Founders and operators now ask an AI assistant to name outside corporate counsel before they ask anyone they know — and the firms that establish visibility inside those answers now lock in a structural advantage while the legal category is still barely contested. Before we run the audit, we need to make sure we're asking the right questions about the right competitors to the right buyers. This document presents what we've learned about Charlotte Corporate Counsel's market — your job is to tell us what we got right, what we got wrong, and what we missed.
Before we measure whether assistants name this firm when a founder asks for outside corporate counsel, these three signals tell us whether AI systems can reach and read the site at all. They are derived mechanically from the August 10, 2026 crawl of all four URLs on charlottecorporatecounsel.com.
Disallow: / against nine named AI agents including GPTBot, ClaudeBot, Google-Extended and CCBot. Three high-severity findings follow it — an HTTP 200 catch-all that serves the homepage for every unrecognized URL, no structured data on the homepage, and no confirmed presence in any search index.Sitemap: directive.Outside corporate counsel is bought the way it has always been bought — on referral and reputation — right up until the moment the founder skips the referral and asks an assistant instead. That moment has already arrived for the buyers in this graph: 87% of B2B software buyers say AI chatbots are changing how they research vendors, and half now start that research in a chatbot rather than Google (G2, October 2025). The population G2 surveyed is exactly this firm's client base — founders and operators at SaaS companies — even though the purchase in question is legal counsel rather than software. A solo practice competing against Am Law 200 brands and national platforms has almost no chance of outspending them on conventional search, but the answer layer is not yet a contested market in this category, and position there is being assigned now rather than defended.
This document is the foundation the audit runs on, and it has three parts. The competitive landscape defines which firms and substitutes the audit tests you against head-to-head, and which it treats as category context. The buyer personas define who is doing the searching, which determines the language and the stage of every query we generate. The Layer 1 technical baseline determines something more fundamental than either: whether AI systems can access and correctly identify this site at all. Each section below is something we are asking you to confirm or correct before the query set is written — not a conclusion we are presenting.
The validation call is a working session, not a walkthrough. Two kinds of decisions come out of it. The first is input validation: whether the right firms are in the right tiers, whether the personas are the people who actually evaluate and sign, and whether the capability ratings match how you win and lose. Every one of those answers changes which queries get written and how they are weighted. The second is engineering triage: which technical items your side can start on immediately, without waiting for query results. Those two lists are collected in full in the Pre-Call Checklist near the end of this document — you can prepare for the call from that section alone.
/robots.txt and confirm whether the nine Disallow: / blocks (GPTBot, ClaudeBot, Google-Extended, CCBot, Applebot-Extended, Amazonbot, meta-externalagent, Bytespider, CloudflareBrowserRenderingCrawler) were authored deliberately or inherited from a Cloudflare default._redirects, add a 404.html at the Cloudflare Pages project root, and add a canonical link to the homepage so / and /index.html stop competing.areaServed: Georgia — the Insights article already carries a complete, correctly formed Article schema, so the pattern exists in the codebase; applying a LegalService block with a founder Person node named Charlotte Lynn Luu to the homepage needs no input from the validation call.Three things to know before you start marking it up.
What this is This is the foundation the audit runs on. We assembled a knowledge graph of outside corporate counsel for startups and growth-stage technology companies as buyers experience it — who competes for the same spend, who sits in the room when a founder decides to hire a lawyer, which capabilities get compared, and what frustrations drive the search in the first place. Every entity below becomes queries. Get the foundation right and the audit measures your market; get it wrong and it measures a market that doesn't exist.
Your job Read for what's wrong and what's missing, not for what's right. Purple boxes throughout the document mark the places where our confidence is lowest and your answer changes the audit most. Every one of them is collected in the Pre-Call Checklist near the end — you can prepare for the call from that section alone.
Confidence badges High means we found it stated directly on your site, a competitor's site, or a review platform. Medium means we triangulated it from multiple weaker signals. Low means we inferred it and need you to confirm or kill it. The low-confidence items are where your input is worth the most.
Pulled from charlottecorporatecounsel.com. This is the anchor entity — every query in the audit is scored on whether the answer names it, which makes getting the entity itself unambiguous the first job.
→ Question 1 Six of the seven name variants in this profile are versions of your personal name, and that is deliberate: "Charlotte Corporate Counsel" reads as a Charlotte, North Carolina firm to both search engines and language models, and a search for the exact firm name returns Charlotte, NC corporate practices — Marcellino Moore, Gardner Skelton, PLG Law, Dozier Miller — rather than a Georgia attorney. Do you want to be found only by buyers searching for Georgia and Atlanta counsel, or do you want us to also test the Charlotte, NC association to measure how much of it there is to displace? If it's Georgia only, we build the query set around Atlanta and Georgia and treat North Carolina results as noise; if you want to contest it, we add a dedicated cluster of entity-resolution queries and the audit reports on how far the firm name has to travel. You are licensed only in Georgia, so this is not a question of preference — it's a question of whether out-of-state traffic is worth anything to you at all.
5 personas: 4 decision-makers, 1 influencer. These are the people whose search language the query set is built from — how they phrase the problem determines what the audit measures.
Critical review area This is the section where client input changes the audit most. Personas determine query phrasing, query stage, and query volume. A persona that doesn't exist in your deals produces a whole cluster of queries measuring a market that isn't yours — and at a solo practice serving pre-GC companies, the buying committee is small enough that one wrong role meaningfully distorts the set.
Data sourcing note Role, seniority, department, influence level, veto power and technical level are KG fields. Two personas — Founder & CEO and Chief Operating Officer — come from role titles on your homepage testimonials, which carry job titles but placeholder attribution ("Client name"), so they are grounded in stated titles rather than confirmed clients. The remaining three (CTO & Co-Founder, VP of Sales, Head of Finance) were inferred from category buying patterns, not observed in your data. The role description, buying jobs and query focus areas on every card are synthesized by us from those fields — they are our reading, and the most useful thing you can do is correct them.
→ Does the founder run the search themselves, or does someone else assemble the shortlist and hand it over? If it's the latter, discovery-stage queries move to that role and the founder only gets validation-stage language.
→ Does the COO actually sign the engagement, or scope the work and route the decision to the founder? If they scope rather than sign, we reclassify to evaluator and their queries shift from "hire outside counsel" to "how do I handle this contract myself."
→ This is the only persona we gave veto power without high influence. Do CTOs find you directly on AI and data-privacy work, or only arrive after the founder has already picked you? If they find you directly, DPA and model-training queries earn their own cluster instead of sitting under the founder.
→ At your typical client's size, does a VP of Sales actually bring you in when a deal stalls in redlines, or does the founder always make that call alone? If founders buy alone, we drop revenue-leader query language and reweight toward founder and operator searches.
→ Does a finance lead ever hold the budget veto on legal spend at your clients, or does that authority sit with the founder? If it always sits with the founder, we delete this persona and redistribute its cost-predictability queries rather than running them twice.
→ Anyone missing? These roles sometimes appear in outside-counsel deals for growth-stage technology companies — do they show up in yours? Head of People / HR lead (if contractor classification and offer-letter work is a distinct buying conversation from the founder's contract work, rather than something the COO absorbs). Incoming first General Counsel or Head of Legal (the person who either replaces you or becomes the one who instructs you — worth knowing whether they're a threat, a buyer, or both). Fractional CFO or outsourced accounting firm (at pre-GC startups these are often the referral path to counsel, and if so they search on behalf of the founder in their own language). Who else shows up in your deals?
5 primary + 5 secondary competitors identified. Tier assignment is what separates a head-to-head comparison query from a category-awareness query, so these ten names decide the shape of the competitive half of the audit.
Why tiers matter Each primary competitor earns roughly six to eight head-to-head queries — questions in the register of "flat-fee startup lawyer vs. hourly firm," "who drafts a SaaS MSA that survives enterprise procurement," and "Westaway alternatives for a Georgia software company" — which puts roughly 30 to 40 of the audit's queries on the tier assignments below. Two things to flag before you read them. First, your site publishes no comparison or "vs" content of any kind, so this entire set is outbound-sourced — we assembled it from competitor sites and category listings, not from anything you told the market. Second, SaaS Law Firm (Andrew S. Bosin LLC) is the one primary competitor we tiered from a category listing rather than a direct signal; if he rarely appears in your actual deals, moving him to secondary shifts about six to eight queries out of the head-to-head set and into category coverage.
→ Three things to correct here (1) When you lose a client, who do you lose them to? An Atlanta firm like Morris, Manning & Martin, another flat-fee solo like Andrew Bosin's SaaS Law Firm, or Common Paper's free templates? If the real fight is against templates and other solos rather than against big firms, we retier the set and the whole competitive half of the audit shifts from "boutique vs. Am Law" to "counsel vs. no counsel." (2) Three of the ten are medium confidence on tier — Bosin's SaaS Law Firm as primary, Lawtrades and Priori Legal as secondary. Do any of the three actually come up in your deals, or are they artifacts of what directories publish? (3) Is anyone here irrelevant, and who's missing? Priori Legal in particular only overlaps with you once a company has hired a first GC, which may be past the point where you're still in the conversation.
12 buyer-level capabilities mapped: 6 strong, 2 moderate, 3 weak, 1 absent. These determine which capability queries the audit tests and which ones we expect you to lose — the honest ratings are as load-bearing as the flattering ones.
Get a real MSA, subscription agreement, and terms of service that hold up when an enterprise buyer's legal team reads them line by line
Have someone sit on the redlines with our biggest customer's legal team and get the deal signed without losing the quarter
Figure out what GDPR and CCPA actually require now that we're running customer data through AI models, and get our DPA and privacy policy to match
Paper the contractors and employees properly on the way in, and make sure the confidentiality and non-solicit terms actually work on the way out
Know exactly what the legal work costs before it starts, with no surprise invoice at the end of the month
Reach the actual lawyer who knows our business and get an answer the same week, not a junior associate and a two-week queue
Make sure the company actually owns the code, brand, and product it built, and license it out on terms we control
Set up the entity, operating agreement, and founder split correctly the first time so it survives the next round of diligence
Cover us as we hire and sell across state lines and into Europe, without having to find a new lawyer in every jurisdiction
Pull in an employment, tax, immigration, or litigation specialist when something comes up that our main lawyer doesn't handle
Give the sales team a playbook and a template library so routine deals close without routing every one through a lawyer
Run our SAFE round or priced Series A, handle the term sheet, and keep the cap table and option pool clean
Which three do you actually win on? The audit tests all 12 capabilities, but competitive differentiation queries will emphasize 3. Six are currently rated Strong:
• SaaS & Commercial Contract Drafting — the only strong capability tied to three separate high-severity pain points
• Enterprise Deal Negotiation & Redline Turnaround
• Data Privacy & AI Compliance — rated strong on the evidence of a single published article (July 2026, GDPR/CCPA and AI processing)
• Contractor & Workforce Agreements
• Fixed-Scope Pricing & Cost Predictability
• Direct Senior Access & Turnaround Speed — the one strong rating we hold at medium confidence, since it rests on the site's stated one-business-day commitment rather than on observed delivery
Which of these best represents where Charlotte Corporate Counsel wins deals — not where the work is most common, but where a prospect chooses you over Westaway, Outside GC, or a template?
→ Three things to correct here (1) Venture Financing & Cap Table Work is rated Absent — we found governance and formation on the site but no financing practice. Is that right? Founders searching for a startup lawyer ask about fundraising before they ask about anything else, so if you do run SAFE rounds and priced Series A financings that rating is wrong and a large share of founder-intent query volume is missing from the audit; if you don't, tell us where you want that traffic to land instead. (2) Are the ratings accurate against named competitors, not in the abstract? Multi-State & Cross-Border Coverage is rated Weak specifically against Outside GC and UpCounsel, who staff nationally — but if you have reciprocal or pro hac arrangements that make cross-border work routine, that's a Moderate and it changes how we handle expansion queries. (3) IP Ownership & Licensing and Entity Formation & Corporate Governance are both Moderate — given that "IP & Brand Protection" and "Corporate Governance" are two of your four published service lines, is Moderate an undersell, or is it correct that these are competent rather than differentiating?
12 pain points: 7 high, 5 medium severity. Buyer language here becomes the literal phrasing of problem-stage queries — this is how the audit asks the question the way your prospect would actually type it.
→ Three things to correct here (1) Seven of twelve are rated High and none are rated Low — that distribution is flatter than it should be, and it means the audit will weight seven problem-stage clusters roughly equally. Which one or two of these actually make a founder pick up the phone that week, rather than nod and carry on? (2) Does the buyer language sound like your clients? "Half the product was built by contractors on a one-page agreement and I'm not actually sure we own the code" is our phrasing of the contractor IP gap, and it was inferred rather than observed — if the way your clients describe it is blunter or more specific, the query set should use their words, not ours. (3) What's missing? Three that show up in growth-stage technology deals and aren't here: customer-demanded indemnity caps and E&O insurance requirements (if enterprise buyers push liability terms your clients can't underwrite); open-source license compliance in the codebase (if copyleft exposure surfaces in diligence alongside the IP chain of title); trademark clearance and name conflicts (given "IP & Brand Protection" is a published service line but no brand-conflict pain appears in this set).
Nine findings from a full crawl of charlottecorporatecounsel.com on August 10, 2026 — one critical, three high, three medium, two low. Eight are diagnostic; one requires manual verification your engineering and marketing teams can run directly.
Engineering: start here One finding sits upstream of every other item in this document. robots.txt issues an explicit Disallow: / against nine named AI agents — GPTBot, ClaudeBot, Google-Extended, CCBot, Applebot-Extended, Amazonbot, meta-externalagent, Bytespider and CloudflareBrowserRenderingCrawler — which are precisely the crawlers that build the corpora behind ChatGPT, Claude, Google AI Overviews and Perplexity. Nothing else on this list changes what an assistant can retrieve while that block stands. Two other items your engineering team can act on independently: the HTTP 200 catch-all, which serves a byte-identical copy of the homepage for every unrecognized path including /sitemap.xml (removing the SPA rewrite from _redirects and adding a 404.html fixes it), and the absent homepage structured data, where the article's existing Article schema is a working template for a LegalService block that would finally state Georgia in machine-readable form. Blocking AI crawlers is common — 75% of major news publishers had blocked at least one by mid-2025 (Screaming Frog, July 2025) — but publishers block to protect a content business they monetize directly, which is a different calculation than a law firm's marketing site.
What we found: https://charlottecorporatecounsel.com/robots.txt issues an explicit Disallow: / against nine named agents: GPTBot (OpenAI), ClaudeBot (Anthropic), Google-Extended (Google AI), Bytespider (ByteDance/TikTok), CCBot (Common Crawl), Applebot-Extended (Apple), Amazonbot, meta-externalagent (Meta), and CloudflareBrowserRenderingCrawler. The User-agent: * group also carries a Content-Signal: search=yes,ai-train=no,use=reference directive. Live-browse and search agents are still permitted: ChatGPT-User, PerplexityBot, and Googlebot all fall through to the wildcard Allow: /. This is a deliberate, well-formed opt-out configuration, not a misconfiguration — but its effect is that the site is excluded from the corpora that AI assistants draw on when answering without a live fetch.
Why it matters: The blocked agents are precisely the crawlers that build the retrieval and training corpora behind ChatGPT, Claude, Google AI Overviews, and Perplexity's index. A GEO audit measures whether the firm surfaces when a buyer asks an assistant to recommend startup counsel; those answers are generated predominantly from indexed corpora, not from a live fetch of a domain the model has never heard of. With GPTBot, ClaudeBot, and Google-Extended blocked, the two pages of substantive content on this site — including the 5,300-word GDPR/CCPA article that is the firm's single strongest differentiator — cannot enter those corpora at all. This block is upstream of every other finding in this report: fixing sitemaps, schema, and headings changes nothing while the crawlers that would read them are turned away. Note also that CCBot's block removes the site from Common Crawl, which is a common seed for third-party AI indexes as well.
Recommended fix: Confirm with the client whether the AI opt-out is an intentional policy decision. If the goal is AI visibility, remove the Disallow: / blocks for GPTBot, ClaudeBot, Google-Extended, CCBot, and Applebot-Extended, and change Content-Signal to search=yes,ai-train=yes,use=reference. If the client wants to permit AI answer citation while still withholding model-training rights, the narrower configuration is to allow the retrieval agents (GPTBot, ClaudeBot, PerplexityBot, Applebot-Extended) and keep ai-train=no in the Content-Signal header, which expresses the training restriction without blocking retrieval. Either way this is a single-file edit deployed with the next Cloudflare Pages build.
→ The one question that changes the engagement Was the AI crawler block authored deliberately, or inherited? Both are plausible and they lead to opposite conclusions. Cloudflare — which hosts this site on Pages — changed its default in July 2025 to block AI crawlers for new sites, and it handles roughly 24% of all web traffic (Cloudflare, July 2025), so a well-formed nine-agent block appearing on a Cloudflare-hosted site is at least as likely to be a platform default as an authored policy. There is also a real argument for keeping it: OpenAI's crawl-to-referral ratio is roughly 1,700:1 and Anthropic's roughly 73,000:1 (Cloudflare, July 2025), meaning these crawlers take far more than they send back, which is exactly why many publishers opted out. If the block is deliberate policy, say so and we rescope — the audit becomes a measurement of what assistants say about you from third-party sources, and site-side GEO work is largely wasted effort. If it's an inherited default, the fix is one file and it should ship this week.
What we found: The host serves the homepage for any path that does not resolve to a real file, with an HTTP 200 status rather than a 404. We verified this by MD5-comparing responses: /, /index.html, /services/, /insights/, /sitemap.xml, and a deliberately invented /nonexistent-page-xyz/ all returned the identical 69,680-byte document with checksum 362823fbf9636f4fa0b99558937ef9c8. There is no canonical tag on the homepage to collapse these variants, and no X-Robots-Tag header on the catch-all responses.
Why it matters: A crawler has no way to distinguish a real page from a fabricated one, because both answer 200 with identical content. Three concrete consequences follow. First, any mistyped, stale, or hallucinated inbound link — including URLs an AI assistant invents when guessing at a site's structure, such as /services/ or /about/ — silently resolves to a valid-looking page, so the error is never surfaced or corrected. Second, / and /index.html are duplicate URLs with no canonical, splitting whatever link equity the domain accrues. Third, and most damaging here, /sitemap.xml returns HTML rather than XML, which means a crawler requesting the sitemap receives a 200 response containing a web page — a failure mode that looks like a malformed sitemap rather than an absent one.
/services/, get a 200 back, and treat a fabricated URL as a real one — so the four published service lines have no citable address of their own, and nothing in the response chain ever flags the mistake.Recommended fix: Configure the Cloudflare Pages deployment to return a genuine HTTP 404 with a dedicated error page for unmatched paths, rather than falling back to index.html. In Cloudflare Pages this means removing the SPA catch-all rewrite from _redirects (or scoping it to only the routes the app actually owns) and adding a 404.html at the project root, which Pages serves automatically with the correct status code. Separately, add <link rel="canonical" href="https://charlottecorporatecounsel.com/"> to the homepage so / and /index.html resolve to one address.
What we found: We retrieved the raw HTML for all four URLs. The homepage contains zero application/ld+json blocks — no Organization, no LegalService, no Person, no FAQPage. It also has no Open Graph tags and no canonical link. The Insights article, by contrast, carries a complete and correctly formed Article schema with headline, description, datePublished (2026-07-01), dateModified (2026-07-21), author as a Person with jobTitle, publisher with logo, image, an about array of topics, and mainEntityOfPage — plus nine Open Graph tags and a canonical URL. The capability and the template pattern already exist in this codebase; they were simply never applied to the homepage.
Why it matters: The homepage is the only page on the site that states who the firm is, what it does, and — critically — that Charlotte Lynn Luu is licensed in Georgia. That information currently exists only as prose. Structured data is the mechanism by which a machine reads an entity's identity unambiguously, and this is the one site we have reviewed where that matters more than usual: a LegalService or Attorney schema with an areaServed of Georgia and a founder/employee Person node named Charlotte Lynn Luu is the single most direct available correction to the Charlotte-NC misidentification. Without it, a machine reading this site has to infer the jurisdiction from a footer sentence while the brand name pushes hard in the opposite direction.
Recommended fix: Add a JSON-LD block to the homepage using the same pattern already implemented on the article. Use @type: LegalService (or ProfessionalService) with name, url, description, areaServed: {"@type": "State", "name": "Georgia"}, knowsAbout covering the four practice areas, and a nested founder of @type: Person named Charlotte Lynn Luu with jobTitle, alumniOf (University of Georgia School of Law), and hasCredential for the Georgia bar admission. Add sameAs links to the firm's LinkedIn and State Bar of Georgia listing. Also add Open Graph tags and a canonical link to the homepage, matching the article's implementation.
What we found: Requests to /sitemap.xml and /sitemap_index.xml both returned the homepage HTML with HTTP 200 (see the catch-all finding above), not sitemap XML. robots.txt contains no Sitemap: directive. No sitemap exists anywhere we could locate.
Why it matters: The direct discovery cost is limited here, because the site has only two indexable URLs and both are reachable from the homepage — the article is linked from the Insights section. The real cost is signalling. A sitemap is where lastmod timestamps live, and lastmod is one of the few machine-readable freshness signals a crawler can act on before fetching a page. The site currently emits no freshness signal of any kind at the URL level: no sitemap lastmod, and no Last-Modified response header on any page (we confirmed this via HEAD requests). It is also the mechanism for telling Search Console what to crawl, which matters given the indexation question raised below.
Recommended fix: Generate a sitemap.xml at build time containing the two indexable URLs (/ and /insights/analyzing-ai-under-gdpr-and-ccpa/) with accurate lastmod values drawn from the build or content-modification date. Exclude /intake/ and /questionnaire/, which are correctly noindexed. Add a Sitemap: https://charlottecorporatecounsel.com/sitemap.xml line to robots.txt. As the Insights section grows, the sitemap should be regenerated on each publish so lastmod stays accurate — inaccurate lastmod values are worse than none.
What we found: Several homepage headings use <br/> for visual line breaks without surrounding whitespace, so the words on either side collide when the markup is stripped. The raw source <h2>Legal counsel,<br/>mapped to how you grow.</h2> extracts as "Legal counsel,mapped to how you grow." Likewise <h2>Trusted by founders<br/>and operators.</h2> extracts as "Trusted by foundersand operators.", the section eyebrow renders as "What yourstartup needs", and the H1 — built from two <span class="hero-line"> elements — extracts as "Less Friction.More Growth." We confirmed this by running the same text-extraction a crawler would perform against the served HTML.
Why it matters: Headings are the strongest structural signal on a page and are frequently used as passage labels when a retrieval system chunks a document. Every affected heading on this site produces at least one word that appears in no dictionary — "foundersand", "yourstartup", "counsel,mapped". A token that does not exist cannot match a query, so these headings contribute nothing to retrieval and mildly degrade the page's apparent text quality. This affects four of the six H2s and the only H1 on the site's only commercial page.
Recommended fix: Add an explicit space before each <br/> inside heading elements, or replace the visual line breaks with CSS (display: block on the spans, or a max-width that wraps naturally). The rendered appearance is unchanged; only the extracted text differs. Apply the same fix to the <span class="hero-line"> construction in the H1.
What we found: The homepage H1 reads "Less Friction. More Growth." It names no practice area, no service, no jurisdiction, and not the firm or attorney. The descriptive line that would make a strong H1 — "Corporate counsel for technology companies" — is present immediately above it but is marked up as a styled div, not a heading. The <title> element and meta description are both well-written and do carry this information; the heading structure does not.
Why it matters: The H1 is the heading a retrieval system most often treats as the document's label, and it is weighted heavily when deciding what a page is about. "Less Friction. More Growth." would apply equally to a fitness studio or a logistics vendor. Given that the firm's brand name actively pushes machines toward Charlotte, North Carolina, the site's most prominent heading is an opportunity to state "corporate counsel", "technology companies", and "Georgia" in the position where that assertion carries the most weight — and it currently states none of them.
Recommended fix: Promote the existing descriptive line to the H1 and demote the tagline to a styled subheading or paragraph: <h1>Corporate counsel for technology companies</h1> followed by "Less Friction. More Growth." as a <p class="hero-tagline">. Consider extending the H1 to name the jurisdiction, e.g. "Georgia corporate counsel for technology companies". The visual hierarchy can be preserved entirely in CSS; this is a semantic change, not a design change.
What we found: The homepage carries no visible published or updated date, no dateModified in structured data (it has no structured data at all), and the server returns no Last-Modified header — we confirmed this with HEAD requests against /, which returned only cache-control: public, max-age=0, must-revalidate from Cloudflare with no modification timestamp. Combined with the absent sitemap, there is no lastmod either. The article page is the sole exception: its Article schema carries datePublished 2026-07-01 and dateModified 2026-07-21, and the byline displays "July 2026".
Why it matters: A crawler cannot establish that the homepage is current. For a product or services page this is a soft signal rather than a defect — commercial pages routinely carry no date, and we have not scored the homepage down for freshness on that basis. It becomes material only in combination: the site has no sitemap lastmod, no Last-Modified header, and no on-page date, so there is no path by which a machine can determine that this firm is actively practising. For a solo practice whose credibility rests partly on being a going concern, that is worth closing.
Recommended fix: Emit a Last-Modified response header from the Cloudflare Pages build (or set it via a _headers rule keyed to the deploy timestamp). Once a sitemap exists, its lastmod values will supply the same signal. Do not add a visible "last updated" date to the homepage — on a marketing page that reads as staleness rather than currency; the header and sitemap are the right carriers.
What we found: The served HTML for /questionnaire/ contains an <h2> whose literal text is ${section.title} — a JavaScript template literal that was shipped in the static markup rather than being interpolated at build time. It sits alongside the legitimate headings "Client & technology questionnaire" (H1), "Respondent information", and "Questionnaire received". The page is correctly served with <meta name="robots" content="noindex, nofollow, noarchive">, as is /intake/.
Why it matters: The visibility impact is essentially nil, because the page is noindexed and is a gated client form rather than marketing content. It is worth reporting for two narrower reasons: it is a template element the client-side script clones at runtime, so if the script fails the placeholder is what a visiting client sees; and it indicates the heading is generated dynamically, which is the pattern to avoid if this markup is ever reused for a public-facing page.
${section.title} where a section heading belongs, at the exact moment they are deciding whether this practice is buttoned-up.Recommended fix: Move the ${section.title} element inside a <template> element so it is not part of the rendered document, or hide the prototype node with hidden until it is cloned and populated. No indexation change is needed — the noindex directives on both form pages are correct as they stand.
The following item could not be assessed through our analysis method (rendered markdown). We recommend your engineering team verify it manually before the validation call. It is worth prioritising: brand web mentions are the strongest known predictor of AI citation (r = 0.664), far ahead of backlinks (r = 0.218) and organic traffic (r = 0.274), per Seer Interactive's October 2025 study — which makes off-site entity signals a first-order concern for a firm whose name resolves to the wrong state.
What to check: A site:charlottecorporatecounsel.com search returned zero results from the domain. A search for the bare domain string also returned no pages from the site; results instead surfaced charlottecounsel.com (Law Office of Todd Gonyer, Charlotte NC), the ACC Charlotte chapter, and unrelated Charlotte, North Carolina corporate firms. We could not confirm from the outside whether this reflects genuine non-indexation, a very recently launched domain that has not yet been crawled, or simply the limits of the search tooling available to this analysis. Googlebot is permitted in robots.txt, so nothing is blocking conventional indexation; the absent sitemap and the lack of inbound links are the more likely explanations, and both are addressable.
Recommended action: Verify actual index coverage directly rather than inferring it from search results: register the property in Google Search Console and Bing Webmaster Tools and read the Index Coverage report. Submit the sitemap once it exists. Then establish the entity-disambiguating citations that both search engines and language models rely on — a Google Business Profile with the Georgia service area, a State Bar of Georgia member listing, and consistent name/jurisdiction data on the firm's LinkedIn and any legal directory profiles. These external references are what allow an assistant to resolve "Charlotte Corporate Counsel" to a Georgia attorney rather than a North Carolina city.
Read the freshness score carefully The crawl covered all four URLs on the domain, so this is a complete sample rather than a partial one — but it is a very small one, and three of the four pages carry no detectable date at all. The 1.00 weighted freshness score rests entirely on the single Insights article, which is genuinely current (published 2026-07-01, modified 2026-07-21). The homepage, /intake/ and /questionnaire/ are unscored because there is no date to score, not because they are fresh. Treat this metric as "nothing stale was found" rather than as evidence of an actively maintained content programme.
Why now The timing argument for a firm this size isn't that AI search is coming — it's that position in the answer layer is being assigned right now, and legal services is one of the last categories to notice:
• Buyer discovery is shifting quarter over quarter: 94% of B2B buyers now use LLMs during the buying process (6sense, November 2025). The founders and operators who hire outside counsel are the same population.
• Early citations compound — the domains AI platforms learn to treat as reliable get pulled into more answers as retrieval patterns settle, and that advantage is self-reinforcing rather than rented month to month.
• Crawler volume is climbing fast: Akamai measured 1.6 billion daily AI bot requests across its CDN, up 78% over six months (Akamai, February 2026). What the engines index this quarter is what they answer with next — and on this domain, the answer is currently nothing.
• Outside corporate counsel for startups is still early-innings in GEO. A solo practice cannot outspend Cooley or Morris, Manning & Martin on conventional search, but in the answer layer it is competing largely against inaction rather than against entrenched strategies — a window that narrows as the larger firms start optimising for the same answers.
Once the inputs above are validated, the audit measures citation visibility across the buyer queries this knowledge graph implies — questions in the register of "who can draft an MSA that survives enterprise procurement," "flat-fee startup lawyer vs. an hourly firm," "what do GDPR and CCPA require when customer data runs through an LLM," and "do we actually own code our contractors wrote." You'll see exactly which of those queries return answers naming Westaway, Outside GC or a free template set but not Charlotte Corporate Counsel, which ones name a Charlotte, North Carolina firm instead of you, and where the gap between the two sits query by query. The Layer 1 items are worth shipping before that measurement runs — crawler access, a real 404, and Georgia stated in machine-readable form raise the baseline the audit reads, rather than becoming findings it discovers.
45–60 minutes. We walk this document top to bottom, resolve the eleven questions in the checklist, and lock the inputs the query set is built from.
We generate buyer queries from the validated personas, competitors, features and pain points, then run them across the selected AI platforms and record every answer and citation.
Visibility analysis, competitive positioning against the validated set, and a three-layer action plan prioritised by which gaps actually cost citations.
Start now Three technical items your engineering team can ship without waiting for the call: (1) remove the SPA catch-all rewrite from _redirects and add a 404.html at the Cloudflare Pages project root, so unmatched paths return a real 404 instead of a byte-identical copy of the homepage — and add <link rel="canonical"> to the homepage while you're in there, which collapses the /index.html duplicate; (2) add a LegalService JSON-LD block to the homepage with areaServed of Georgia and a nested founder Person node for Charlotte Lynn Luu, reusing the Article schema pattern already implemented on the Insights page, plus the Open Graph tags the homepage is missing; (3) generate sitemap.xml at build time with the two indexable URLs and accurate lastmod, add the Sitemap: directive to robots.txt, and emit a Last-Modified header from the Pages build. Separately, register the domain in Google Search Console and Bing Webmaster Tools now — that answers the open indexation question directly rather than by inference, and it takes a day. The robots.txt AI-crawler block is deliberately not on this list: it needs your policy decision first, and if crawlers stay blocked it supersedes everything else here. These don't depend on the rest of the audit and will improve your baseline visibility before we even measure it.
Two jobs before we meet. The questions on the left require your judgment — no one knows your business better than you. The engineering tasks on the right don't require the call at all.
_redirects and add a 404.html at the Cloudflare Pages project root/services/ and /sitemap.xml — from returning a 200 with a byte-identical copy of the homepage.<link rel="canonical"> and Open Graph tags to the homepage/index.html duplicate into one address; the article page already has both, so the pattern exists in the codebase.LegalService JSON-LD block to the homepage with areaServed of Georgia and a founder Person node for Charlotte Lynn Luusitemap.xml at build time with accurate lastmod, add the Sitemap: directive to robots.txt, and emit a Last-Modified header<br/> inside headings and promote "Corporate counsel for technology companies" to the H1site: results. Marketing-owned, one day of work.