A buyer asks AI for a company like yours. Who gets named?
Not you, probably. We measured our own site — here is what came back.
No signup · about a minute · 46 checks, 24 AI crawlers
Three views of the same run
The score and where it leaks, who your server really let through, and how many visitors assistants already send you.
Filed in your analytics as ordinary referral traffic, next to newsletters. One line of JavaScript, or a GA4 filter, pulls it out.
Why does AI visibility need its own checker?
Because search hands you a list and AI hands you one answer. On a results page you can be tenth and still get the click. Inside an AI answer there is no tenth place — there are usually three sources, and often one.
So being absent stops being a ranking problem and becomes a visibility problem. And it is decided by things almost nobody has checked: whether a crawler is allowed in, whether your page has any text before JavaScript runs, whether a model can tell your company apart from one with a similar name.
Every one measured against your live site during the run. No database lookups, no third-party crawl data, no model guessing on your behalf.
We do not merely read your robots.txt. We knock on your server as each real crawler and record what actually comes back.
No account, no tag, no access granted. Measured entirely from outside, exactly the way an answer engine sees you.
What does the checker look at?
Weighted by what a failure in each actually costs you. Crawler access is worth thirty points because a blocked crawler cannot cite you at any score. Trust signals are worth ten because they shift the odds, not the outcome.
Crawler access 30 points
Two tests per crawler: what robots.txt permits, and what your server actually does when 24 real AI crawlers knock. The only band that can take you to zero on its own — and the one we most often find broken by a firewall toggle somebody switched on years ago.
Machine readability 25 points
Whether your content exists in the HTML that is actually served, before any JavaScript runs. AI crawlers do not execute your JavaScript. A beautiful client-rendered site is an empty page to every one of them.
Structured data 20 points
Whether your brand is a thing a model can resolve rather than a string it has to guess at. This is how a citation ends up landing on a company that merely shares your name — we found exactly that happening to our own domain.
Discoverability 15 points
ChatGPT Search and Copilot read Bing's index. If you are not in Bing you are in neither. Usually the cheapest points on the board, and usually untouched.
Trust signals 10 points
Whether a real organisation is visible behind the website. When an engine picks three sources out of a hundred candidates, accountability is the tiebreaker.
What you get back, specifically
- A 0–100 score with a letter grade and what that grade means
- All five band scores, with the points lost in each
- Every failed check, ordered by points recoverable
- The evidence behind each finding — status codes, matched rules, byte counts
- The specific fix, written for a developer rather than for a sales call
- A crawler-by-crawler table: what robots.txt says, and what your server did
- The projected score if you fix the top three
And what it will not tell you
- Whether ChatGPT currently recommends you — that is measured separately
- How much traffic AI sends you — only your own logs know that
- Anything about pages behind a login
- Anything derived from a third-party crawl or a guessed estimate
Which AI engines does this actually cover?
All 24 crawlers, from 18 operators, in every check. They do not share a pipeline: allowing GPTBot does nothing for Gemini, and allowing Google-Extended does nothing for Claude.
OpenAI3 probed
- OAI-SearchBotcritical
- ChatGPT-Usercritical
- GPTBothigh
Google1 probed
- Googlebotcritical
- Google-Extendedcritical
Perplexity2 probed
- PerplexityBotcritical
- Perplexity-Usercritical
Microsoft1 probed
- bingbotcritical
Anthropic3 probed
- Claude-SearchBothigh
- Claude-Userhigh
- ClaudeBothigh
Amazon1 probed
- Amazonbotmedium
Apple0 probed
- Applebot-Extendedmedium
Common Crawl1 probed
- CCBotmedium
DuckDuckGo1 probed
- DuckAssistBotmedium
Meta1 probed
- meta-externalagentmedium
Allen Institute0 probed
- AI2Botlow
ByteDance0 probed
- Bytespiderlow
Cohere0 probed
- cohere-ailow
Diffbot0 probed
- Diffbotlow
Huawei0 probed
- PetalBotlow
Mistral0 probed
- MistralAI-Userlow
Timpi0 probed
- Timpibotlow
You.com0 probed
- YouBotlow
How does the check actually work?
No account, no tag on your site, no access to grant. If a fix is needed, the report is written so your own developer can act on it without us.
We resolve your real origin
https against http, www against apex, redirects followed and recorded. Sites are frequently not serving what their owners think they serve.
We audit the live site
46 checks plus a user-agent probe of 24 real AI crawlers, spaced apart with a hard per-host budget and a circuit breaker.
You get evidence, not a grade
Every failed check carries what we measured and what to change, ordered by points recoverable rather than by how alarming it sounds.
Where does the measurement stop?
These four rules are written into the engine rather than into a policy page, because good intentions do not survive a deadline. They are the reason to trust the parts we do show you.
A rate limit is never reported as a block
If your server pushes back because we asked too quickly, that is our problem, not your finding. Those responses are excluded from scoring. Otherwise a shared host's throttle ends up in a report as "this site blocks GPTBot".
Anti-spoofing is reported as a question
If your edge refuses a request claiming to be OAI-SearchBot, that may be correct anti-spoofing rather than a block. From outside the network the two are indistinguishable, so we say so instead of picking the scarier reading.
Readiness and recommendation stay apart
This score says whether engines can use you as a source. It does not say whether they currently recommend you. Merging those into one number is how a tool quotes you noise and calls it a metric.
A request we chose not to send is "not tested"
There is a hard per-host request budget and a circuit breaker. We built that guard after one of our own audits got our office IP banned by a shared host — so it comes from experience rather than from a checklist.
Is AI already sending you visitors?
Assistant referrals arrive in your analytics as ordinary referral traffic, filed next to newsletters. Almost nobody segments them out, which is why almost nobody knows their number — and it usually converts better than everything else in the report.
One line of JavaScript
Records the referring host, the landing path and the date. No cookies, no IP address, no fingerprint, no third-party call. Free with every check.
Your own GA4, two minutes
We publish the exact host list and regex so you can pull the same number yourself. We receive no data at all from this route.
The check is free. The rest is priced by what it costs to deliver.
The free audit is the whole audit — every finding, every fix. What is paid is what comes after it, and it is sold in two separate pieces.
The whole technical audit, every finding, every fix, and the AI traffic tracker. Not a trial and it does not expire.
Ten buyer questions run against four answer engines every week, tracked and dated, with an alert when your position actually moves more than the noise floor.
Our team implements the fixes in two weeks. The scope is your own report, so there is nothing to discover and nothing to negotiate.
Questions people actually ask
Is this SEO?
Why is the free check actually free?
Why is the paid tool cheaper than the agencies?
Do you need access to my site?
Will running this slow my server down?
It takes a minute and costs nothing.
You will either find out your site is fine, or find out something worth fixing. Both beat not knowing.