Sec. 04 — Signals & plan
2,929 submitted. 720 forbidden.
The sitemap asks Google to crawl URLs that robots.txt tells it not to — wasted crawl budget and a mixed signal.
Evidence: sitemap.xml (2,929 URLs) vs robots.txt disallowed paths /partners/, /customers/, /blog-tags/, /blog-authors/, /blog-categories/ = 720
Still “API Security”
/about-us reads “API Security Company - About Us Salt Security API Security” — legacy positioning against the agentic message. A rewrite for 12 company pages.
DienDeal / DeinDeal
/customers spells the customer “DienDeal” once vs “DeinDeal” ten times — on a page linking 32 noindex, ~38-word stubs.
llms.txt
A 404 today, and robots.txt has no AI-crawler rules. llms.txt / llms-full.txt is the emerging convention and costs nothing.
The answer layer, shipped
Schema map
- JSON-LD embed per Webflow template (FAQPage, TechArticle, SoftwareApplication, Organization)
- Two live FAQPage builds as proof
- llms.txt / llms-full.txt
Clean signals
- Remove 720 disallowed URLs from the sitemap
- Decide the 32 noindex customer stubs
- Rewrite 12 “API Security” titles; fix the typo
Measure
- AEO dashboard: query set, engines, citation tracking
- Keak test plan (named in your posting)
- Search Console + Profound baseline
Method & scope — said plainly
Public data pulled Sep 19, 2026: the source of 60 sampled salt.security pages, llms.txt, robots.txt, and sitemap.xml cross-referenced against robots.txt disallowed paths. Snippets illustrate the markup I'd add, validated against Google's docs before shipping. My background is retail and B2B e-commerce, not SaaS or cybersecurity, and I haven't shipped in Webflow yet (Elementor, Divi and Shopify themes are the analog). What transfers is six years of owning sites end to end. If the schema audit is useful on its own, take it.