Skip to main content
Hardening

Is Your Website Invisible to AI Search? A GEO Primer

John Sabo 6 min read

Is Your Website Invisible to AI Search? A GEO Primer

More people are asking an assistant for a recommendation instead of typing a query into a search box. The answer they get is written by a model, and the model picks which businesses to mention. Generative engine optimization, or GEO, is the work of making sure your business is one of them.

It is not a trick and it is not a rewrite of everything you have published. It is a small set of technical and writing changes that make your site easy for a machine to read, quote, and trust.

How this differs from regular search

Search gave you ten blue links. An assistant gives you a paragraph, usually with a few sources named underneath. That changes what matters.

Ranking is not the goal anymore. Being quotable is. A model needs a sentence it can lift, attribute, and be confident about. If your site only has a photo of a storefront and a contact form, there is nothing to lift.

Step one: let the crawlers in

Each AI product sends its own crawler to read pages. OpenAI has GPTBot and OAI-SearchBot. Anthropic has ClaudeBot and Claude-Web. Perplexity has PerplexityBot. Google has Google-Extended. There are others, including Amazonbot, Applebot-Extended, CCBot, FacebookBot, and Bytespider.

Many websites block all of them without knowing it, because the site copied a robots.txt file from somewhere that treated every unfamiliar crawler as a threat. The result is a site that is technically perfect and completely absent from AI answers.

I do the opposite on my own site. I allow the search-oriented crawlers in, and I say so explicitly in robots.txt so it is obvious and auditable. If you would rather stay out of AI answers, that is a legitimate choice. Just make it a choice and not an accident.

Step two: publish an llms.txt

An llms.txt file is a short map of your site, written in plain markdown, that sits at your domain root. It lists the pages that matter and gives each one a one-line description.

Think of it as a summary you hand to a busy assistant instead of making it walk every room in the house. Your services, your about page, your contact details, your best articles, each on one line with a link.

It takes an hour to write and it is one of the cheapest things you can do for AI visibility. Mine is at lonosecurity.com/llms.txt if you want to see the shape of it. I also keep a longer version, llms-full.txt, with the whole text of the site and my articles.

Step three: structured data

Structured data is a block of labels inside your page that states facts in a format a machine reads without guessing. The common format is JSON-LD, and you never see it when you look at the site.

A good set for a small business says: this is my business name, this is my address, this is my phone number, these are the services I offer, these are the questions I get asked and the answers. That last one is called FAQPage, and it is the format most likely to get quoted back verbatim.

I put structured data on every page of my site, including a person record for me, because the assistant should be able to connect the business to a human with a name.

Step four: write like a practitioner

Google uses a phrase for this that stuck: Experience, Expertise, Authoritativeness and Trustworthiness. Usually shortened to E-E-A-T. Models weigh the same signals when they decide whom to cite.

In practice it means three things:

  • Say who you are. A named person with a real background beats a logo and a slogan.
  • Say what you have done. A specific case beats an adjective. "I recovered a Mesa family farm's Facebook portfolio" is worth more than "trusted expert."
  • Answer one question per section. Write the answer first, in one plain sentence, then explain it. That first sentence is the one a model will quote.

None of that requires you to become a writer. It requires you to stop hiding behind marketing language.

A seven-item self-check

Run this on your own site. You can finish it in twenty minutes.

  1. Fetch your robots.txt. Are the AI crawlers allowed, deliberately?
  2. Do you have an llms.txt at your domain root?
  3. Does your home page contain one plain sentence describing what you do and who you do it for?
  4. Is your phone number and service area in structured data, not just in a footer image?
  5. Do you have three or more real questions answered in FAQ format somewhere on the site?
  6. Does your site display its content with JavaScript turned off? If it does not, some crawlers see an empty page.
  7. Does your site name a real person with real credentials?

Anything you answered no to is a gap. Number six surprises people most often, because the site looks fine in a browser.

Where this fits with security

I know why a security consultant is writing about this, and it is not a pivot. Both problems have the same root: a machine is trying to decide whether your site can be trusted, and your site is not giving it an answer.

The hardening service I offer covers both sides. Firewall setup and tuning, security headers, and TLS configuration on one side. Crawler access, llms.txt, structured data, and content fixes on the other. It ends with a monthly report showing how visible you are in AI answers, so you can see whether any of it worked.

Work with me

Every engagement starts with a free 30-minute consult and a written quote. If you would rather try the self-check first, do it and bring me what you found.

Book a free 30-minute consult at /book, or call 602.501.0772. I answer the phone.

John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere

JS

John Sabo

John Sabo — 30 years in cybersecurity, GoDaddy WAF architect

Work with me

Every engagement starts with a free 30-minute consult and ends with a written quote.

Book a free consult