Skip to content
Flowpane

Product

Level 1 / Value

Treat every public file as a claim. Then check it.

Flowpane fetches the files that govern your site, scores each one, checks them against each other and against what crawlers and Google actually see, and keeps a record you can defend.

app.flowpane.com/w/northwind/sites/northwind.example

Northwind Outdoor

Verified

northwind.example · Checked 14 min ago

Sitemaps

Read by search engines · weight 35 of 100

Stale
  • Issue3 of 6 children in the root index return 404.
  • WarningEvery URL carries the same lastmod, so it tells crawlers nothing.
  • Inforobots.txt declares 2 sitemaps the root index never mentions.
Current file/sitemap_index.xml
1<sitemapindex xmlns="http://www.sitemaps.org/...">
2 <sitemap><loc>/sitemaps/pages.xml</loc></sitemap>
3 <sitemap><loc>/sitemaps/campaign-2019.xml</loc></sitemap>404
4 <sitemap><loc>/sitemaps/stores-old.xml</loc></sitemap>404
5 <sitemap><loc>/sitemaps/products.xml</loc></sitemap>
6</sitemapindex>

The loop

Six steps, one of which is yours.

Flowpane does the reading, scoring and remembering. Publishing stays with you, on your own host.

  1. 01

    Add

    One URL, a pasted list, or a CSV. Platform and audience are detected, and kept apart from what you declare.

  2. 02

    Verify

    A file, a DNS TXT record, or a meta tag. One value covers the whole workspace.

  3. 03

    Check

    Fetch, parse, assess, score, store. Every run is immutable.

  4. 04

    Review

    Findings with the exact line, ranked by severity: Issue, Warning, Recommendation, Information.

  5. 05

    Publishyou

    You publish the fix through your own host or CMS. Flowpane proposes, you decide.

  6. 06

    Monitor

    Checks repeat on your plan's schedule, from weekly to hourly. The next public check moves the score.

The score

One number, built from eight, weighted by what they cost you.

Each file gets its own score from 0 to 100. The site score weights them by what they cost you, and skips what does not apply.

Sitemaps 35robots.txt 15security.txt 12Cookies and consent 12ads.txt 8llms.txt 7ai.txt 6humans.txt 5

Only what applies to you

robots.txt, sitemaps and security.txt always count. ads.txt only counts if you sell advertising, so a site without ads is never marked down for it.

The last good result

The score uses each file's last good result, so a failed fetch does not wipe out good evidence.

Blocked is not missing

If a firewall challenges the crawler, the result is Blocked and the site is shown as unscorable. You never get a flattering partial score.

Bands

  • 80 to 100Good
  • 60 to 79Needs attention
  • 0 to 59Failing
How the score works

Cross-file coherence

Sixteen rules for files that contradict each other.

Coherence is reported beside the site score, so a set of individually valid files that disagree still shows up.

Read the method
  • robots.txt blocks URLs the sitemap asks search engines to index
  • The sitemap lists pages marked noindex
  • A sitemap exists but robots.txt never declares it
  • llms.txt links to URLs robots.txt blocks
  • robots.txt and ai.txt disagree about AI training
  • ai.txt and security.txt give different contacts
  • + ten more rules

Evidence layers

What you declared, what is reachable, what Google kept.

Three sources, kept apart on purpose. Flowpane never blends them into one number, because the gaps between them are the findings.

Layer 1

Public pull

What is on the wire?

Every artefact, fetched over public HTTPS from the canonical origin by a crawler that identifies and signs itself.

Layer 2

Deep Scan crawl

What is reachable?

A breadth-first crawl from the homepage that respects robots.txt and Crawl-delay, then compares every page with what the sitemap declares.

Layer 3

New

Search Console

What did Google accept?

Read-only. Submitted sitemaps, counts, and a bounded URL inspection, shown beside Flowpane's own observation with timestamps.

Sitemap truth map · northwind.example

Illustrative

Declared

sitemap files

4,812

Reachable

Deep Scan crawl

4,390

Accepted

Search Console

3,977

611

declared URLs that are broken or redirect

189

reachable pages you never declared

835

declared URLs Google did not keep

Evidence as ofpublic pull 14 min agocrawl 2 days agoSearch Console 6 h ago

A crawler that signs its name

Governance fetches carry a Flowpane user agent and an HTTP Message Signature, so your firewall can verify the request before it answers.

Request headers, abridgedRFC 9421 · Ed25519

GET /.well-known/security.txt HTTP/2

Host: northwind.example

User-Agent: Flowpane/1.0 (+https://crawler.flowpane.com)

Signature-Agent: "https://crawler.flowpane.com/.well-known/http-message-signatures-directory"

Signature-Input: sig1=("@authority" "signature-agent");alg="ed25519";tag="web-bot-auth"…

Signature: sig1=:k3Jd…Q9w==:

How Flowpane fetches

The workbench

Fix it without guessing, and without inventing anything.

Every failing or missing file opens in a workbench with the current file beside a proposed one.

security.txtWorkbench · northwind.example

Findings

IssueExpires is in the past.
AdviceAdd Canonical.
AdviceAdd Preferred-Languages.
1Contact: mailto:security@northwind.example
2-Expires: 2026-09-18T00:00:00Z
3+Expires: 2027-03-31T00:00:00Z
4Encryption: https://northwind.example/pgp.asc
5Policy: https://northwind.example/disclosure
6+Preferred-Languages: en
7+Canonical: https://northwind.example/.well-known/security.txt
  • Fix and Fix all

    Deterministic, safe patches for mechanical problems. No model involved.

  • AI Assist

    Drafts text for a missing or failing file. The draft must pass the same factual-safety and validation checks as anything you write, and a rejected draft does not use your allowance.

  • Safe starters

    Missing files start from a conservative template that never invents a contact, a policy, a publisher ID, or an AI stance.

  • Review, then publish

    Validate, then on Agency approve an exact saved revision. You publish it. A draft never changes a score.

AI readiness

Know exactly what you are telling AI systems.

robots.txt is assessed against a directory of named AI crawlers, from GPTBot to ClaudeBot to Google-Extended. Content-Signal directives are read, and ai.txt and llms.txt are checked against both. The result is a grade from A to F with the checks behind it.

AI crawler policy in practice
C

AI readiness

1 coherence conflict
penalty applied

Crawler coverage

robots.txt

  • GPTBotOpenAIAllowed
  • ClaudeBotAnthropicAllowed
  • Google-ExtendedGoogleBlocked
  • PerplexityBotPerplexityNo rule
  • CCBotCommon CrawlNo rule
  • Applebot-ExtendedAppleNo rule
Conflictai.txt says AI-Training: no while GPTBot is allowed.

Reports and portfolios

A record you can send, and a queue you can work.

Governance reports

A PDF with an executive summary, per-file state, cross-file coherence, recommendations, and a section on what the evidence can and cannot prove. From Starter.

Workspace analytics

Needs-attention ranking, file coverage and AI readiness across every site in a workspace, with CSV export from Pro.

Roles per workspace

Viewer, Editor, Reviewer, Publisher and Admin. Workspaces map to clients, brands or teams.

White-label

On Agency and Enterprise, reports carry your logo and can drop the Flowpane footer.

What Flowpane is not

Clear edges make it easier to trust.

Not an on-page SEO plugin

Plugins shape individual pages. Flowpane checks the site-level files around them. Use both.

Not an uptime monitor

It does not page you when the site is down. It tells you when the site's public claims are wrong.

Not a compliance certificate

Scores are product models. Reports state their evidence boundaries rather than promise legal outcomes.

Not a tool that edits your site

Flowpane reads your origin. You decide what gets published, and when.

See what your sites are claiming.

Add an origin and get a score, the gaps, and the evidence behind each one. Then Flowpane keeps checking, so the answer stays current.

Free during the beta. Flowpane only reads your origin.