Engagement Foundation Review

Charlotte Corporate Counsel
Audit Foundation

Founders shipping AI into a product now ask an assistant which lawyer can tell them whether it's safe to ship — and the firms that establish visibility inside those answers now lock in a structural advantage while legal counsel for AI and emerging technology is still barely contested as a category. Before we run the audit, we need to make sure we're asking the right questions about the right competitors to the right buyers. This document presents what we've learned about Charlotte Corporate Counsel's market — your job is to tell us what we got right, what we got wrong, and what we missed.

Prepared August 11, 2026
charlottecorporatecounsel.com
AI & Emerging Technology Legal Counsel
Revision 2 — client feedback applied
GEO Readiness

Where You Stand Today

Before we measure whether assistants name this firm when a founder asks who can make an AI-enabled product legally safe to ship, these three signals tell us whether AI systems can reach and read the site at all. They are derived mechanically from the August 10, 2026 crawl of all four URLs on charlottecorporatecounsel.com and are unchanged in this revision — the client feedback in Revision 2 changed the knowledge graph, not the site.

Technical Readiness
At Risk
One critical finding: robots.txt issues an explicit Disallow: / against nine named AI agents including GPTBot, ClaudeBot, Google-Extended and CCBot. Three high-severity findings follow it — an HTTP 200 catch-all that serves the homepage for every unrecognized URL, no structured data on the homepage, and no confirmed presence in any search index.
Content Freshness
Good
Weighted freshness: 1.00. 1 page updated within 90 days — the July 2026 GDPR/CCPA article, which carries both datePublished (2026-07-01) and dateModified (2026-07-21). 0 pages older than 6 months. The rating rests on a single scored page: 1 product page (the homepage) has no detectable date — no on-page date, no Last-Modified header, no sitemap lastmod — verify manually. 3 of 4 pages are unscored for freshness.
Crawl Coverage
At Risk
robots.txt confirmed blocking GPTBot, ClaudeBot, Google-Extended and Bytespider at the root. ChatGPT-User, PerplexityBot and Googlebot fall through to the wildcard and are allowed. No XML sitemap exists at any conventional location, and robots.txt carries no Sitemap: directive.
Executive Summary

What You Need to Know

Legal counsel is bought the way it has always been bought — on referral and reputation — right up until the moment the founder skips the referral and asks an assistant instead. That moment has already arrived for the buyers in this graph: 87% of B2B software buyers say AI chatbots are changing how they research vendors, and half now start that research in a chatbot rather than Google (G2, October 2025). The population G2 surveyed is exactly this firm's client base — founders and operators at software companies — even though the purchase in question is legal counsel rather than software. The repositioning this revision records makes that shift sharper rather than softer: a buyer who needs someone to tell them whether their AI feature is safe to ship is, almost by definition, a buyer already comfortable asking an AI what to do. A solo practice has almost no chance of outspending Am Law 200 brands and national platforms on conventional search, but legal counsel for AI and emerging technology is not yet a contested market in the answer layer, and position there is being assigned now rather than defended.

This document is the foundation the audit runs on, and it has three parts. The competitive landscape defines which firms and substitutes the audit tests you against head-to-head, and which it treats as category context. The buyer personas define who is doing the searching, which determines the language and the stage of every query we generate. The Layer 1 technical baseline determines something more fundamental than either: whether AI systems can access and correctly identify this site at all. Each section below is something we are asking you to confirm or correct before the query set is written — not a conclusion we are presenting.

The validation call is a working session, not a walkthrough. Two kinds of decisions come out of it. The first is input validation: whether the right firms are in the right tiers, whether the personas are the people who actually evaluate and sign, and whether the capability ratings match how you win and lose. Every one of those answers changes which queries get written and how they are weighted. The second is engineering triage: which technical items your side can start on immediately, without waiting for query results. Those two lists are collected in full in the Pre-Call Checklist near the end of this document — you can prepare for the call from that section alone.

TL;DR — Action Items
  • 🔴 Critical: robots.txt blocks every major AI training and indexing crawler — engineering should pull /robots.txt and confirm whether the nine Disallow: / blocks (GPTBot, ClaudeBot, Google-Extended, CCBot, Applebot-Extended, Amazonbot, meta-externalagent, Bytespider, CloudflareBrowserRenderingCrawler) were authored deliberately or inherited from a Cloudflare default.
  • 🟡 High: Every unrecognized URL returns HTTP 200 with a byte-identical copy of the homepage — remove the SPA catch-all rewrite from _redirects, add a 404.html at the Cloudflare Pages project root, and add a canonical link to the homepage so / and /index.html stop competing.
  • 🟣 Validate at the Call: the "Charlotte" in Charlotte Corporate Counsel — if you want Georgia buyers only, the entire query set is built around Atlanta and Georgia and we treat the Charlotte, NC association as noise; if you want to contest that association, we add a query cluster specifically to measure how much of it there is to displace.
  • 🟣 Validate at the Call: the competitive set still reflects your prior positioning — the ten firms below were assembled against outside corporate counsel generally, and only SaaS Law Firm (Andrew S. Bosin) markets AI contract work at all; if buyers comparing AI counsel are shortlisting practices we haven't listed, the head-to-head queries measure you against the wrong opponents and roughly 30 to 40 of the audit's queries move.
  • ✅ Start Now: homepage JSON-LD with areaServed: Georgia — the Insights article already carries a complete, correctly formed Article schema, so the pattern exists in the codebase; applying a LegalService block with a founder Person node named Charlotte Lynn Luu to the homepage needs no input from the validation call.
  • 📋 Validation Call: is the AI crawler opt-out a deliberate policy position? — this is upstream of everything else in this document; if the block stays, no amount of schema, sitemap or heading work changes what an assistant can retrieve, and the engagement's scope needs rethinking before the queries run.
How This Works

Reading This Document

Three things to know before you start marking it up.

What this is This is the foundation the audit runs on. We assembled a knowledge graph of outside legal counsel for startups and small businesses building with AI and emerging technologies as buyers experience it — who competes for the same spend, who sits in the room when a founder decides to hire a lawyer, which capabilities get compared, and what frustrations drive the search in the first place. Every entity below becomes queries. Get the foundation right and the audit measures your market; get it wrong and it measures a market that doesn't exist. This is Revision 2. Your feedback has been applied to the knowledge graph: the category and service lines now lead with AI and emerging technology, three AI capabilities and patent support have been added to the taxonomy, IP Ownership has been raised to Strong, a Head of Product (AI) persona has been added, and four AI-specific pain points are now in the set. Items you touched carry a High badge sourced to client feedback.

Your job Read for what's wrong and what's missing, not for what's right. Purple boxes throughout the document mark the places where our confidence is lowest and your answer changes the audit most. Every one of them is collected in the Pre-Call Checklist near the end — you can prepare for the call from that section alone.

Confidence badges High means we found it stated directly on your site, a competitor's site, or a review platform. Medium means we triangulated it from multiple weaker signals. Low means we inferred it and need you to confirm or kill it. The low-confidence items are where your input is worth the most.

Company Profile

Who We Think You Are

Pulled from charlottecorporatecounsel.com, with the category and service lines rewritten to your correction. This is the anchor entity — every query in the audit is scored on whether the answer names it, which makes getting the entity itself unambiguous the first job.

Company name Charlotte Corporate Counsel High
Domain charlottecorporatecounsel.com
Name variants Charlotte Lynn Luu · Charlotte Luu · Charlotte Luu, Esq. · Charlotte L. Luu · Law Office of Charlotte Luu · Luu Corporate Counsel · CCC
Category Outside legal counsel for startups and small businesses building with AI and emerging technologies — protecting AI-enabled product workflows, SaaS terms of service, and technology licensing, delivered on fixed-scope engagements rather than hourly billing High
Segment Startup — and small businesses building with emerging technology
Service lines AI Workflow & Emerging Technology Protection · SaaS Terms of Service & Commercial Contracts · Technology Licensing & IP Ownership · Contractor & Workforce · Corporate Governance High
Positioning (from site) "Less Friction. More Growth." — corporate counsel for technology companies, delivered on fixed-scope proposals with a one-business-day response commitment

→ Question 1 Six of the seven name variants in this profile are versions of your personal name, and that is deliberate: "Charlotte Corporate Counsel" reads as a Charlotte, North Carolina firm to both search engines and language models, and a search for the exact firm name returns Charlotte, NC corporate practices — Marcellino Moore, Gardner Skelton, PLG Law, Dozier Miller — rather than a Georgia attorney. Do you want to be found only by buyers searching for Georgia and Atlanta counsel, or do you want us to also test the Charlotte, NC association to measure how much of it there is to displace? If it's Georgia only, we build the query set around Atlanta and Georgia and treat North Carolina results as noise; if you want to contest it, we add a dedicated cluster of entity-resolution queries and the audit reports on how far the firm name has to travel. You are licensed only in Georgia, so this is not a question of preference — it's a question of whether out-of-state traffic is worth anything to you at all. Your feedback moved the category toward AI and emerging technology but said nothing about geography, so this remains the single most consequential open item in the graph.

Buyer Personas

Who's Actually Buying

6 personas: 4 decision-makers, 1 evaluator, 1 influencer. These are the people whose search language the query set is built from — how they phrase the problem determines what the audit measures.

Critical review area This is the section where client input changes the audit most. Personas determine query phrasing, query stage, and query volume. A persona that doesn't exist in your deals produces a whole cluster of queries measuring a market that isn't yours — and at a solo practice serving pre-GC companies, the buying committee is small enough that one wrong role meaningfully distorts the set.

Data sourcing note Role, seniority, department, influence level, veto power and technical level are KG fields. Two personas — Founder & CEO and Chief Operating Officer — come from role titles on your homepage testimonials, which carry job titles but placeholder attribution ("Client name"), so they are grounded in stated titles rather than confirmed clients. Two now come from you directly: Head of Product, AI is a persona you added, and the CTO & Co-Founder role was rewritten to your correction — both now carry High confidence sourced to client feedback rather than inference. The remaining two (VP of Sales, Head of Finance) are still inferred from category buying patterns and are where your input is now worth the most. The role description, buying jobs and query focus areas on every card are synthesized by us from those fields — they are our reading, and the most useful thing you can do is correct them.

Marcus Ellery
Founder & CEO · Executive · C-Suite
Decision-maker High
Runs the company and owns the legal relationship by default, because there is no one else to own it. Signs the engagement, sets the budget, and is the person the enterprise contract lands on at 11pm when it has nowhere else to go.
Veto power: Yes — at this company size the founder is both the initiator and the signer, with no procurement layer in between.
Technical level: Medium — can read an MSA and understand what an indemnity does, cannot tell whether the limitation-of-liability language actually holds.
Primary buying jobs: Problem recognition and vendor selection — decides the downloaded template is no longer good enough, shortlists counsel, and signs the engagement.
Query focus areas: Startup lawyer vs. big firm, flat-fee legal for startups, whether an MSA needs a lawyer at all, ownership of contractor-built code, what a first-time enterprise contract should contain.
Source: homepage testimonial titles (automated scrape)

Does the founder run the search themselves, or does someone else assemble the shortlist and hand it over? If it's the latter, discovery-stage queries move to that role and the founder only gets validation-stage language.

Priya Raghunathan
Chief Operating Officer · Operations · C-Suite
Decision-maker Medium
The operator every contract routes to once the founder stops handling them personally — with no legal training, no GC to escalate to, and no budget to hire one.
Veto power: Yes — but this is the field we are least sure of, since it was assigned from a testimonial title rather than an observed engagement.
Technical level: Low — evaluates counsel on responsiveness and clarity, not on doctrinal depth.
Primary buying jobs: Requirements definition and ongoing scope management — defines what "covered" means month to month and owns the relationship after signature.
Query focus areas: Outsourced general counsel for startups, fractional GC cost, handling contracts without an in-house lawyer, multi-state hiring and non-compete rules.
Source: homepage testimonial titles (automated scrape)

Does the COO actually sign the engagement, or scope the work and route the decision to the founder? If they scope rather than sign, we reclassify to evaluator and their queries shift from "hire outside counsel" to "how do I handle this contract myself."

Devin Okafor
CTO & Co-Founder — owns AI/ML stack and model vendor decisions · Engineering · C-Suite
Decision-maker High
Co-founder responsible for the codebase, the customer data inside it, and — per your correction — the choice of model provider and the terms that came with it. The one who reads the DPA and the model vendor's acceptable-use policy line by line.
Veto power: Yes — can stop an engagement over IP assignment, data-processing terms, or what a model vendor is permitted to do with the company's data, though they rarely initiate the search.
Technical level: High — can evaluate whether the privacy and AI advice is technically coherent, which is the bar a generalist firm fails in front of them.
Primary buying jobs: Technical evaluation and risk veto — reviews DPA, subprocessor disclosure, model vendor terms, and contractor IP assignment language before anything is signed.
Query focus areas: What a model provider's terms permit them to do with customer data, GDPR and CCPA obligations when customer data runs through AI models, indemnity for AI output, DPA and subprocessor disclosure, whether the company owns contractor-written code.
Source: client feedback — role rewritten in Revision 2

With a Head of Product (AI) now in the set, who actually owns the model vendor decision — the CTO, or the product lead? If it's shared, vendor-terms and output-ownership queries need both registers rather than the CTO's alone.

Nadia Ferreira
Head of Product, AI · Product · Director
Evaluator High
The builder you told us you want to reach — the person who ships the AI feature and discovers afterwards that nobody can say who owns its output. High influence over what gets built and what gets promised, no signature authority over the legal engagement.
Veto power: No — the only high-influence persona in this set without it, which is why they are classed as an evaluator rather than a decision-maker. They shape the requirement and hand the decision up.
Technical level: High — understands the model, the pipeline, and the difference between a training-data question and an output-ownership question.
Primary buying jobs: Requirements definition and technical evaluation — surfaces the AI-specific legal question, defines what "safe to ship" means for a given feature, and evaluates whether counsel understands the product before recommending them.
Query focus areas: Who owns LLM-generated output, what the terms of service need to say about AI features, acceptable-use and human-review provisions, disclaiming AI accuracy to customers, whether the company can promise ownership of AI output in a contract.
Source: client feedback — persona added in Revision 2

Does a product lead ever contact you directly, or does the AI-legal question always route through the founder or CTO first? If they contact you directly, product-stage queries about shipping AI features earn their own cluster; if not, this persona's language folds into the CTO's.

Tanya Brzezinski
VP of Sales · Revenue · VP
Influencer Medium
Owns the number and experiences legal review purely as deal latency. Escalates hard when redlines stall the quarter, but does not control the legal budget and does not select counsel.
Veto power: No — the only persona in this set without it, which is why they are classed as an influencer rather than a decision-maker.
Technical level: Low — cares about turnaround time and whether a term can be conceded, not about how it's drafted.
Primary buying jobs: Problem escalation and speed requirements — supplies the pain that triggers the search without selecting or signing.
Query focus areas: Enterprise redline turnaround times, MSA negotiation help, answering security questionnaires and DPA requests, contract playbooks that let reps close without a lawyer.
Source: inferred from category buying patterns (LLM inference)

At your typical client's size, does a VP of Sales actually bring you in when a deal stalls in redlines, or does the founder always make that call alone? If founders buy alone, we drop revenue-leader query language and reweight toward founder and operator searches.

Gabriel Soto
Head of Finance · Finance · Director
Decision-maker Low
Controls spend and reacts to legal invoices after the fact. Present at growth-stage clients with a real finance function; frequently absent at seed, where the role collapses into the founder or the COO.
Veto power: Yes — assigned on the assumption that budget authority over legal spend sits here rather than with the founder. This is the single least certain assertion in the knowledge graph.
Technical level: Low — evaluates on predictability and comparability of cost, not on legal substance.
Primary buying jobs: Budget approval and cost containment — compares a fixed-scope proposal against last quarter's hourly invoices.
Query focus areas: Flat fee vs. hourly legal costs, typical legal spend for a startup, outside counsel retainer pricing, what a fractional GC should cost per month.
Source: inferred from category buying patterns (LLM inference)

Does a finance lead ever hold the budget veto on legal spend at your clients, or does that authority sit with the founder? If it always sits with the founder, we delete this persona and redistribute its cost-predictability queries rather than running them twice.

→ Anyone missing? These roles sometimes appear in counsel deals at companies building with AI and emerging technology — do they show up in yours? Head of Security / Compliance (if the SOC 2 and AI-governance conversation is separate from the CTO's, which it usually becomes the moment an enterprise customer sends an AI questionnaire). Incoming first General Counsel or Head of Legal (the person who either replaces you or becomes the one who instructs you — worth knowing whether they're a threat, a buyer, or both). Fractional CFO or outsourced accounting firm (at pre-GC startups these are often the referral path to counsel, and if so they search on behalf of the founder in their own language). Who else shows up in your deals?

Competitive Landscape

Who You're Up Against

5 primary + 5 secondary competitors identified. Tier assignment is what separates a head-to-head comparison query from a category-awareness query, so these ten names decide the shape of the competitive half of the audit.

Why tiers matter Each primary competitor earns roughly six to eight head-to-head queries — questions in the register of "flat-fee startup lawyer vs. hourly firm," "who drafts terms of service for an AI product," and "Westaway alternatives for a Georgia software company" — which puts roughly 30 to 40 of the audit's queries on the tier assignments below. Three things to flag before you read them. First, your site publishes no comparison or "vs" content of any kind, so this entire set is outbound-sourced — we assembled it from competitor sites and category listings, not from anything you told the market. Second, SaaS Law Firm (Andrew S. Bosin LLC) is the one primary competitor we tiered from a category listing rather than a direct signal; if he rarely appears in your actual deals, moving him to secondary shifts about six to eight queries out of the head-to-head set and into category coverage. Third — and this is new in Revision 2 — this set was built against your prior positioning as outside corporate counsel generally, and Bosin's practice is the only one on it that markets AI contract work at all. Your feedback did not change any competitor, so nothing below has moved; the question is whether it should.

Primary Competitors

Westaway

Primary High
westaway.com
Founder-led startup law firm that replaced the billable hour with flat fees and a monthly subscription fractional GC. Same anti-hourly pitch as you and a far stronger content and brand presence with founders, but a generalist startup practice rather than deep SaaS commercial-contract and privacy specialization.
Source: competitor website

Outside GC

Primary High
outsidegc.com
National partner-only outsourced general counsel firm staffing former in-house lawyers on flexible engagements. Wins on multi-state coverage and the ability to swap in a specialist mid-engagement; loses on the single-relationship continuity and startup-stage pricing a solo practice can offer.
Source: competitor website

SaaS Law Firm (Andrew S. Bosin LLC)

Primary Medium
njbusiness-attorney.com
Solo flat-fee SaaS and AI contracts practice that actively markets into Atlanta and dozens of other startup metros for MSAs, ToS, privacy policies, and reseller agreements. The closest like-for-like alternative on scope and price, and currently far more visible in AI answers for "SaaS contract lawyer" queries; weaker on ongoing counsel relationship and governance work.
Source: category listing / directory

Morris, Manning & Martin

Primary High
mmmlaw.com
Atlanta-founded Am Law 200 firm (now part of Taft) whose Corporate Technology practice averages roughly 50 venture deals a year and is the default incumbent for Georgia tech companies. Wins on investor network, specialist bench, and local brand; loses on hourly billing, partner access, and willingness to prioritize a pre-Series-A client. Both "Morris, Manning & Martin" and "Taft" are in the variant list — AI answers may use either.
Source: competitor website

UpCounsel

Primary High
upcounsel.com
Marketplace matching businesses with vetted ex-BigLaw attorneys, including a dedicated outside general counsel program. Wins on price transparency, instant availability, and the sheer volume of contract-lawyer search traffic it captures; loses on continuity, accountability, and the deal-context knowledge that comes from one ongoing counsel.
Source: competitor website

Secondary Competitors

Cooley

Secondary High
cooley.com
The default venture-track startup firm, ranked first globally for VC financings, with Cooley GO free resources that dominate founder search results. Rarely a real head-to-head at your price point, but it anchors the "best startup lawyer" answer set and sets founder expectations before they ever look at a boutique.
Source: category listing / directory

Lawtrades

Secondary Medium
lawtrades.com
On-demand legal talent platform offering hourly, project, and subscription access to contract attorneys, typically in the $150–180/hour range. Skews mid-market and enterprise in-house teams rather than pre-legal-function startups, so it surfaces in AI recommendations more often than it appears in your actual deals.
Source: category listing / directory

Priori Legal

Secondary Medium
priorilegal.com
Curated outside-counsel marketplace plus panel-management software built for existing in-house legal departments. Overlaps with you only when a growth-stage company has already hired a first GC and is sourcing overflow contract work.
Source: competitor website

Common Paper

Secondary High
commonpaper.com
Free, open-source standard SaaS agreements (cloud service agreement, DPA, mutual NDA, SLA, design partner) plus a guided contracting platform. Not a law firm, but the most common reason an early-stage founder decides they do not need counsel yet — the substitute you have to displace, not just outsell.
Source: competitor website

LegalZoom

Secondary High
legalzoom.com
Mass-market DIY formation and document service with an attorney-access subscription add-on. Owns the bottom of the funnel for entity formation and operating agreements, and routinely appears in AI answers to "how do I set up my startup legally" — capturing buyers before they consider bespoke counsel.
Source: category listing / directory

→ Three things to correct here (1) Now that you lead with AI and emerging technology, is this still the right set? SaaS Law Firm (Andrew S. Bosin) is the only practice here that markets AI contract work; every other name competes with you on the corporate-counsel positioning you just moved away from. Are there AI-specialist boutiques a founder shopping for AI counsel would shortlist that we haven't listed — and if so, do they displace names on this list or sit alongside them? This is the highest-consequence competitive question in the revision: the head-to-head half of the audit is only as good as this set. (2) When you lose a client, who do you lose them to? An Atlanta firm like Morris, Manning & Martin, another flat-fee solo like Bosin, or Common Paper's free templates? If the real fight is against templates and other solos rather than against big firms, we retier the set and the competitive half of the audit shifts from "boutique vs. Am Law" to "counsel vs. no counsel." (3) Three of the ten are medium confidence on tier — Bosin's SaaS Law Firm as primary, Lawtrades and Priori Legal as secondary. Do any of the three actually come up in your deals, or are they artifacts of what directories publish? Priori Legal in particular only overlaps with you once a company has hired a first GC, which may be past the point where you're still in the conversation.

Feature Taxonomy

What Buyers Compare

15 buyer-level capabilities mapped: 9 strong, 2 moderate, 3 weak, 1 absent. These determine which capability queries the audit tests and which ones we expect you to lose — the honest ratings are as load-bearing as the flattering ones.

AI Workflow Legal Protection Strong High

Make sure the AI parts of our product are legally safe to ship — who owns the outputs, what the model vendor can do with our data, and what we're actually promising customers about how the AI behaves

Emerging Technology Counsel Strong High

Get a lawyer who already understands the technology we're building instead of one we have to educate before every conversation about a product nobody has written rules for yet

SaaS Terms of Service & Commercial Contract Drafting Strong High

Get a real MSA, subscription agreement, and terms of service that hold up when an enterprise buyer's legal team reads them line by line

Enterprise Deal Negotiation & Redline Turnaround Strong High

Have someone sit on the redlines with our biggest customer's legal team and get the deal signed without losing the quarter

Data Privacy & AI Regulatory Compliance Strong High

Figure out what GDPR and CCPA actually require now that we're running customer data through AI models, and get our DPA and privacy policy to match

Contractor & Workforce Agreements Strong High

Paper the contractors and employees properly on the way in, and make sure the confidentiality and non-solicit terms actually work on the way out

Fixed-Scope Pricing & Cost Predictability Strong High

Know exactly what the legal work costs before it starts, with no surprise invoice at the end of the month

Direct Senior Access & Turnaround Speed Strong Medium

Reach the actual lawyer who knows our business and get an answer the same week, not a junior associate and a two-week queue

IP Ownership & Licensing Strong High

Make sure we actually own the code, models, and data our product is built on, and license our technology out on terms that don't give the other side our IP

Entity Formation & Corporate Governance Moderate Medium

Set up the entity, operating agreement, and founder split correctly the first time so it survives the next round of diligence

Patent Strategy & Filing Support Moderate High

Figure out whether anything we've built is worth patenting and get the filing handled without it becoming the whole legal budget

Multi-State & Cross-Border Coverage Weak High

Cover us as we hire and sell across state lines and into Europe, without having to find a new lawyer in every jurisdiction

Specialist Bench Depth Weak Medium

Pull in an employment, tax, immigration, or litigation specialist when something comes up that our main lawyer doesn't handle

Self-Serve Templates & Contract Automation Weak Medium

Give the sales team a playbook and a template library so routine deals close without routing every one through a lawyer

Venture Financing & Cap Table Work Absent Medium

Run our SAFE round or priced Series A, handle the term sheet, and keep the cap table and option pool clean

Which three do you actually win on? The audit tests all 15 capabilities, but competitive differentiation queries will emphasize 3. Nine are now rated Strong — up from six, after your feedback added two AI capabilities and raised IP Ownership:

AI Workflow Legal Protection — added by you, and the strongest claim on the data: four separate high-severity pain points link to it
SaaS Terms of Service & Commercial Contract Drafting — also four high-severity pain points, including the AI features that outran the terms of service
Emerging Technology Counsel — added by you; the only Strong capability with no high-severity pain point linked to it yet, which is a gap in the graph rather than a judgment on the capability
IP Ownership & Licensing — raised from Moderate to Strong on your correction
Data Privacy & AI Regulatory Compliance — three high-severity pain points, though the site evidence is still a single published article (July 2026, GDPR/CCPA and AI processing)
Enterprise Deal Negotiation & Redline Turnaround
Contractor & Workforce Agreements
Fixed-Scope Pricing & Cost Predictability
Direct Senior Access & Turnaround Speed — the one Strong rating we still hold at medium confidence, since it rests on the site's stated one-business-day commitment rather than on observed delivery

Nine of fifteen rated Strong is a high proportion, and it matters more now than it did in Revision 1: with three quarters of the taxonomy marked as a strength, the differentiation queries have nothing to concentrate on unless you pick. Which three best represent where Charlotte Corporate Counsel wins deals — not where the work is most common, but where a prospect chooses you over Westaway, Outside GC, or a template?

→ Three things to correct here (1) Venture Financing & Cap Table Work is still rated Absent — your feedback added patent work and three AI capabilities but left this one alone, so we have carried the Absent rating forward unchanged. Is that right? Founders searching for a startup lawyer ask about fundraising before they ask about anything else, so if you do run SAFE rounds and priced Series A financings that rating is wrong and a large share of founder-intent query volume is missing from the audit; if you don't, tell us where you want that traffic to land instead. (2) Patent Strategy & Filing Support came in at Moderate — is that a referral or work you do? The distinction changes the query treatment entirely: if you file, patent queries belong in the capability set; if you refer out to a registered patent attorney, they belong in a referral-intent cluster and we should be measuring whether assistants send that buyer to you first. (3) Are the ratings accurate against named competitors, not in the abstract? Multi-State & Cross-Border Coverage is rated Weak specifically against Outside GC and UpCounsel, who staff nationally — but if you have reciprocal or pro hac arrangements that make cross-border work routine, that's a Moderate and it changes how we handle expansion queries. Entity Formation & Corporate Governance also stays at Moderate while Corporate Governance remains one of your five published service lines: undersell, or correctly competent-rather-than-differentiating?

Pain Points

What Sends Them Looking

16 pain points: 10 high, 6 medium severity. Buyer language here becomes the literal phrasing of problem-stage queries — this is how the audit asks the question the way your prospect would actually type it.

Hourly billing produces invoices unrelated to the estimate High High

"I asked for a contract review, budgeted two thousand dollars, and got a twenty thousand dollar invoice nobody warned me about"
Personas: Founder & CEO, Chief Operating Officer, Head of Finance

Enterprise negotiations stall in slow redlines High High

"Our biggest deal has been sitting in redlines for six weeks and it takes our lawyer four days just to send back comments"
Personas: VP of Sales, Founder & CEO

Template MSAs fall apart at the first enterprise buyer High High

"We've been selling on a template MSA we found online and the first real enterprise buyer tore it apart in the first review"
Personas: VP of Sales, Founder & CEO

Procurement blocks on the DPA and security review High High

"Every enterprise deal stalls on the DPA and the security questionnaire and nobody here can answer what they're asking for"
Personas: VP of Sales, CTO & Co-Founder

Running customer data through AI models outruns the privacy policy High High

"We started running customer data through an LLM and I have no idea whether our privacy policy still covers it or what we're supposed to tell customers about training"
Personas: CTO & Co-Founder, Founder & CEO, Head of Product (AI)

Nobody can say who owns the AI's output High High

"Our product generates output with an LLM and I genuinely don't know if we own it, if the customer owns it, or if the model vendor has a claim on any of it"
Personas: CTO & Co-Founder, Head of Product (AI), Founder & CEO

Model vendor terms accepted without review High High

"We clicked accept on the model provider's terms a year ago and now an enterprise customer is asking questions I can't answer without admitting nobody read them"
Personas: CTO & Co-Founder, Head of Product (AI)

Terms of service describe a product that no longer exists High High

"We shipped three AI features this year and our terms of service still describe the product we had in 2024"
Personas: Head of Product (AI), Founder & CEO, VP of Sales

Contractor-built product with no IP assignment High Medium

"Half the product was built by contractors on a one-page agreement and I'm not actually sure we own the code"
Personas: CTO & Co-Founder, Founder & CEO

Legal work arrives long before a GC can be justified High High

"Every contract ends up on my desk and I'm the COO, not a lawyer, but we're nowhere near being able to hire a real GC"
Personas: Chief Operating Officer, Founder & CEO, Head of Finance

Big firms deprioritize their smallest clients Medium High

"We're the smallest client at a big firm so we get a first-year associate and a two-week wait for anything"
Personas: Founder & CEO, Chief Operating Officer

DIY formation and unpapered founder splits surface in diligence Medium Medium

"We formed the company on LegalZoom and never papered the founder split, and now diligence is asking questions I can't answer"
Personas: Founder & CEO, CTO & Co-Founder

Hiring across state lines outruns single-state counsel Medium Medium

"We just hired in three new states and nobody can tell me whose non-compete rules actually apply to those people"
Personas: Chief Operating Officer, Head of Finance

Contracts and corporate records won't survive investor diligence Medium Medium

"We're sixty days from a term sheet and I already know our contracts and corporate records won't survive diligence"
Personas: Founder & CEO, Head of Finance

Legal review is the rate limiter on every non-standard deal Medium Medium

"My reps have to stop and ask a lawyer about every clause a customer pushes back on, and it's costing us weeks per deal"
Personas: VP of Sales, Chief Operating Officer

The rules for genuinely new technology are unsettled Medium High

"Every lawyer I ask about this says it's a gray area and bills me for saying it"
Personas: Founder & CEO, CTO & Co-Founder, Head of Product (AI)

→ Three things to correct here (1) Ten of sixteen are now rated High and none are rated Low — the four pain points you added all came in at High, which makes a flat distribution flatter still, and it means the audit would weight ten problem-stage clusters roughly equally. Which two or three actually make a founder pick up the phone that week, rather than nod and carry on? Of the four AI pains you added, is it the ownership question, the unreviewed vendor terms, or the terms of service that lag the product? (2) Does the buyer language sound like your clients? The four new items are recorded in the phrasing your feedback used, and they read as the sharpest language in the set — which makes the older inferred items the weak spot by comparison. "Half the product was built by contractors on a one-page agreement and I'm not actually sure we own the code" is our phrasing, not theirs; if your clients say it blunter, the query set should use their words. (3) What's still missing? Three that show up in AI and emerging-technology deals and aren't here: an enterprise customer's AI questionnaire or AI addendum arriving mid-deal (the AI analogue of the DPA blocker already in this set); open-source and model-license compliance (weight licenses with use restrictions sit alongside copyleft in diligence); a state AI statute or disclosure rule landing on a product already shipped (if regulatory change, rather than a customer, is what triggers the call).

Layer 1 Technical Findings

What We Found on the Site

Nine findings from a full crawl of charlottecorporatecounsel.com on August 10, 2026 — one critical, three high, three medium, two low. Eight are diagnostic; one requires manual verification your engineering and marketing teams can run directly.

Engineering: start here One finding sits upstream of every other item in this document. robots.txt issues an explicit Disallow: / against nine named AI agents — GPTBot, ClaudeBot, Google-Extended, CCBot, Applebot-Extended, Amazonbot, meta-externalagent, Bytespider and CloudflareBrowserRenderingCrawler — which are precisely the crawlers that build the corpora behind ChatGPT, Claude, Google AI Overviews and Perplexity. Nothing else on this list changes what an assistant can retrieve while that block stands. Two other items your engineering team can act on independently: the HTTP 200 catch-all, which serves a byte-identical copy of the homepage for every unrecognized path including /sitemap.xml (removing the SPA rewrite from _redirects and adding a 404.html fixes it), and the absent homepage structured data, where the article's existing Article schema is a working template for a LegalService block that would finally state Georgia in machine-readable form. Blocking AI crawlers is common — 75% of major news publishers had blocked at least one by mid-2025 (Screaming Frog, July 2025) — but publishers block to protect a content business they monetize directly, which is a different calculation than a law firm's marketing site.

🔴 robots.txt blocks every major AI training and indexing crawler

What we found: https://charlottecorporatecounsel.com/robots.txt issues an explicit Disallow: / against nine named agents: GPTBot (OpenAI), ClaudeBot (Anthropic), Google-Extended (Google AI), Bytespider (ByteDance/TikTok), CCBot (Common Crawl), Applebot-Extended (Apple), Amazonbot, meta-externalagent (Meta), and CloudflareBrowserRenderingCrawler. The User-agent: * group also carries a Content-Signal: search=yes,ai-train=no,use=reference directive. Live-browse and search agents are still permitted: ChatGPT-User, PerplexityBot, and Googlebot all fall through to the wildcard Allow: /. This is a deliberate, well-formed opt-out configuration, not a misconfiguration — but its effect is that the site is excluded from the corpora that AI assistants draw on when answering without a live fetch.

Why it matters: The blocked agents are precisely the crawlers that build the retrieval and training corpora behind ChatGPT, Claude, Google AI Overviews, and Perplexity's index. A GEO audit measures whether the firm surfaces when a buyer asks an assistant to recommend startup counsel; those answers are generated predominantly from indexed corpora, not from a live fetch of a domain the model has never heard of. With GPTBot, ClaudeBot, and Google-Extended blocked, the two pages of substantive content on this site — including the 5,300-word GDPR/CCPA article that is the firm's single strongest differentiator — cannot enter those corpora at all. This block is upstream of every other finding in this report: fixing sitemaps, schema, and headings changes nothing while the crawlers that would read them are turned away. Note also that CCBot's block removes the site from Common Crawl, which is a common seed for third-party AI indexes as well.

Business consequence: When a founder asks an assistant "who reviews the terms of service for an AI product," "what lawyer handles AI output ownership," or "flat-fee startup lawyer in Atlanta," every firm whose pages are in the index is eligible to be named and Charlotte Corporate Counsel structurally is not — the loss is not a ranking position, it's exclusion from the candidate set.

Recommended fix: Confirm with the client whether the AI opt-out is an intentional policy decision. If the goal is AI visibility, remove the Disallow: / blocks for GPTBot, ClaudeBot, Google-Extended, CCBot, and Applebot-Extended, and change Content-Signal to search=yes,ai-train=yes,use=reference. If the client wants to permit AI answer citation while still withholding model-training rights, the narrower configuration is to allow the retrieval agents (GPTBot, ClaudeBot, PerplexityBot, Applebot-Extended) and keep ai-train=no in the Content-Signal header, which expresses the training restriction without blocking retrieval. Either way this is a single-file edit deployed with the next Cloudflare Pages build.

Impact: critical Effort: < 1 day Owner: Engineering Affected: Entire site — all 4 URLs, including the homepage and the sole Insights article

→ The one question that changes the engagement Was the AI crawler block authored deliberately, or inherited? Both are plausible and they lead to opposite conclusions. Cloudflare — which hosts this site on Pages — changed its default in July 2025 to block AI crawlers for new sites, and it handles roughly 24% of all web traffic (Cloudflare, July 2025), so a well-formed nine-agent block appearing on a Cloudflare-hosted site is at least as likely to be a platform default as an authored policy. There is also a real argument for keeping it: OpenAI's crawl-to-referral ratio is roughly 1,700:1 and Anthropic's roughly 73,000:1 (Cloudflare, July 2025), meaning these crawlers take far more than they send back, which is exactly why many publishers opted out. If the block is deliberate policy, say so and we rescope — the audit becomes a measurement of what assistants say about you from third-party sources, and site-side GEO work is largely wasted effort. If it's an inherited default, the fix is one file and it should ship this week.

🟡 Every unrecognized URL returns HTTP 200 with a byte-identical copy of the homepage

What we found: The host serves the homepage for any path that does not resolve to a real file, with an HTTP 200 status rather than a 404. We verified this by MD5-comparing responses: /, /index.html, /services/, /insights/, /sitemap.xml, and a deliberately invented /nonexistent-page-xyz/ all returned the identical 69,680-byte document with checksum 362823fbf9636f4fa0b99558937ef9c8. There is no canonical tag on the homepage to collapse these variants, and no X-Robots-Tag header on the catch-all responses.

Why it matters: A crawler has no way to distinguish a real page from a fabricated one, because both answer 200 with identical content. Three concrete consequences follow. First, any mistyped, stale, or hallucinated inbound link — including URLs an AI assistant invents when guessing at a site's structure, such as /services/ or /about/ — silently resolves to a valid-looking page, so the error is never surfaced or corrected. Second, / and /index.html are duplicate URLs with no canonical, splitting whatever link equity the domain accrues. Third, and most damaging here, /sitemap.xml returns HTML rather than XML, which means a crawler requesting the sitemap receives a 200 response containing a web page — a failure mode that looks like a malformed sitemap rather than an absent one.

Business consequence: An assistant answering "what practice areas does Charlotte Corporate Counsel cover" will guess at /services/, get a 200 back, and treat a fabricated URL as a real one — so the published service lines have no citable address of their own, and nothing in the response chain ever flags the mistake.

Recommended fix: Configure the Cloudflare Pages deployment to return a genuine HTTP 404 with a dedicated error page for unmatched paths, rather than falling back to index.html. In Cloudflare Pages this means removing the SPA catch-all rewrite from _redirects (or scoping it to only the routes the app actually owns) and adding a 404.html at the project root, which Pages serves automatically with the correct status code. Separately, add <link rel="canonical" href="https://charlottecorporatecounsel.com/"> to the homepage so / and /index.html resolve to one address.

Impact: high Effort: < 1 day Owner: Engineering Affected: Site-wide URL handling — an unbounded number of non-existent paths plus the /index.html duplicate of the homepage

🟡 The homepage carries no structured data, while the one article does

What we found: We retrieved the raw HTML for all four URLs. The homepage contains zero application/ld+json blocks — no Organization, no LegalService, no Person, no FAQPage. It also has no Open Graph tags and no canonical link. The Insights article, by contrast, carries a complete and correctly formed Article schema with headline, description, datePublished (2026-07-01), dateModified (2026-07-21), author as a Person with jobTitle, publisher with logo, image, an about array of topics, and mainEntityOfPage — plus nine Open Graph tags and a canonical URL. The capability and the template pattern already exist in this codebase; they were simply never applied to the homepage.

Why it matters: The homepage is the only page on the site that states who the firm is, what it does, and — critically — that Charlotte Lynn Luu is licensed in Georgia. That information currently exists only as prose. Structured data is the mechanism by which a machine reads an entity's identity unambiguously, and this is the one site we have reviewed where that matters more than usual: a LegalService or Attorney schema with an areaServed of Georgia and a founder/employee Person node named Charlotte Lynn Luu is the single most direct available correction to the Charlotte-NC misidentification. Without it, a machine reading this site has to infer the jurisdiction from a footer sentence while the brand name pushes hard in the opposite direction.

Business consequence: For a query like "corporate counsel for a software company in Georgia," the firm has no machine-readable claim to Georgia at all, so the jurisdiction question gets answered by the brand name — which points at North Carolina and hands the query to firms that actually practise there.

Recommended fix: Add a JSON-LD block to the homepage using the same pattern already implemented on the article. Use @type: LegalService (or ProfessionalService) with name, url, description, areaServed: {"@type": "State", "name": "Georgia"}, knowsAbout covering the four practice areas, and a nested founder of @type: Person named Charlotte Lynn Luu with jobTitle, alumniOf (University of Georgia School of Law), and hasCredential for the Georgia bar admission. Add sameAs links to the firm's LinkedIn and State Bar of Georgia listing. Also add Open Graph tags and a canonical link to the homepage, matching the article's implementation.

Impact: high Effort: 1-3 days Owner: Engineering Affected: Homepage — the site's only commercial page and only description of the firm

🔵 No XML sitemap exists at any conventional location

What we found: Requests to /sitemap.xml and /sitemap_index.xml both returned the homepage HTML with HTTP 200 (see the catch-all finding above), not sitemap XML. robots.txt contains no Sitemap: directive. No sitemap exists anywhere we could locate.

Why it matters: The direct discovery cost is limited here, because the site has only two indexable URLs and both are reachable from the homepage — the article is linked from the Insights section. The real cost is signalling. A sitemap is where lastmod timestamps live, and lastmod is one of the few machine-readable freshness signals a crawler can act on before fetching a page. The site currently emits no freshness signal of any kind at the URL level: no sitemap lastmod, and no Last-Modified response header on any page (we confirmed this via HEAD requests). It is also the mechanism for telling Search Console what to crawl, which matters given the indexation question raised below.

Business consequence: As the Insights section grows past its single article, questions like "what do GDPR and CCPA require when customer data goes through an AI model" will be answered from pages whose recency no engine has a URL-level way to confirm — which for a legal topic that changes quarterly is the difference between authoritative and stale.

Recommended fix: Generate a sitemap.xml at build time containing the two indexable URLs (/ and /insights/analyzing-ai-under-gdpr-and-ccpa/) with accurate lastmod values drawn from the build or content-modification date. Exclude /intake/ and /questionnaire/, which are correctly noindexed. Add a Sitemap: https://charlottecorporatecounsel.com/sitemap.xml line to robots.txt. As the Insights section grows, the sitemap should be regenerated on each publish so lastmod stays accurate — inaccurate lastmod values are worse than none.

Impact: medium Effort: < 1 day Owner: Engineering Affected: Site-wide discovery and freshness signalling; currently 2 indexable URLs, growing with the Insights section

🔵 Line-break tags inside headings produce corrupted words in extracted text

What we found: Several homepage headings use <br/> for visual line breaks without surrounding whitespace, so the words on either side collide when the markup is stripped. The raw source <h2>Legal counsel,<br/>mapped to how you grow.</h2> extracts as "Legal counsel,mapped to how you grow." Likewise <h2>Trusted by founders<br/>and operators.</h2> extracts as "Trusted by foundersand operators.", the section eyebrow renders as "What yourstartup needs", and the H1 — built from two <span class="hero-line"> elements — extracts as "Less Friction.More Growth." We confirmed this by running the same text-extraction a crawler would perform against the served HTML.

Why it matters: Headings are the strongest structural signal on a page and are frequently used as passage labels when a retrieval system chunks a document. Every affected heading on this site produces at least one word that appears in no dictionary — "foundersand", "yourstartup", "counsel,mapped". A token that does not exist cannot match a query, so these headings contribute nothing to retrieval and mildly degrade the page's apparent text quality. This affects four of the six H2s and the only H1 on the site's only commercial page.

Business consequence: A founder-intent query phrased around "trusted by founders and operators" cannot match a heading that extracts as "Trusted by foundersand operators." — the strongest structural signal on the firm's only commercial page is spending itself on tokens no buyer will ever type.

Recommended fix: Add an explicit space before each <br/> inside heading elements, or replace the visual line breaks with CSS (display: block on the spans, or a max-width that wraps naturally). The rendered appearance is unchanged; only the extracted text differs. Apply the same fix to the <span class="hero-line"> construction in the H1.

Impact: medium Effort: < 1 day Owner: Engineering Affected: Homepage — H1 and 4 of 6 H2 headings, plus the services section eyebrow text

🔵 The only H1 on the primary page is a tagline with no topical or jurisdictional content

What we found: The homepage H1 reads "Less Friction. More Growth." It names no practice area, no service, no jurisdiction, and not the firm or attorney. The descriptive line that would make a strong H1 — "Corporate counsel for technology companies" — is present immediately above it but is marked up as a styled div, not a heading. The <title> element and meta description are both well-written and do carry this information; the heading structure does not.

Why it matters: The H1 is the heading a retrieval system most often treats as the document's label, and it is weighted heavily when deciding what a page is about. "Less Friction. More Growth." would apply equally to a fitness studio or a logistics vendor. Given that the firm's brand name actively pushes machines toward Charlotte, North Carolina, the site's most prominent heading is an opportunity to state "corporate counsel", "technology companies", and "Georgia" in the position where that assertion carries the most weight — and it currently states none of them.

Business consequence: A query like "startup corporate counsel Atlanta" is assembled from exactly the three concepts the page's most heavily weighted heading omits, so the firm's only commercial page competes for that answer with a label that says nothing about what it sells or where.

Recommended fix: Promote the existing descriptive line to the H1 and demote the tagline to a styled subheading or paragraph: <h1>Corporate counsel for technology companies</h1> followed by "Less Friction. More Growth." as a <p class="hero-tagline">. Consider extending the H1 to name the jurisdiction, e.g. "Georgia corporate counsel for technology companies". The visual hierarchy can be preserved entirely in CSS; this is a semantic change, not a design change.

Impact: medium Effort: < 1 day Owner: Engineering Affected: Homepage (https://charlottecorporatecounsel.com/)

🔵 No date signal of any kind on the homepage or in HTTP response headers

What we found: The homepage carries no visible published or updated date, no dateModified in structured data (it has no structured data at all), and the server returns no Last-Modified header — we confirmed this with HEAD requests against /, which returned only cache-control: public, max-age=0, must-revalidate from Cloudflare with no modification timestamp. Combined with the absent sitemap, there is no lastmod either. The article page is the sole exception: its Article schema carries datePublished 2026-07-01 and dateModified 2026-07-21, and the byline displays "July 2026".

Why it matters: A crawler cannot establish that the homepage is current. For a product or services page this is a soft signal rather than a defect — commercial pages routinely carry no date, and we have not scored the homepage down for freshness on that basis. It becomes material only in combination: the site has no sitemap lastmod, no Last-Modified header, and no on-page date, so there is no path by which a machine can determine that this firm is actively practising. For a solo practice whose credibility rests partly on being a going concern, that is worth closing.

Business consequence: A buyer checking whether a solo practice is still operating gets no machine-readable answer, which slightly deprioritizes the homepage in responses that weight recency — a smaller effect than the items above, but one that compounds with an unindexed domain.

Recommended fix: Emit a Last-Modified response header from the Cloudflare Pages build (or set it via a _headers rule keyed to the deploy timestamp). Once a sitemap exists, its lastmod values will supply the same signal. Do not add a visible "last updated" date to the homepage — on a marketing page that reads as staleness rather than currency; the header and sitemap are the right carriers.

Impact: low Effort: < 1 day Owner: Engineering Affected: Homepage; also /intake/ and /questionnaire/, though those are noindexed and unaffected in practice

🔵 An unrendered template placeholder is served in the questionnaire page markup

What we found: The served HTML for /questionnaire/ contains an <h2> whose literal text is ${section.title} — a JavaScript template literal that was shipped in the static markup rather than being interpolated at build time. It sits alongside the legitimate headings "Client & technology questionnaire" (H1), "Respondent information", and "Questionnaire received". The page is correctly served with <meta name="robots" content="noindex, nofollow, noarchive">, as is /intake/.

Why it matters: The visibility impact is essentially nil, because the page is noindexed and is a gated client form rather than marketing content. It is worth reporting for two narrower reasons: it is a template element the client-side script clones at runtime, so if the script fails the placeholder is what a visiting client sees; and it indicates the heading is generated dynamically, which is the pattern to avoid if this markup is ever reused for a public-facing page.

Business consequence: No search or answer-engine consequence — the page is noindexed — but a prospective client opening the intake questionnaire while the script is failing sees ${section.title} where a section heading belongs, at the exact moment they are deciding whether this practice is buttoned-up.

Recommended fix: Move the ${section.title} element inside a <template> element so it is not part of the rendered document, or hide the prototype node with hidden until it is cloned and populated. No indexation change is needed — the noindex directives on both form pages are correct as they stand.

Impact: low Effort: < 1 day Owner: Engineering Affected: https://charlottecorporatecounsel.com/questionnaire/ (noindexed client form)

Manual Verification Checklist

The following item could not be assessed through our analysis method (rendered markdown). We recommend your engineering team verify it manually before the validation call. It is worth prioritising: brand web mentions are the strongest known predictor of AI citation (r = 0.664), far ahead of backlinks (r = 0.218) and organic traffic (r = 0.274), per Seer Interactive's October 2025 study — which makes off-site entity signals a first-order concern for a firm whose name resolves to the wrong state.

No evidence the domain is present in any search index

What to check: A site:charlottecorporatecounsel.com search returned zero results from the domain. A search for the bare domain string also returned no pages from the site; results instead surfaced charlottecounsel.com (Law Office of Todd Gonyer, Charlotte NC), the ACC Charlotte chapter, and unrelated Charlotte, North Carolina corporate firms. We could not confirm from the outside whether this reflects genuine non-indexation, a very recently launched domain that has not yet been crawled, or simply the limits of the search tooling available to this analysis. Googlebot is permitted in robots.txt, so nothing is blocking conventional indexation; the absent sitemap and the lack of inbound links are the more likely explanations, and both are addressable.

Recommended action: Verify actual index coverage directly rather than inferring it from search results: register the property in Google Search Console and Bing Webmaster Tools and read the Index Coverage report. Submit the sitemap once it exists. Then establish the entity-disambiguating citations that both search engines and language models rely on — a Google Business Profile with the Georgia service area, a State Bar of Georgia member listing, and consistent name/jurisdiction data on the firm's LinkedIn and any legal directory profiles. These external references are what allow an assistant to resolve "Charlotte Corporate Counsel" to a Georgia attorney rather than a North Carolina city.

Impact: high Effort: 1-3 days Owner: Marketing

Site Analysis Summary

Total pages analyzed 4 of 4 discoverable URLs
Commercially relevant pages 2 (homepage + Insights article; /intake/ and /questionnaire/ are noindexed)
Heading hierarchy 0.63
Content depth 0.38
Schema coverage 0.25
Passage extractability 0.35
Freshness (weighted) 1.00 (content marketing: 1.00 · product/commercial: unable to assess · structural: unable to assess — 3 pages unscored)

Read the freshness score carefully The crawl covered all four URLs on the domain, so this is a complete sample rather than a partial one — but it is a very small one, and three of the four pages carry no detectable date at all. The 1.00 weighted freshness score rests entirely on the single Insights article, which is genuinely current (published 2026-07-01, modified 2026-07-21). The homepage, /intake/ and /questionnaire/ are unscored because there is no date to score, not because they are fresh. Treat this metric as "nothing stale was found" rather than as evidence of an actively maintained content programme.

Next Steps

What Happens From Here

Why now The timing argument for a firm this size isn't that AI search is coming — it's that position in the answer layer is being assigned right now, and legal services is one of the last categories to notice:

• Buyer discovery is shifting quarter over quarter: 94% of B2B buyers now use LLMs during the buying process (6sense, November 2025). The founders and operators who hire outside counsel are the same population.
• Early citations compound — the domains AI platforms learn to treat as reliable get pulled into more answers as retrieval patterns settle, and that advantage is self-reinforcing rather than rented month to month.
• Crawler volume is climbing fast: Akamai measured 1.6 billion daily AI bot requests across its CDN, up 78% over six months (Akamai, February 2026). What the engines index this quarter is what they answer with next — and on this domain, the answer is currently nothing.
• Legal counsel for AI and emerging technology is still early-innings in GEO — earlier than corporate counsel generally, because the category barely existed two years ago and almost no firm has built content for it. A solo practice cannot outspend Cooley or Morris, Manning & Martin on conventional search, but in the answer layer it is competing largely against inaction rather than against entrenched strategies — a window that narrows as the larger firms start optimising for the same answers.

Once the inputs above are validated, the audit measures citation visibility across the buyer queries this knowledge graph implies — and after this revision that set leans harder on AI: questions in the register of "who owns the output our LLM generates," "does our terms of service need to change now that we've shipped AI features," "what did we agree to in the model provider's terms," alongside "flat-fee startup lawyer vs. an hourly firm" and "do we actually own code our contractors wrote." You'll see exactly which of those queries return answers naming Westaway, Outside GC or a free template set but not Charlotte Corporate Counsel, which ones name a Charlotte, North Carolina firm instead of you, and where the gap between the two sits query by query. The Layer 1 items are worth shipping before that measurement runs — crawler access, a real 404, and Georgia stated in machine-readable form raise the baseline the audit reads, rather than becoming findings it discovers.

01

Validation Call

45–60 minutes. We walk this document top to bottom, resolve the twelve questions in the checklist, and lock the inputs the query set is built from.

02

Query Generation & Execution

We generate buyer queries from the validated personas, competitors, features and pain points, then run them across the selected AI platforms and record every answer and citation.

03

Full Audit Delivery

Visibility analysis, competitive positioning against the validated set, and a three-layer action plan prioritised by which gaps actually cost citations.

Start now Three technical items your engineering team can ship without waiting for the call: (1) remove the SPA catch-all rewrite from _redirects and add a 404.html at the Cloudflare Pages project root, so unmatched paths return a real 404 instead of a byte-identical copy of the homepage — and add <link rel="canonical"> to the homepage while you're in there, which collapses the /index.html duplicate; (2) add a LegalService JSON-LD block to the homepage with areaServed of Georgia and a nested founder Person node for Charlotte Lynn Luu, reusing the Article schema pattern already implemented on the Insights page, plus the Open Graph tags the homepage is missing; (3) generate sitemap.xml at build time with the two indexable URLs and accurate lastmod, add the Sitemap: directive to robots.txt, and emit a Last-Modified header from the Pages build. Separately, register the domain in Google Search Console and Bing Webmaster Tools now — that answers the open indexation question directly rather than by inference, and it takes a day. The robots.txt AI-crawler block is deliberately not on this list: it needs your policy decision first, and if crawlers stay blocked it supersedes everything else here. These don't depend on the rest of the audit and will improve your baseline visibility before we even measure it.

Before the Call

Your Pre-Call Checklist

Two jobs before we meet. The questions on the left require your judgment — no one knows your business better than you. The engineering tasks on the right don't require the call at all.

Questions for You
Was the robots.txt block against GPTBot, ClaudeBot and Google-Extended authored deliberately, or inherited from a Cloudflare default?
If deliberate: site-side GEO work is largely wasted and the engagement rescopes to measuring what assistants say about you from third-party sources.
Do you want Georgia and Atlanta buyers only, or should we also test and contest the Charlotte, North Carolina association your firm name creates?
If wrong: the entire query set is built around the wrong geography, and out-of-state traffic you can't serve on a Georgia license gets counted as a win.
Now that you lead with AI and emerging technology, are there AI-specialist practices a founder would shortlist that aren't on our list — and do you still lose clients to Morris, Manning & Martin, to a flat-fee solo like Andrew Bosin's SaaS Law Firm, or to Common Paper's free templates?
If wrong: roughly 30 to 40 head-to-head queries measure you against firms buyers aren't actually comparing you to, and the competitive half of the audit is spent on the wrong fight.
Is Venture Financing & Cap Table Work genuinely Absent, is Patent Strategy work you do or work you refer out, and are Multi-State Coverage (Weak, against Outside GC and UpCounsel) and Entity Formation (Moderate) right?
If wrong: a large share of founder-intent fundraising query volume is missing entirely, and patent queries land in the capability set when they belong in a referral cluster.
Which two or three of the ten high-severity pain points actually make a founder call you that week — and of the four AI pains you added, is it output ownership, unreviewed vendor terms, or terms of service that lag the product?
If wrong: ten problem-stage clusters get weighted equally when only two or three drive real inbound.
Who owns the model vendor decision at your clients — the CTO, the Head of Product (AI), or both?
If wrong: vendor-terms and output-ownership queries are written in one register when the buyer searches in another.
Does a Head of Product (AI) ever contact you directly, or does the AI-legal question always route through the founder or CTO first?
If wrong: the persona you asked us to add gets no query cluster of its own and folds back into the CTO's language.
Does a Head of Finance ever hold the budget veto on legal spend at your clients, or does that authority always sit with the founder?
If wrong: we delete the lowest-confidence persona in the graph and redistribute its cost-predictability queries rather than running them twice.
Does a VP of Sales actually bring you in when a deal stalls in redlines, or does the founder always make that call alone?
If wrong: we drop revenue-leader query language and reweight the audit toward founder and operator searches.
Does the COO sign the engagement, or scope the work and route the decision to the founder?
If wrong: their queries shift from "hire outside counsel" to "how do I handle this contract myself," which is a different half of the funnel.
Does the founder run the search themselves, or does someone else assemble the shortlist and hand it over?
If wrong: discovery-stage queries are pointed at the wrong role and the founder only ever sees validation-stage language.
Do a Head of Security / Compliance, an incoming first General Counsel, or a fractional CFO show up in your deals?
If wrong: a whole buying role goes untested, and the audit under-reports where you're invisible.
For Engineering — Start Now
Remove the SPA catch-all rewrite from _redirects and add a 404.html at the Cloudflare Pages project root
Stops every invented path — including /services/ and /sitemap.xml — from returning a 200 with a byte-identical copy of the homepage.
Add <link rel="canonical"> and Open Graph tags to the homepage
Collapses the /index.html duplicate into one address; the article page already has both, so the pattern exists in the codebase.
Add a LegalService JSON-LD block to the homepage with areaServed of Georgia and a founder Person node for Charlotte Lynn Luu
The only machine-readable correction available to the Charlotte-NC misidentification; reuse the Article schema pattern from the Insights page.
Generate sitemap.xml at build time with accurate lastmod, add the Sitemap: directive to robots.txt, and emit a Last-Modified header
The site currently emits no URL-level freshness signal of any kind; these three carry it.
Add an explicit space before each <br/> inside headings and promote "Corporate counsel for technology companies" to the H1
Fixes "foundersand", "yourstartup" and "counsel,mapped" in extracted text, and gives the page a label that names what it sells. Pure semantics — the rendered design does not change.
Register the domain in Google Search Console and Bing Webmaster Tools and read the Index Coverage report
Answers the open indexation question directly rather than by inference from zero site: results. Marketing-owned, one day of work.
Alignment

We're Aligned On

This isn't a contract — it's a shared understanding. The audit runs against what's below. If something changes between now and the call, we adjust. The goal is to make sure we're asking the right questions for the right buyers against the right competitors.
Already Confirmed
Competitive set — 5 primary (Westaway, Outside GC, SaaS Law Firm / Andrew S. Bosin, Morris Manning & Martin, UpCounsel) + 5 secondary (Cooley, Lawtrades, Priori Legal, Common Paper, LegalZoom), all outbound-sourced since the site publishes no comparison content
Company profile — category and five service lines rewritten to your correction, now leading with AI workflow protection, SaaS terms of service, and technology licensing
Persona set — 6 personas: 4 decision-makers, 1 evaluator, 1 influencer; 2 from you directly (Head of Product AI added, CTO role rewritten), 2 grounded in site testimonial titles, 2 still inferred from category patterns and flagged for correction
Feature taxonomy — 15 capabilities with strength ratings: 9 strong, 2 moderate, 3 weak, 1 absent. Three added by you (AI Workflow Legal Protection, Emerging Technology Counsel, Patent Strategy & Filing Support) and IP Ownership raised to Strong
Pain point set — 16 buyer frustrations with severity ratings: 10 high, 6 medium; four AI-specific pains added from your feedback
Layer 1 technical audit — 9 findings logged across all 4 URLs (1 critical, 3 high, 3 medium, 2 low), unchanged in this revision, engineering notified
Decided at the Call
The AI crawler opt-out — deliberate policy or inherited Cloudflare default? This determines whether the engagement measures site-side visibility at all, so nothing downstream is settled until it is
Entity resolution — Georgia and Atlanta only, or a dedicated cluster to measure and contest the Charlotte, North Carolina association. Your feedback repositioned the category but did not touch geography, so this stays open
Whether the competitive set survives the repositioning — every name on it was assembled against outside corporate counsel generally, and only SaaS Law Firm (Andrew S. Bosin) markets AI contract work. Missing AI-specialist practices move the head-to-head half of the audit
Feature overweighting — top 3 of the 9 strong capabilities. We won't pick for you, but the data has a clearer opinion than it did in Revision 1: AI Workflow Legal Protection and SaaS Terms of Service & Commercial Contract Drafting each carry four high-severity pain points, ahead of every other Strong rating. The third place is yours to break
Pain point prioritization — top 3 of the 10 high-severity pains. By severity × persona breadth the data points at AI output ownership and terms of service lagging AI features (3 personas each, both new from your feedback), alongside runaway legal bills and no in-house legal function
Venture Financing & Cap Table Work — confirm Absent, or reinstate it and add the founder-intent fundraising queries it carries. Patent Strategy also needs a line: work you do, or work you refer out?
Competitor tier adjustments — SaaS Law Firm (Andrew S. Bosin) as primary, Lawtrades and Priori Legal as secondary; all three are medium confidence on tier
Persona corrections — Head of Finance (low confidence, may not exist at seed-stage clients) and VP of Sales (inferred, may never initiate); plus whether the CTO or the new Head of Product (AI) owns the model vendor decision
Client
Date