The Shareholder Asset Compounding Suite
Enterprise-grade full-stack command center for autonomous content portfolio management, predictive SEO intelligence, and multi-site revenue compounding.
CoreText Executive OS is a fully autonomous content portfolio management system that transforms you from an operator into a Shareholder. You establish your asset compounding parameters once, review prioritized multi-dimensional content portfolios, and trigger fully predictive AI webhook engines that compound your enterprise asset valuation permanently.
| Role | Responsibility |
|---|---|
| Shareholder (You) | Set strategy. Review briefings. Approve Tier 3/4 decisions. |
| CoreText Executive OS | Executes Tier 1/2 autonomously. Predicts decay. Intercepts trends. Compounds revenue. |
Production deployment: https://coretext-eight.vercel.app
Autonomous overnight situation reports per asset β revenue pacing, strategic decisions queued, 30-day forecasts, and compounding metrics. One screen, full portfolio awareness.
- Layer 1 β Real-time crawl budget, CTR micro-dip detection, and predictive health scoring
- Layer 2 β Industry velocity analysis, algorithm weather, and emerging topic cluster interception
- Layer 3 β Persistent AI memory per site: audience posture, tone calibration, monetization rules
| Tier | Description | Execution |
|---|---|---|
| T1 | Broken links, meta updates, schema fixes | Fully autonomous |
| T2 | Statistic refreshes, FAQ injections | Autonomous + notification |
| T3 | New content clusters, link restructuring | Human approval required |
| T4 | Strategic pivots, product launches | Human discussion required |
Multi-dimensional scoring engine (demand Γ GEO Γ monetization Γ competitive gap Γ authority fit) with one-click Atomization Studio β instantly fragments a pillar into newsletter, LinkedIn carousel, Twitter thread, YouTube script, and podcast outline.
Track and optimize your citation footprint across ChatGPT Search, Perplexity Pro, and Claude β deploy structured AI Answer Baits and run citability audits.
Predictive decay probability scoring with autonomous refresh briefing generation. Catch ranking erosion 14β30 days before it hits.
Per-article RPM tracking, untapped affiliate gap detection, digital product creation opportunities, and live affiliate program radar.
Real-time competitor publishing velocity monitoring with autonomous fast-response brief generation for viral trend windows (X/Twitter, Reddit, HackerNews, GitHub Trending).
Transfer winning strategies between portfolio sites β conversion tactics, content formats, and engagement patterns that compound across your entire asset network.
Context-aware strategic dialogue powered by OpenRouter (any model), OpenAI GPT-4o, or Anthropic Claude, with full Layer 3 memory access for every asset in your portfolio.
βββββββββββββββββββββββββββββββββββββββββββββββββββ
β FRONTEND (React 18) β
β Vite Β· TypeScript Β· Tailwind CSS Β· Recharts β
β Lucide Icons Β· Axios β
β Deployed via Vercel β
βββββββββββββββββββββββββββββββββββββββββββββββββββ€
β /api REST API prefix β
βββββββββββββββββββββββββββββββββββββββββββββββββββ€
β BACKEND (FastAPI) β
β Python 3.11+ Β· SQLAlchemy ORM Β· Pydantic v2 β
β OpenRouter SDK Β· OpenAI SDK Β· Anthropic SDK β
β JWT Auth Β· TOTP 2FA Β· DB-backed rate limiter β
β Deployed via Vercel Serverless Functions β
βββββββββββββββββββββββββββββββββββββββββββββββββββ€
β PERSISTENCE (Neon Postgres) β
β SQLite fallback for local dev β
βββββββββββββββββββββββββββββββββββββββββββββββββββ
| File | Purpose |
|---|---|
main.py |
FastAPI app, CORS, lifespan bootstrap |
models.py |
SQLAlchemy ORM models (16+ tables including DBUser, DBUserSettings, DBRateLimit) |
schemas.py |
Pydantic validation schemas |
security.py |
JWT, bcrypt, TOTP 2FA (encrypted secrets), Fernet encryption, backup codes |
ai_engine.py |
OpenRouter β OpenAI β Anthropic β template fallback |
init_db.py |
Database bootstrap with migration helpers + demo seeding |
database.py |
DB engine config (SQLite local, Postgres prod) |
routers/ |
Modular API routers (auth, sites, briefing, chat, monetization, geo, etc.) |
| File | Purpose |
|---|---|
App.tsx |
Root app with auth gate, state, tab routing |
api.ts |
Typed Axios API client (JWT interceptor) |
types.ts |
Full TypeScript interface definitions |
components/ |
Login, Header, Sidebar, SettingsModal, AddSuiteModal, AtomizeModal, Toast |
components/tabs/ |
10 specialized tab components (Briefing, NervousSystem, Decisions, Portfolios, GEO, Decay, Monetization, Competitors, Hive, Chat) |
- Python 3.11+ with
pip - Node.js 18+ with
npm - For local Postgres testing: Neon account (optional β falls back to SQLite)
git clone https://github.com/fxinfo24/CoreText.git
cd CoreTextcd backend
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
python -m app.init_db # Seeds demo data + creates tables
python run.py # Starts at http://localhost:8000Verify: curl http://localhost:8000/api/health β {"status":"ok"}
cd frontend
npm install
npm run dev # Starts at http://localhost:3000Default dev credentials (change in production):
- Owner: Set
OWNER_EMAIL+OWNER_PASSWORDin env (owner is pinned tofxinfo24@gmail.com) - Admin:
admin@coretext.local/changeme123(seeded byINITIAL_ADMIN_EMAIL/INITIAL_ADMIN_PASSWORD) - Sign in at
http://localhost:3000, or the production URL
| Variable | Required | Purpose |
|---|---|---|
DATABASE_URL |
Prod | Postgres connection (Neon). Omit for local SQLite. |
JWT_SECRET |
Yes | β₯32 random bytes for JWT signing |
OWNER_EMAIL |
Yes | Pinned super-admin email (default: fxinfo24@gmail.com) |
OWNER_PASSWORD |
Strongly | Owner's login password (set once on every boot) |
FERNET_KEY |
β 2FA | 32-byte url-safe base64 for encrypting TOTP secrets at rest |
INITIAL_ADMIN_EMAIL |
Recommended | Content admin email (default: admin@coretext.local) |
INITIAL_ADMIN_PASSWORD |
Recommended | Content admin password (default: changeme123) |
CORS_ORIGINS |
Prod | Comma-separated allowed origins |
OPENROUTER_API_KEY |
Optional | For live LLM via Settings UI (or paste in-app) |
Open Settings (βοΈ icon in sidebar) to configure:
| Provider | Models Used | Purpose |
|---|---|---|
| OpenRouter (preferred) | Any of 100+ models | Live chat, content atomization, strategic analysis |
| OpenAI | gpt-4o, gpt-4o-mini |
Fallback AI engine |
| Anthropic | claude-sonnet, claude-haiku |
Fallback AI engine |
CoreText works fully without API keys β all core features (briefings, portfolios, decay shields, GEO audits) operate on deterministic logic. AI keys unlock enhanced chat and atomization quality.
- JWT-based: HS256 tokens (24h expiry) stored in
localStorage - Two-step login: Password β if 2FA enabled β TOTP code or backup code β JWT
- RBAC (3 tiers):
owner>admin(content only) >viewer(read-only) - Registration: Invite-code gated; disposable email blocked; rate-limited
- Enable in Settings β "Two-Factor Authentication"
- Any authenticator app (Google Authenticator, 1Password, Authy)
- TOTP secret is Fernet-encrypted at rest (never plaintext in DB)
- 10 one-time backup codes generated on enable β shown exactly once, bcrypt-hashed thereafter
- Backup codes are single-use (reuse returns 401); regenerate anytime
- Requires
FERNET_KEYenv var in production
- DB-backed sliding-window (survives restarts, shared across serverless instances)
- Login: 10 attempts per 5 minutes per IP
- Registration: 5 attempts per 10 minutes per IP
- OpenRouter free-tier: 20 RPM on chat endpoint
- Pinned owner (
OWNER_EMAIL) cannot be demoted, deactivated, or deleted CORS_ORIGINSenv-driven β not*in prod- Env secrets never hardcoded; keys entered via Settings UI
All endpoints prefixed with /api/. Interactive docs at /api/docs (Swagger UI) when running.
| Method | Endpoint | Description |
|---|---|---|
POST |
/api/auth/login |
Login (password β 2FA step if enabled) |
POST |
/api/auth/2fa/setup |
Generate TOTP secret (requires FERNET_KEY) |
POST |
/api/auth/2fa/enable |
Confirm code, activate 2FA + return backup codes |
POST |
/api/auth/2fa/verify |
Second login step (temp_token + code β JWT) |
POST |
/api/auth/2fa/backup-codes |
Regenerate backup codes |
POST |
/api/auth/2fa/disable |
Disable 2FA on your account |
GET |
/api/auth/me |
Current user profile (incl. backup_codes_remaining) |
GET |
/api/auth/users |
List users (owner-only) |
POST |
/api/auth/register |
Register with invite code |
| Method | Endpoint | Description |
|---|---|---|
GET |
/api/sites |
List all shareholder suites |
GET |
/api/briefing/{site_id} |
Morning briefing |
GET |
/api/nervous-system/{site_id} |
3-layer nervous system |
GET |
/api/decisions/{site_id} |
4-tier decision queue |
POST |
/api/decisions/execute/{id} |
Execute decision |
GET |
/api/portfolios/{site_id} |
Content portfolios |
POST |
/api/portfolios/atomize |
Atomize content |
GET |
/api/geo/{site_id} |
GEO visibility data |
GET |
/api/decay/{site_id} |
Decay predictions |
POST |
/api/decay/shield/{id} |
Deploy decay shield |
GET |
/api/monetization/{site_id} |
Revenue intelligence |
GET |
/api/competitors/{site_id} |
Competitive intelligence |
GET |
/api/hive |
Hive mind cross-pollinations |
POST |
/api/chat |
AI Co-Director chat |
GET |
/api/settings |
Get user settings |
POST |
/api/settings |
Update user settings |
GET |
/api/health |
Health check (unauthenticated) |
cd backend
.venv/bin/python test_smoke_api.py # 33 prod-parity smoke checksThe smoke test exercises login, 2FA gate flow, backup codes, rate limiting, settings persistence, CTB endpoints, chat, and RBAC β all against an isolated SQLite database.
CoreText/
βββ backend/
β βββ app/
β β βββ main.py # FastAPI app entry
β β βββ models.py # SQLAlchemy models (18+)
β β βββ schemas.py # Pydantic schemas
β β βββ security.py # JWT + bcrypt + TOTP + Fernet + backup codes
β β βββ ai_engine.py # AI integration (OpenRouter β OpenAI β Anthropic)
β β βββ init_db.py # Bootstrap + migrations + demo seed
β β βββ database.py # DB engine config
β β βββ limiter.py # Rate-limit helpers (deprecated β body in auth.py)
β β βββ routers/ # 12 modular API routers
β βββ requirements.txt
β βββ run.py
β βββ test_smoke_api.py # 33-check prod-parity smoke test
βββ frontend/
β βββ src/
β β βββ App.tsx # Auth gate + tab routing
β β βββ api.ts # Typed axios client
β β βββ types.ts # TS interfaces
β β βββ components/
β β βββ Login.tsx # Login with 2FA step
β β βββ Header.tsx
β β βββ Sidebar.tsx
β β βββ SettingsModal.tsx # Model selection + 2FA enable/disable
β β βββ AddSuiteModal.tsx
β β βββ AtomizeModal.tsx
β β βββ Toast.tsx
β β βββ tabs/ # 10 tab components
β βββ ...
βββ vercel.json # Serverless function config + /api route prefix
βββ HANDOVER.md # Status ledger for agents
- Multi-user authentication (JWT + RBAC + DB-backed rate limiting)
- TOTP 2FA with encrypted secrets + single-use backup codes
- Neon Postgres production deployment (Vercel Serverless)
- OpenRouter multi-model chat
- DB-backed sliding-window rate limiter
- Webhook integrations (Stripe, PartnerStack, Impact)
- Scheduled autonomous briefing emails (SendGrid/Resend)
- Real-time Google Search Console API integration
- Live Perplexity/ChatGPT citation tracking
- Docker Compose deployment configuration
- Progressive Web App (PWA) shell
MIT License β see LICENSE for details.
CoreText Executive OS v2.1.0
Stop operating. Start compounding.