keyword list,  produces its first structured-data payload in under ten minutes.

Three AI worker teams on one queue. Optimisation (Claude) refines existing assets, Writer (Gemini) drafts new content, and Research (OpenAI) classifies and extracts entities. Three systemd timers drain the shared queue every 90 seconds, each reserving jobs with a row lock so two ticks can never claim the same job; results land in a triage queue for the operator to approve.

Citation tracking. Four providers, an offline mock plus Gemini, Perplexity and SearchGPT/OpenAI,  probe AI answer engines nightly for whether a client is being cited.

Multi-format deliverables. Exports in CSV, JSON and YAML, plus a single-pack ZIP bundling all of those with a client’s llms.txt, robots.txt, sitemap.xml, an HTML report, per-keyword JSON-LD and a compliance matrix.

Per-client discovery feeds. A client’s llms.txt, robots.txt and sitemap.xml are generated to reference that client’s own site, not the workbench’s, so they drop straight into the client’s webroot.

Compliance matrix. A per-branch by per-provider description-budget grid, Google Business Profile, Bing, Apple and others — with a pass or fail per cell and an aggregate score.

Hierarchical English dialect engine. Content generation covers six English locales (US, GB, CA, AU, NZ, ZA) with curated regional vocabulary, spelling, grammar, date formats and cultural framing, opt-in per client and free of invented regionalisms.

WordPress plugin (phase 1). A separate machine-credential API lets a client’s WordPress install authenticate with its own rotating token; the tenant is always resolved from that token, never from a client-supplied header.

Quality, security and operations

Every route sits behind a default-deny session gate, added in a security review and confirmed by a further production-readiness audit. A single local script is the quality gate, PHP, Python and JavaScript test suites, a forbidden-character lint on shipped copy, and an authenticated accessibility render audit,  and it must read green before any change is considered done, since there is no separate pull-request review step on this single, version-control-free host. The most recent authenticated audit measured WCAG 2.1 A/AA across 15 views with zero critical or serious violations, alongside a Lighthouse accessibility score of 100.

Security work runs as recurring adversarial audit sprints rather than a one-off pass: recent rounds closed confirmed CSRF, SSRF and cross-tenant findings. A dedicated backup subsystem archives checksummed ZIP snapshots on a grandfather-father-son retention schedule, with its own idempotent installer and test suite. External spend is capped by policy: every AI or data provider in use has a free tier or a low-cost prepay plan, and no paid search-data API is used anywhere in the product.

Internationalisation

The operator chrome defaults to English, left-to-right, with a header switcher that flips the shell to Hebrew and right-to-left layout, persisted per browser. That switch only affects the workbench’s own labels; the data layer beneath it processes Hebrew, Arabic and English content as first-class, in whatever language a client’s material arrives in. The hierarchical English dialect engine extends that same first-class treatment to six English-speaking markets on the content-generation side.

Technology summary

  • PHP 8.4-FPM behind Apache 2.4, with a manual autoloader rather than a framework.
  • MariaDB 11.x for durable, multi-tenant data; Redis 8.x for sessions, cache, rate limits and anomaly counters.
  • Python 3.11+ worker scripts, one per AI team plus onboarding, citation and maintenance jobs, all driven by systemd timers.
  • Static HTML with a pre-built Tailwind CSS bundle and Lucide icons, no client-side framework, no runtime CDN dependency.

The whole stack runs directly on the host: no containers, no orchestration layer, and no version-control-driven deployment pipeline. A saved edit to a PHP file or a worker script is live on the next request or the next timer tick.

Design principles

  • Utility over polish. No marketing panels or “what this tool does” explainers in the chrome,  it is a work tool, and the first thing below the header is live data.
  • Sidebar navigation. Intent clusters live in a left rail, with the workbench’s action buttons underneath them, not in a horizontal top row.
  • Bilingual chrome, not a bilingual product. The shell offers an English/Hebrew switch; client content stays in whatever language it was written in.
  • Correct the reference, don’t copy it. The current violet and lavender visual identity was adapted from an outside interface specification, but the accessibility defects identified in that source, low-contrast placeholders, hover-only actions, colour-only status, undersized text, no visible focus ring,  were fixed rather than reproduced.
  • No silent failures. An error is surfaced immediately rather than swallowed, a written rule for the human team and for any AI agent working on the codebase alike.

Intellectual property notice

Spark is proprietary software. Its source code, AI worker prompts and provider configuration, client data model, documentation and branding are the property of the project owner. This description is a summary for portfolio purposes only. It intentionally leaves out source code, API keys and provider configuration, database schema, infrastructure and host details, security controls, and operational and recovery procedures. It grants no licence to use, copy or reproduce any part of the product. Any use beyond reading this summary needs written permission from the owner.

Live

GenX Tribe

A social platform for people who remember the web before infinite feeds.

  • NGINX
  • PHP 8.5
  • PostgreSQL 17
  • Tailwind CSS
v0.16.1
Live EZMart

Makolet.store

One flat-fee platform for the corner-store economy.

  • Alpine.js
  • MariaDB 10.11
  • NGINX
  • PHP 8.4
v1.1.0
Building

leat-leat

Freelance tasks designed around the realities of working with PTSD.

  • Alpine.js
  • MariaDB 11.8
  • NGINX
  • PHP 8.5