Free website audit · a plan and a fair price built around your business · no lock-in

Free audit · a plan built for you · no lock-in

Run a free audit →

Trades & local services · Computer & laptop repair · Case study

Checkable, or it is not claimed: rebuilding JorTech in public

Our own repair practice: brand, build, SEO, conversion and security, shown screen by screen, and the daily enquiries its owner reports on zero ad spend.

Client JorTech www.jortech.co.uk ↗
Sector Trades & local services · Computer & laptop repair
Published
  • Astro 7 on Vercel (London, lhr1)
  • Design tokens with per-brand injection
  • Build gate against hardcoded colours
  • Edge APIs + shared abuse-guard library
  • JSON-LD entity graph (Person · Org · JobPosting · FAQ)
  • Self-hosted Directus asset platform (EU)
  • Pagefind static search
  • Plausible + Sentry (EU)
£0 Google Ads spend
405 → 0, build-gated Hardcoded brand colours
0, by design File uploads accepted
69 Pages from one dynamic route
JorTech, cover

JorTech is our own group’s repair practice: computer and laptop repair across Leeds, West Yorkshire and North Yorkshire, a trading name of the same company as VerySEOly (TicketWave HQ Ltd, company no. 17143167), run from the same Pudsey registered office. We own both sides of this work, and that changes what a case study is allowed to be. There is no client confidentiality to hide behind, no reason to round anything up, and no screenshot standing in for a thing you cannot visit. The site is live at www.jortech.co.uk. Open it next to this page; everything below is in the source.

That is also the honest disclosure this genre usually skips: this is our sibling, not a paying client. What you should take from it is not “they made a client happy” but “this is the standard they build to when nobody is watching”. Where a number appears on this page it is a count, not a boast.

What it produces

Because a portfolio piece should start where a buyer’s interest starts. The honest framing first: the subject is ours, so what follows is the owner’s own attestation rather than an audited report, and the analytics will be published when the site is old enough for them to tell a fuller story.

With that said plainly: enquiries arrive by email every day, and the phone rings alongside them, on a Google Ads spend of zero pounds. No paid search, no paid social, nothing boosted. What was built to earn that work is described below: the local search footing, the entity and structured-data engineering, and being the kind of site people decide to trust while they are on it. For a weeks-old rebrand in a trade drowning in bought clicks, that is the result that matters, and it is the one this page is careful not to inflate further.

The JorTech homepage: a dark green hero reading Computer and laptop repair in Leeds, we come to you, with call and booking buttons, above a section titled Real jobs, not stock photos showing photographs of actual repairs

The brand: a name, an identity, and a refusal

JorTech began this year as Leeds Tech Repair: a descriptive name with no room to grow and a ranking footprint we did not want to lose. Our web design work covered the whole arc: the new name, the wordmark and the green identity you can see above, an editorial design language of hairline rules, big numerals and full-width sections, and one reserved amber that carries the money promises, so the reassurance thread is a colour you can follow down the page.

The refusal is part of the brand: no bordered card grids, no icon walls, no badge furniture, a position the site’s own stylesheet records as rejected on record. The showpiece is the credentials page, which exists because computer repair has no licence, so the honest move is to publish what can be verified and what the business refuses to claim. The design went through a three-direction competitive panel with an adversarial judge before it was built, and the entry for the founder’s bench training carries the most honest Verify note on the site: nothing to point at, experience stated as experience.

The credentials page: a dark ledger of four numbered entries, each with a Verify note in the margin: three name their checking mechanism and one admits there is nothing to point at. It closes on the full-width pull quote: if a business rounds its own credentials up, assume it rounds your quote up too

The build: rules the deploy enforces

Under the identity sits an engineering position: brand consistency is not a guideline here, it is a build gate. A mid-project audit found four hundred and five hardcoded colour values that had crept past the design tokens, and the response was not a cleanup but a tripwire: the first command of every build now fails the deploy if a raw brand colour exists anywhere outside a token definition. Today the count is zero and cannot silently rise. Around twenty copy-pasted hero blocks became one component; around fifteen forked dark-gradient style blocks became three tokens; contrast ratios are computed and written in the source next to the colours they justify, to a 7:1 body-text floor, which is WCAG’s AAA tier rather than the AA most sites aim at.

Every deploy runs five gates: the token check, the build itself, static search indexing, a link checker that can actually fail the pipeline, and an internal-link verifier.

The SEO matrix

Local SEO here is a matrix, not a page. Twenty-two service pages, thirty-five area pages across three honestly tiered regions (Leeds, West Yorkshire, North Yorkshire, with a county hub), and twelve plain-words fault pages for the way people actually describe a problem: laptop will not turn on, screen stays black. All sixty-nine live at flat, keyword-first URLs served by one dynamic route from typed data registries, so URLs read the way people search, and the sitemap, internal links and structured data derive from, or are build-verified against, that one source.

The matrix is honest by written rule: pages for towns an hour out are forbidden from promising response times the drive could not keep, and the shared area templates enforce it. And the grid is not an island: every area page links the guides that serve it, and the guides feed the matrix back through the service and fault pages they educate for, so the educational layer passes authority into the commercial one instead of orphaning it.

Local search and NAP consistency

Under the matrix sits the unglamorous foundation: NAP consistency. One business name, one phone number, one registered office, identical on every page, because pages render them from a single config value rather than retyping them; on the pages, consistency is architecture, not vigilance. The same identity flows into the LocalBusiness structured data: the site names the Google Business Profile in its schema, and the profile lists the site as its home. Before that binding was made in the source, the schema’s sameAs had rendered zero times across a hundred and one pages, which is exactly the kind of silent gap a proper audit exists to find.

Region-aware structured data places each area page in its true container, Bradford in West Yorkshire, York in North Yorkshire, so the coverage machines read matches the tiering humans see. Reviews follow the same honesty: the Google reviews on the site are quoted verbatim with the owner’s replies, and no aggregate star rating is emitted in schema at all, a standing position rather than a pending feature.

On-page, technical, and the AI layer

This is technical SEO of the unglamorous, compounding kind. The pre-rebrand audit found that all sixty-four pages carried a canonical URL pointing at a host with no DNS records at all: Google was being told the true home of every page was a server that did not exist. One config value in each of two files fixed it, and the fix cascaded through canonicals, Open Graph URLs, the sitemap and every structured-data identifier. The rename itself moved forty-four files and a hundred and two occurrences in a single commit and kept the keyword-bearing slugs and titles: rebrand insurance for the ranking surface.

Then the single best finding of the conversion audit, which is almost embarrassing and belongs in a case study precisely because of it: the booking page, the destination of every call-to-action across roughly a hundred pages, carried a noindex tag. Hundreds of internal links poured equity into a page that told Google to turn away, on the commercial-intent query the business should own. The fix was deleting one word; finding it required auditing the funnel page by page. A later pass in the same audit series rewrote the page’s title from a brand-generic label to the query people actually type, and the on-page discipline runs site-wide: one h1 per page, query-matching titles, FAQ markup on guides, services and the booking page, a human-readable sitemap built from the real route set, and sitemap modification dates derived from git history with a build warning if they ever fall back to fabricated freshness.

The entity layer is where the site earns trust from machines the way the copy earns it from people: one business identity across a hundred pages, a canonical Person node for the founder linked bidirectionally with his profile on the group’s own estate, each side naming the other, and an llms.txt file that serves the brand’s promises directly to AI crawlers, because the next referrer after Google looks like being an answer engine.

Conversion: the enquiry system, not an enquiry form

The JorTech booking form: named fields including Which machine is it and Postcode or area, most with the reason printed beside the label, next to a promise rail and a card titled How we treat your files

The form above looks simple. Its design carries more operational learning than anything else on the site.

The fields state their reasons. “Which machine is it?” exists as a first-class field because the machine and the location used to share one box, which is exactly why model numbers had to be chased by email after every enquiry; the hint text asks for the model on the underside sticker, and the confirmation email asks the customer to reply with a photo of the fault and of that sticker, which solved the same pain a second time without adding an upload anywhere. A check-before-send step lets the customer review what they wrote. The promise rail sits beside the fields, and a “How we treat your files” card answers the privacy anxiety a repair customer actually has, in the same words the privacy policy makes enforceable.

One more thing about that confirmation email: it is not a pleasantry. It is written as the durable medium required for distance contracts under the Consumer Contracts Regulations 2013, with the reasoning cited in the code and a staff warning on the path where no email exists, because skipping it can extend a cancellation window from fourteen days to twelve months. The pricing page converts by explaining honestly why no tariff is published instead of inventing a fake “from” price. And the phone number stands beside every form, because in this trade the fastest conversion is a conversation.

The JorTech homepage at phone width: the promise bar, a one-thumb call button and booking button, and the hero stacked cleanly at five hundred pixels wide

The careers engine

Hiring is part of the platform, not a mailto link. Seven roles each have their own page, because Google for Jobs only honours job markup on a per-job detail page, and each carries JobPosting structured data with a fixed first-published date, never a rebuild timestamp, because a static site that re-stamps datePosted on every deploy is lying to the crawler. Two fields are deliberately absent from that markup, employment type and salary, because neither is settled and this build does not publish placeholders; the pages commit to the process instead, pay stated plainly in the first conversation.

Each role page arrives with the application form preselected to that role. Applications are email-native by the same design as the enquiries, so the pipeline a recruitment system later ingests already exists, and the employer brand argues the same thesis as the consumer brand: free diagnosis plus a fixed quote means a technician is paid to be right, never to upsell. Two recruitment guides feed the funnel, how to get into the trade and what the job actually contains, each cross-linked with the roles they describe, so the hiring surface earns search traffic the same way the commercial one does.

Protection: the upload that is not there

Both public forms on the site accept precisely zero file uploads, and the policy is written at the top of the code with its reasoning. CVs and fault photos arrive as replies to the confirmation email. That one decision removes an entire class of surface: no multipart parsing, no stored files, no scanning question, no retention schedule, no spam vector, and the email thread it uses already exists. It is also deliberately compatible with where the group is heading operationally, because an email-native flow is exactly what a recruitment or CRM system ingests later without migration: pipeline thinking applied before the CRM exists.

Around the forms sits a shared guard library used by both endpoints. Requests are rate-limited and provenance-checked before the body is even parsed. The spam traps are tuned around a hard rule learned the expensive way: browser autofill trips honeypots for real customers, and a false positive must never silently cost a real enquiry. The anti-bot timing checks were re-tuned after they threatened to lock out real customers, including the laptops with dead motherboard batteries and wrong clocks that this business exists to fix. Outbound emails cannot be turned into branded phishing: user-controlled text is sanitised before it reaches a subject line or greeting, and the endpoints withhold the customer-confirmation leg entirely for requests that fail provenance checks, because that is the leg that would mail a caller-supplied stranger from a trusted domain.

None of that is exotic. All of it is the kind of thing that only exists when someone attacks their own build before a stranger does.

Web security, above the forms

The perimeter matches the endpoint discipline. The site ships a strict header set: HSTS with preload, cross-origin opener and resource policies, frame denial, and a permissions policy that switches off browser capabilities the site never uses. Content Security Policy is served two ways on purpose: a static policy for the static pages, and a per-request nonce injected by middleware for the routes that render server-side, with violations reporting to the site’s own endpoint. API responses are never cached, job photographs are published with their camera metadata stripped, and a SECURITY.md states how to report a vulnerability. For a local repair site this is over-engineering by industry habit, and exactly the standard by ours: the security posture the group sells is the one it runs on its own shop.

DNS, run like production

Domain work is treated as production infrastructure, because it is. The rebrand retired an entire previous identity without breaking search or email: every legacy host reaches the canonical site in one verified permanent redirect, and the redirect rules deliberately live in two layers, platform settings and repo config, with a table in the repo recording which layer owns which host so nobody has to rediscover it during an outage. Zone changes were additive, leaving records that other services depend on standing, with the warning written down that tidying a dead domain can silently break things still depending on it; even the proxying trap that would have broken certificate renewal on the retired hosts is documented where it bites. None of this is visible to a visitor, which is exactly why it is in the case study: DNS is where rebrands quietly die, and this one did not.

The plumbing is ours too

The stack behind the practices is owned, not rented, and declared where the law asks for it. Photography and campaign assets for the group’s brands are managed on our own digital asset platform, built on self-hosted Directus on EU infrastructure, with CDN delivery from an EU-owned provider, and named, with its hosting, in the group’s public data-processor register, which is where you can check it rather than take our word. Analytics is cookieless Plausible and error monitoring is Sentry, both EU-region. Search is Pagefind, static, no third-party service. Social and Open Graph images render from the site’s own pipeline. This is the fractional CTO posture applied to our own shop: fewer vendors, more ownership, every processor accounted for.

The method, which is the product

The part we would sell, if only one part could be sold, is the process visible in the git history. Work on this site does not merge on its author’s say-so. Changes go through adversarial review, with independent lenses attacking claims, contrast arithmetic, security and copy, and the findings are closed in the same pull request that records them. The history includes a commit that openly documents the one time pages merged before review returned, what the review then found, and the safety-grade corrections that followed. The same log contains commits titled with their own confessions: photos that showed the wrong device on pages promising they never would, filenames that were lies. House rules are enforced as gates rather than intentions: no invented counts, no fabricated reviews, no response-time promises, and the rules exist because each records a real past failure.

Even this case study went through that mill. The first draft claimed a bidirectional link that was, at the time, one-way, and described two security mechanics precisely enough to help an attacker. The review caught both; the link was then actually closed, and the mechanics generalised. You are reading the version that survived.

What this case study does not claim

No audited traffic figures, no ranking positions, no conversion percentages: the enquiry result above is stated as what it is, the owner’s attestation, and the measured numbers will be published from analytics, not memory, when the rebuilt site has accrued enough of them to be honest. No client testimonial, because the client is us. And nothing in this write-up that the subject site would refuse to say about itself.

What we can say is this: the brand, the build, the search work, the conversion system and the security posture above are the same method VerySEOly applies to client work. JorTech is simply the version where you can check every line of it yourself, tonight, from the page source. If you want that standard applied to your business, get in touch.

← All case studies

Free audit · a plan built for you · no lock-in

Ready to find out exactly what your business needs?

Run a free audit
Common Run a free website audit What does this cost? What is managed website service? SEO in Leeds Get more enquiries Websites vs systems See the work Talk to someone Enter opens the first result · Esc closes