Skip to content
Helix GTM tools
Claude plugin · 6 skills

Will AI search engines and AI agents cite and shortlist your B2B pages?

The Optise and Helix AEO and GEO Toolkit is a free Claude plugin with six skills, built with Optise on its FITq and RACE frameworks. It builds the buyer prompts to track, audits pages for AI citation and AI agent shortlisting, writes answer blocks and EU trust pages, and sets up weekly tracking.

What does each skill do, and who is it for?

SkillWhat it doesWho it is for
Prompt Pack Builder
optise-helix-prompt-pack-builder
Builds 25 buyer prompts across six categories (shortlist, pricing, implementation, EU privacy, integrations, role-based), ranked by how likely each is to decide a deal.B2B marketing teams selling into Europe who want to know what buyers ask AI assistants.
FITq Audit
optise-helix-fitq-audit
Fetches a web page and scores it on Optise FITq (Findability, Intent match, Trust, Quoteability) for AI search citation, with fixes ranked by impact.Marketers and SEO leads who want pages cited by ChatGPT, Perplexity, Gemini and Claude.
RACE Audit
optise-helix-race-audit
Scores a page on Optise RACE (Requirements, Actions, Constraints, Evidence): how well an AI agent can evaluate and shortlist it.Teams whose buyers use AI agents to build shortlists.
BLUF Writer
optise-helix-bluf-writer
Writes a 40 to 60 word Bottom Line Up Front answer block in three lengths, using only the proof points you give.Page owners who want AI engines to quote a clean answer.
EU Trust Centre
optise-helix-eu-trust-centre
Drafts an EU Trust Centre page that answers the eight EU buyer questions (GDPR, storage, residency, DPA, subprocessors, retention, AI providers, security), with placeholders for anything you did not give.B2B software companies selling to EU buyers.
AEO Tracker
optise-helix-aeo-tracker
Sets up weekly AI citation tracking (Citation Rate, Prominence, Competitor Delta) across ChatGPT, Perplexity, Gemini and Claude.Teams measuring whether AI engines cite them.

Who is it not ideal for?

How do I install it?

Claude Code

/plugin marketplace add shashwatgtm/optise-helix-aeo-skills
/plugin install optise-helix-aeo-toolkit@optise-helix-aeo-skills

Or from a terminal: claude plugin marketplace add shashwatgtm/optise-helix-aeo-skills then claude plugin install optise-helix-aeo-toolkit@optise-helix-aeo-skills.

Cowork

  1. Open Customize in the sidebar, then Plugins.
  2. Select Add marketplace and enter shashwatgtm/optise-helix-aeo-skills.
  3. Find the plugin in the list and select Install. Its skills apply when relevant, or type / to run one.

What does it produce? Real outputs from a test run

On 25 September 2026 each skill was run once on the prompt shown, in a fresh Claude Code session with the plugin installed from GitHub. The outputs below are shown as produced, with these edits only: dashes are written out in words to match this site's style, paths to files saved on the test computer are replaced, where an output quotes this site's old byline, the author's title is updated to his current one (Co-Founder and Fractional CMO), one link a web search found to a private person's LinkedIn profile is removed (the text stays), and a placeholder attendee name that the search matched to a real person is shown as "Dana Example". Company and product names are placeholders.

Prompt Pack Builder: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-prompt-pack-builder):

Build a prompt pack for ExampleCo. We sell expense management software to finance leaders at 200 to 2,000 person companies in Germany, Austria and Switzerland. Our top 3 competitors are Competitor A, Competitor B and Competitor C.

Built for: Marketing / Growth Lead. Your message didn't say what your role is, so I used this default. Reply if that's wrong.
Inputs used: Category: expense management software · ICP: CFOs, Heads of Finance and Finance Controllers at companies with 200 to 2,000 employees · Competitors: Competitor A, B and C · Markets: Germany, Austria, Switzerland

Before you read the table
- The names are placeholders. ExampleCo and Competitors A, B and C aren't real names, so I couldn't check your site, the competitors or any ownership links between you. Before any comparison page goes live, run searches like "[competitor] acquired by" (Plugin Rule 1).
- The page addresses are guesses. I couldn't check your site, so none of the target pages are marked as existing or to be built. Check each one against your sitemap.
- The 5/5 scores are my judgement. "Decides" is a 1 to 5 score for how directly a good answer to a prompt wins or loses a deal. Your sales team hasn't confirmed that compliance actually knocks vendors out of your deals. If it doesn't, drop prompts 1 to 6 to 4/5.
- Prompts are English only. German-language prompts aren't supported in this version. Terms buyers type as-is (GoBD, DATEV, AVV, nFADP) are kept.

The 25-prompt pack

#PromptCategoryDecidesTarget pageMarket
1is ExampleCo GDPR compliant for German companiesEU Privacy5/5/trustDE
2where does ExampleCo store receipt and expense data, EU or USEU Privacy5/5/trust/data-residencyDACH
3can I get a DPA (AVV) from ExampleCoEU Privacy5/5/trust/dpaDACH
4who are ExampleCo's subprocessors and where are they locatedEU Privacy5/5/trust/subprocessorsDACH
5is ExampleCo GoBD compliant for replacing paper receiptsCompliance5/5/compliance/gobdDE
6ExampleCo ISO 27001 SOC 2EU Privacy5/5/trust/securityDACH
7Competitor A vs ExampleCoShortlist5/5/compare/competitor-aDACH
8Competitor B vs ExampleCoShortlist5/5/compare/competitor-bDACH
9Competitor C vs ExampleCoShortlist4/5/compare/competitor-cDACH
10Competitor A alternatives for companies in Germany, Austria and SwitzerlandShortlist4/5/alternatives/competitor-aDACH
11does ExampleCo integrate with DATEVIntegration4/5/integrations/datevDE
12does ExampleCo integrate with SAP S/4HANAIntegration4/5/integrations/sapDACH
13ExampleCo pricing for a 500-employee companyPricing4/5/pricingDACH
14how long does it take to implement ExampleCo for 1,000 employeesImplementation4/5/implementationDACH
15does ExampleCo support German, Austrian and Swiss per diem rates and VAT reclaimImplementation4/5/features/dach-travel-expensesDACH
16does ExampleCo use third-party AI providers to read receipts, and what data do they receiveEU Privacy4/5/trust/aiDACH
17how long does ExampleCo retain receipt data, and can we delete it on requestEU Privacy4/5/trust/data-retentionDACH
18best expense management software for CFOs at mid-sized German companiesRole-based4/5/solutions/cfoDE
19is ExampleCo compliant with the Swiss nFADPEU Privacy3/5/trust/switzerlandCH
20Competitor B alternatives for Mittelstand finance teamsShortlist3/5/alternatives/competitor-bDE
21does ExampleCo export to Abacus or BMDIntegration3/5/integrations/abacus-bmdCH + AT
22is ExampleCo ready for Germany's B2B e-invoicing mandateCompliance3/5/compliance/e-invoicingDE
23best expense management software for Swiss companiesShortlist3/5/switzerlandCH
24is ExampleCo's AI receipt processing EU AI Act compliantEU Privacy3/5/trust/aiDACH
25best expense management software for HR teamsRole-based2/5/solutions/hrDACH

Score spread: 8 prompts at 5/5 · 10 at 4/5 · 6 at 3/5 · 1 at 2/5 · 0 at 1/5. This is within the method's target range.

Why each 5/5 is a dealbreaker:

  • Prompts 1 to 4 and 6: these are the standard EU questions about privacy, data location and security certification. German buyers tend to rule out a vendor quietly on these.
  • Prompt 5: a finance leader in Germany can't go paperless without GoBD-compliant receipt archiving. GoBD is Germany's rulebook for digital bookkeeping records.
  • Prompts 7 to 8: head-to-head searches naming a competitor. If Competitor A or B has a comparison page and you don't, the AI answer tells their story.

Where my scores are guesses (please confirm):

  • Competitor C is set to 4/5 and A and B to 5/5. This assumes C comes up least often in your deals. Swap the scores if that's wrong.
  • Prompt 13 (pricing) is 4/5 because pricing is assumed to be public. If your pricing isn't on your site, it moves to 5/5 and near the top of the build order.
  • Prompt 15 (per diem and VAT) assumes ExampleCo covers travel expenses. If it doesn't, drop the prompt.
  • Prompt 22 (e-invoicing) only matters if ExampleCo also processes supplier invoices. If it does, move it to 4/5.
  • Prompt 21 (Abacus / BMD) assumes Austria and Switzerland are a smaller share of revenue than Germany. If not, move it to 4/5.

Top 10 to ship (ordered by build priority, not score)

  1. /trust (Trust Centre hub): covers prompts 1 and 6, and links out to answers for 2, 3, 4, 16, 17, 19 and 24. This is the most valuable page in the pack. → Hand off to optise-helix-eu-trust-centre.
  2. /compliance/gobd: covers prompt 5. This question is specific to Germany, and the buyers asking it are exactly your finance leaders.
  3. /compare/competitor-a: covers prompt 7, a dealbreaker head-to-head.
  4. /compare/competitor-b: covers prompt 8.
  5. /trust/data-residency: covers prompt 2. It should be its own page so a German buyer can check it in 10 seconds.
  6. /trust/dpa: covers prompt 3. Offer the DPA as a self-serve download.
  7. /trust/subprocessors: covers prompt 4. List each subprocessor with its country and your policy for notifying customers of changes.
  8. /integrations/datev: covers prompt 11. DATEV is the standard accounting software used by German tax advisers.
  9. /pricing: covers prompt 13. Move this to #2 if your pricing isn't public.
  10. /implementation: covers prompts 14 and 15. Implementation answers shorten the sales cycle.

What this pack is missing

  • Corporate card licensing. If ExampleCo issues corporate cards, add a prompt like "is ExampleCo's corporate card BaFin regulated" (BaFin is Germany's financial regulator). Card licensing is a common due-diligence question for finance buyers. I left it out because you didn't mention cards.
  • Austrian-specific prompts and other systems. No prompt in the pack is only about Austria. Microsoft Dynamics 365 Business Central and HR system sync (e.g. Personio) aren't covered either. Add them if they come up in your deals.

Suggested next step

Run optise-helix-eu-trust-centre to draft /trust. That one build answers 9 of the 25 prompts. Then build the GoBD page and the two head-to-head comparison pages, once you've run the ownership checks above.


Verification Log

Generated: 2026-09-25
Skill: optise-helix-prompt-pack-builder (toolkit 1.4.0, operating principles v1.3)
Session hygiene: Confirmed fresh (first request in session)

Web searches run
  1. "GoBD digital receipts replacement scanning…". Found supporting sources for GoBD as the German rulebook for digital receipt archiving, and for replacement scanning (scanning originals, then discarding the paper) being allowed with documented processes. All sources are vendor blogs. [Tier 4, directional only, not authoritative]. Some are also expense-management vendors: [bias note: vendor content].
  2. "Germany B2B e-invoicing mandate timeline…". Confirmed by the European Commission (Tier 1): all businesses must be able to receive e-invoices from 2025. Sending becomes mandatory in 2027 for turnover over €800k and in 2028 for all companies.
  3. "Swiss revised Federal Act on Data Protection nFADP…". Confirmed by KMU.admin.ch (Tier 1): in force since 1 September 2023.
  4. "Abacus Swiss ERP BMD Austria DATEV…". DATEV (Wikipedia) (Tier 1) confirms DATEV is the market leader in German tax-advisory software. Abacus (Tier 1, the vendor describing itself) calls itself the Swiss SME market leader. That BMD plays the same role in Austria rests only on Chift [Tier 4, directional only, not authoritative].
Web fetches run
  • None. ExampleCo has no real domain, so there was nothing to fetch.
How claims are tagged
  • VERIFIED (3): the German e-invoicing timeline, the nFADP start date, and DATEV's position in Germany.
  • INFERRED (6):
  • the scores for Competitor C, pricing, per diem, e-invoicing and Abacus/BMD (based on the rubric and assumed deal patterns)
  • BMD as Austria's main accounting system
  • USER-CONFIRMED (awaiting your input, 6):
  • whether any of the target pages already exist
  • whether pricing is public
  • whether ExampleCo issues corporate cards
  • whether ExampleCo handles supplier invoices
  • which competitor you meet most often
  • whether compliance really knocks vendors out of your deals
Verification gaps
  • Brand and competitor checks: couldn't run, because the names are placeholders.
  • GoBD replacement-scanning details: supported only by Tier 4 sources, so check them before publishing /compliance/gobd.
  • Page addresses: all are [ASSUMED SLUG]. Check them against your sitemap.

⚠ Disclaimer

This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


FITq Audit: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-fitq-audit):

Run a FITq audit on https://craft-gtm.gtmhelix.com/ for the buyer prompt 'free MCP server for go-to-market planning in Claude'.

Built for: Marketing / Growth Lead (the default; your message didn't name a role)
URL audited: https://craft-gtm.gtmhelix.com/
Target prompt: "free MCP server for go-to-market planning in Claude"
Audit timestamp: 2026-09-24T20:22:38Z (from fetch_page.py)
Session hygiene: Fresh session, since this was the first task in it.

FITq™ Score: 77/100 (Grade B)

SignalScoreWhat's driving it
Findability25/25HTTP 200, all content is in the raw HTML (5,144 characters of body text, no JS gating), time to first byte 905 ms, page weight 20 KB, self-referencing canonical, index, follow. robots.txt explicitly allows GPTBot, OAI-SearchBot, ClaudeBot, Claude-SearchBot and PerplexityBot, and blocks only /api/ and /mcp.
Intent Match20/25The H1 is a question that contains "Claude" and "go-to-market", but it leaves out "free" and "MCP server" (8/10). The 54-word lead gives a direct answer, but it never says "MCP server" and never says how to connect it to Claude. "MCP" appears only in the small label above the H1 (7/10). The page sticks to one topic (5/5).
Trust13/25There is no visible last-updated date. dateModified: 2026-09-25 exists only in the JSON-LD (0/8), so domain rule 4 caps Trust at 15. The author is named in the text but not linked to a bio (4/5). Most credibility claims have no source, and one may be wrong (2/5). Organization and Person schema are present (4/4). Person schema includes awards and profile links (3/3).
Quoteability19/255 structured lists (8/8). FAQPage schema that matches the visible Q&A (6/6). All paragraphs are short (5/5). None of the 6 H2s is a question (0/4). The lead opens with "Yes.", so it can't be quoted on its own (0/2).

Total: 25 + 20 + 13 + 19 = 77, which is Grade B.

Top 5 fixes (ranked by impact)

Fix 1: Make the H1 and lead match the buyer prompt [+5 Intent Match, +2 Quoteability] [ship this week]

This combines common fixes 3 and 4. The lead also appears word for word as the answer to "What is CRAFT GTM?" in both the visible FAQ and the FAQPage JSON-LD. There it reads "What is CRAFT GTM?" / "Yes. CRAFT GTM is…", which doesn't make sense. Fix all three places together.

Before:

<h1>Can Claude turn your go-to-market details into a plan you can use this week?</h1>
<p class="hx-lead">Yes. CRAFT GTM is a free set of eight planning tools by Shashwat Ghosh of Helix GTM Consulting. Give it your metrics, launch date, customers or competitors, and it returns a product-market fit scorecard, a launch plan, interview guides, retention, partner or crisis playbooks, battle cards, or a CRAFT review of any GTM document.</p>

After (58-word lead, with no "Yes." so it can be quoted on its own):

<h1>Is there a free MCP server for go-to-market planning in Claude?</h1>
<p class="hx-lead">CRAFT GTM is a free MCP server that gives Claude eight go-to-market planning tools, built by Shashwat Ghosh of Helix GTM Consulting. Add https://craft-gtm.gtmhelix.com/mcp as a custom connector with no sign-in. Give it your metrics, launch date, customers or competitors, and it returns a product-market fit scorecard, launch plan, interview guides, playbooks, battle cards or a CRAFT review.</p>

Every fact in this copy comes from your own page, the Connect page or the GitHub repo: free, MCP server, 8 tools, the connector URL, and no sign-in.

Also update the FAQ answer to "What is CRAFT GTM?", both the visible <details> text and the JSON-LD acceptedAnswer.text. Remove the "Yes." at the start so it matches the new lead.

Rule 4 note on FAQPage: since August 2023, Google has shown FAQ rich results only for well-known government and health sites, so this page won't get them. Keep FAQPage for AI parsers. SoftwareApplication + Offer (price 0) is the schema that fits this page, and it's already there.

Fix 2: Show the last-updated date on the page [+8 Trust] [ship this week]

This is common fix 1. Put it directly below the lead and take the value from the same field that sets dateModified:

<p class="hx-updated">By <a href="https://gtmexpert.com/" rel="author">Shashwat Ghosh</a>, Co-Founder and Fractional CMO, Helix GTM Consulting · <time datetime="2026-09-25">Last updated: September 25, 2026</time></p>

Check one thing: dateModified equals the audit date, which suggests the build stamps it automatically [INFERRED · basis: value matches today's date]. If so, change the build so the date moves only when the content changes, not on every deploy.

Fix 3: Turn the H2s into questions [+4 Quoteability] [ship this week]
Current H2Proposed
The 8 toolsWhat are the 8 CRAFT GTM tools?
Who it is forWho is CRAFT GTM for?
How to use itHow do I use CRAFT GTM in Claude or my browser?
What it is built onWhat is CRAFT GTM built on, and who made it?
Fix 4: Source the credibility claims and correct one [+3 Trust] [ship this week]

This is common fix 7.

  • "more than 50 CRAFT templates on the Notion Marketplace" may be inaccurate. The Notion listing I found is one template called "CRAFT: 50 AI Context Engineering for Business Template", and the creator profile shows "1 template" [VERIFIED · notion.com/templates/ai-context-engineering-craft-framework]. A suggested rewrite: "he has published CRAFT: 50 AI Context Engineering for Business on the Notion Marketplace." [USER-CONFIRMED · awaiting input: do you have other CRAFT listings that make "50+ templates" accurate?]
  • "24+ years in B2B": link it to https://gtmexpert.com/, which states the same figure [VERIFIED · gtmexpert.com].
  • "10+ years of fractional experience": gtmexpert.com doesn't state this. [User to add: a source link for this claim, or remove it]
  • Version mismatch: the page schema says softwareVersion: 2.1.0, but the GitHub README shows 2.0.0 [INFERRED · basis: README read by fetch summary]. [User to confirm: the current release number]
Fix 5: Link the author name to a bio [+1 Trust] [ship this week]

This is common fix 6. It's covered by the byline in Fix 2's snippet: "Shashwat Ghosh" becomes a rel="author" link to gtmexpert.com, matching Person.url in your schema. Ship it with Fix 2.

Rubric points these five fixes cover: Intent +5, Trust +12, Quoteability +6. These are points on the page-structure rubric only. They don't predict whether AI engines will actually cite the page (see Rule 7).

What's already strong (don't break these)

  • Server-rendered, lightweight HTML: 20 KB, no JS gating, canonical present.
  • robots.txt that names AI crawlers: it allows the search bots (including OAI-SearchBot and Claude-SearchBot) and correctly keeps the /mcp endpoint out of crawling.
  • SoftwareApplication schema: it includes Offer with price 0, isAccessibleForFree, featureList and sameAs links to GitHub and npm. This is exactly the structured data that supports a "free" claim.
  • Honest FAQ answer: "Does it use AI to write the answers? No…". This clear statement of what the tool doesn't do is a trust signal, and it will help with the RACE audit.
  • Title tag: it already contains "Free … MCP Server".

Suggested next step

Ship Fixes 1 and 2 together; both are small copy changes. If you want other lead options, optise-helix-bluf-writer can draft them. Then run optise-helix-race-audit on this URL to check whether agents can evaluate the page. Add this prompt to optise-helix-aeo-tracker to measure actual citations. optise-helix-eu-trust-centre isn't recommended because you didn't mention EU buyers.

Verification Log

Generated: 2026-09-25 · Skill: optise-helix-fitq-audit v1.4.0 · Session hygiene: Confirmed fresh

Web searches

  1. "Shashwat Ghosh CRAFT templates Notion Marketplace": found the Notion listing (Tier 1).

Web fetches

  1. fetch_page.py https://craft-gtm.gtmhelix.com/: 200 OK, full structural JSON.
  2. Raw HTML of the same URL, saved to the scratchpad: confirmed H1, lead, H2s, FAQ, schema and that no visible date appears.
  3. https://craft-gtm.gtmhelix.com/robots.txt: 200 OK, AI bots allowed, /api/ and /mcp disallowed.
  4. https://github.com/shashwatgtm/craft-gtm-mcp: 200 OK, confirmed MIT licence, 8 tools, stdio and Streamable HTTP transports, npm package name.
  5. https://craft-gtm.gtmhelix.com/connect/: 200 OK, confirmed the connector steps and no sign-in.
  6. https://gtmexpert.com/: 200 OK, states 24+ years in B2B; doesn't mention Notion templates.
  7. https://www.notion.com/templates/ai-context-engineering-craft-framework: 200 OK, one template listing whose title says "50".

Claims tagged

  • VERIFIED (6): the product is free, it's an MCP server, it has 8 tools, the connector URL, connection needs no sign-in, 24+ years in B2B.
  • INFERRED (2): dateModified is stamped at build time; the page and GitHub version numbers don't match.
  • USER-CONFIRMED (3): the "50+ templates" wording, a source for "10+ years fractional", the current release number.

Verification gaps: no source found for "10+ years of fractional experience". No competitors were named, so no ownership checks were needed.


⚠ Disclaimer

This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


Sources: CRAFT GTM · Connect page · GitHub repo · GTMExpert · Notion Marketplace listing

RACE Audit: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-race-audit):

Run a RACE audit on https://craft-gtm.gtmhelix.com/ for an AI agent that is shortlisting free GTM planning tools a B2B marketing team can connect to Claude.

RACE™ audit: CRAFT GTM (craft-gtm.gtmhelix.com)

Written for: Marketing / Growth Lead (the default, since you didn't name a role)
Agent task tested: "Shortlist free GTM planning tools a B2B marketing team can connect to Claude"
URL audited: https://craft-gtm.gtmhelix.com/ (HTTP 200, 20.2 KB, content is in the HTML without JavaScript)
Audit timestamp: 2026-09-24T20:25:57Z
Session hygiene: Fresh session; this was the first task.

RACE™ Score: 54/100, Grade D

SignalScoreWhat's driving it
Requirements14/25"Free, no account, no sign-in" is clear. But what you need is spread across prose and the Q&A. There is no "What you need" list. The page doesn't say which inputs each tool needs, how long setup takes, or which Claude plan limits apply. The SoftwareApplication schema has operatingSystem but no softwareRequirements.
Actions16/25There are two numbered 3-step lists (browser and AI assistant), and "the result appears on the page" works as a done-state. Nothing says how long each step takes. The 2 to 5 minute setup time is only on /connect/.
Constraints12/25"Who it is for" names three roles but excludes nobody. The honest limits exist but are scattered: no AI model and no lookups (on the homepage Q&A), 30 requests/minute and placeholders in output (on /faq/ only). There's no "not ideal for" section and no alternatives.
Evidence12/25Strong open-source proof: MIT-licensed GitHub repo and an npm package. The creator's credentials are named. There are no users, sample outputs, case studies or reviews. One claim doesn't match what Notion shows (see Fix 3).

How the page does on this specific task: it answers the three shortlist filters well. "Free" is [VERIFIED · JSON-LD Offer price 0 + page Q&A]. "Connect to Claude" includes exact steps. The MCP endpoint is live and returns all 8 tools [VERIFIED · POST /mcp tools/list → 200]. An agent will likely find it. What drags the score down is that an agent can't easily tell a buyer when the tool is the wrong choice.

Top 5 fixes (ranked by impact)

Fix 1: Add a "Who it is not for" section [Constraints +10 to +13] [about 30 min]

The facts are already verified; they just aren't on the page in one place.

Before (the "Who it is for" section ends, then the page goes straight to "How to use it"):

<h2>Who it is for</h2>
  … Founders and first marketers / Product marketers / GTM and customer leads …
<h2>How to use it</h2>

After:

<h2>Who it is for</h2>
  … (unchanged) …

<h2>Who CRAFT GTM is not for</h2>
<p>CRAFT GTM turns details you already have into structured GTM plans using fixed rules. It is not the right fit if:</p>
<ul>
  <li><strong>You need competitor or market research done for you.</strong> The tools do not call an AI model or look anything up, so Competitive Intel builds a battle card only from what you give it. For live research, use [User to add: recommended research tool or Helix connector].</li>
  <li><strong>You need plans saved, shared or versioned across a team.</strong> Nothing you type is stored, so there is no history or shared workspace. Copy results into [User to add: recommended doc tool].</li>
  <li><strong>You are on Claude's Free plan and already use a custom connector.</strong> Free plans allow one custom connector. Use the browser version instead, or [User to add: recommendation].</li>
  <li><strong>You want results written into your CRM or other systems.</strong> All eight tools are read-only. [User to add: alternative or Helix connector].</li>
  <li><strong>You plan to call the API at high volume.</strong> The hosted API allows 30 requests per minute. [User to confirm: does the local npx package remove this limit? If yes, point here.]</li>
</ul>
<p>Not sure it fits? Press <em>Fill in a tested example</em> on any tool to see a full result before entering your own data.</p>

Where each line comes from:

  • No AI model, nothing stored: [VERIFIED · homepage Q&A]
  • Free plan allows one custom connector: [VERIFIED · support.claude.com custom connectors article]
  • Read-only: [VERIFIED · MCP tools/list readOnlyHint:true + /connect/]
  • 30 requests/minute: [VERIFIED · /faq/]

Customize this: Fill every [User to add] before publishing. The +3 "linked alternatives" points depend on that. I didn't name any outside competitors because none were given. Your own Helix connectors (ICP Intelligence, Revenue Enablement, etc.) are natural links if they really cover those gaps. [USER-CONFIRMED · awaiting input]

Fix 2: Add a "What you need" list above the tools [Requirements +6 to +8] [about 20 min]

A 4 to 5 bullet list:

  • A browser, or any MCP client that supports Streamable HTTP. [VERIFIED · JSON-LD operatingSystem]
  • For Claude, any plan including Free (Free allows one custom connector). [VERIFIED · support.claude.com]
  • 2 to 5 minutes of setup per assistant. [VERIFIED · /connect/]
  • Your own numbers. For example, PMF Scorecard requires product, target market and current metrics. [VERIFIED · MCP inputSchema]
  • Who it suits, by role (already on the page; move it into the list).

Also add "softwareRequirements" to the SoftwareApplication JSON-LD.

Fix 3: Correct the Notion claim and put proof in the hero [Evidence +4 to +6] [about 30 min]
  • Mismatch: The page says Shashwat "has published more than 50 CRAFT templates on the Notion Marketplace." The Notion listing is one template called "CRAFT: 50 AI Context Engineering for Business Template," and the creator profile appears to show "1 template."
  • Why it matters: An agent that checks third-party sources sees a claim that doesn't match, and that lowers trust in the page.
  • Suggested wording: "a CRAFT template with 50 context-engineering prompts on the Notion Marketplace," with a link. [USER-CONFIRMED · awaiting input: confirm the correct count]
  • Hero proof: Link the GitHub repo there, and show one real sample output (for example a PMF scorecard excerpt from the tested example).
Fix 4: Add time and a done-state to each step [Actions +4] [about 15 min]
  • Put "(2 to 5 min)" on the assistant setup step.
  • Say what a finished result looks like, for example "a scorecard with a score per metric."
  • Schema note under Rule 4: HowTo is not eligible for Google rich results for software workflows. If you want step markup for AI agents to read, use Article with step properties instead.
Fix 5: Fix the first Q&A answer [Evidence / quotability, about 5 min]

"What is CRAFT GTM?" currently starts with "Yes." It reuses the hero answer to the H1 question, both on the page and in the FAQPage JSON-LD. An agent pulling that Q&A gets a definition that opens with "Yes."

  • Rewrite it to begin "CRAFT GTM is a free set of eight…"
  • The FAQPage markup is fine for AI agents to read, but it has not been eligible for Google FAQ rich results since August 2023 (Rule 4).

Rubric arithmetic, not a forecast: Fixes 1 and 2 alone would add about 16 to 21 points, which takes the page from D to roughly B (70 to 75). How agents actually behave has to be measured, not assumed.

What's already strong (keep these)

  • The H1 is the buyer's question, and the next line answers it directly.
  • The MCP URL and exact Claude connection steps are on the page. The endpoint is live, with no sign-in and read-only tool hints.
  • Detailed JSON-LD: SoftwareApplication with price: 0, isAccessibleForFree, featureList, downloadUrl, author and publisher, plus a current dateModified.
  • A clear, plain-language answer on data handling ("nothing is stored or logged").
  • Open source under MIT, with a local install option through npx. Agents can check this.

Suggested next step

Ship Fixes 1 and 2 this week, then re-run this audit. To see whether agents shortlist the page more often, set up optise-helix-aeo-tracker with prompts like "free GTM planning MCP servers for Claude."

Verification Log

Generated: 2026-09-25 · Skill: optise-helix-race-audit (toolkit 1.4.0) · Session hygiene: Confirmed fresh

Web fetches

  1. fetch_page.py on the homepage → 200. Headings, schema counts and list counts captured.
  2. Homepage (WebFetch) → full visible text.
  3. Homepage raw HTML (Python) → complete JSON-LD extracted.
  4. POST /mcp tools/list → 200. 8 tools, readOnlyHint:true, PMF required inputs confirmed.
  5. /connect/ → 200. Per-assistant steps and the 2 to 5 minute setup time.
  6. /faq/ → 200. 30 requests/minute limit and the placeholder behaviour.
  7. github.com/shashwatgtm/craft-gtm-mcp → exists, MIT, 0 stars.
  8. The Notion template page → a single template; the creator profile appears to show "1 template."

Web searches

  1. Claude custom connectors on the Free plan → support.claude.com (Tier 1): available on Free, limited to 1 custom connector.
  2. Shashwat Ghosh CRAFT Notion → notion.com listing (Tier 1).

Claims

  • Verified (9): price 0, no account, no AI model or lookups, nothing stored, read-only, 30 requests/minute, 2 to 5 minute setup, Free plan limited to 1 custom connector, PMF required inputs.
  • Inferred (0).
  • Need your input (4): alternatives for each "not for" line, whether the npx package has a rate limit, the Notion template count, which sample output to show.

Gaps

  • The "1 template" reading of the Notion creator profile comes from a summarised fetch. Check the profile yourself.
  • The "owner approval needed on Team/Enterprise" note on /connect/ wasn't checked against Anthropic docs, so I left it out of the template.

Sources


⚠ Disclaimer

This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


BLUF Writer: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-bluf-writer):

Write a BLUF for the buyer prompt 'is ExampleCo GDPR compliant'. Proof points: GDPR compliant; ISO 27001 certified; EU data residency in Frankfurt; a signed data processing agreement is available on request.

Built for: Marketing / Growth Lead (default)
Buyer prompt: is ExampleCo GDPR compliant
Pattern: Pattern 6, Compliance Anchor. Any prompt about GDPR always uses this pattern.

3 variants

40-word variant (recommended)

Yes, ExampleCo is GDPR compliant. ExampleCo holds ISO 27001 certification and provides EU data residency, with data hosted in Frankfurt. A signed data processing agreement (DPA) is available on request, so buyers can review ExampleCo's data processing terms in writing.
[40 words]

50-word variant

Yes, ExampleCo is compliant with the EU General Data Protection Regulation (GDPR). ExampleCo is certified to ISO 27001, the international standard for information security management, and provides EU data residency in Frankfurt. A signed data processing agreement (DPA) is available on request, so legal teams can review ExampleCo's processing terms.
[50 words]

60-word variant

Yes, ExampleCo is compliant with the EU General Data Protection Regulation (GDPR). ExampleCo is certified to ISO 27001, the international standard for information security management systems, and provides EU data residency, with data hosted in Frankfurt. A signed data processing agreement (DPA) is available on request, so procurement, legal and security teams can review ExampleCo's data processing terms in writing.
[60 words]

Recommended pick

Use the 40-word variant. It states all four proof points and adds nothing else. There's only one number to work with (27001), so the longer variants have to fill space by restating facts. Pick the 50-word version instead if you want "GDPR" spelled out in full, which helps a buyer who searches for the long name.

Rule compliance check (all 3 variants)

  • ✓ 40, 50 and 60 words, confirmed with a word-count tool
  • ✓ Answer first: each one opens with "Yes"
  • ✓ Buyer-native wording: "ExampleCo", not "our platform"
  • ✓ No banned superlatives
  • ✓ Each one makes sense when quoted on its own
  • ✓ One pattern only (Pattern 6)
  • ✓ Has a number: ISO 27001
  • ✓ Only facts you stated. The one addition is a general definition of ISO 27001, which says nothing new about ExampleCo.

Assumptions and gaps

  • Assumption: "EU data residency in Frankfurt" is standard for customers, not an opt-in. If it's optional or only on some plans, change "provides" to "offers optional".
  • Assumption: "data hosted in Frankfurt" (in the 40- and 60-word variants) says the same thing as your residency point. If only some data stays in Frankfurt, use the 50-word wording.
  • Gap: Pattern 6 works best when it ends with a place to verify the claims. Add a link if you have one: [User to add: DPA request URL or email]. I didn't make one up.
  • Not included because you didn't state them: SOC 2, subprocessor list, change-notice period, hosting provider. Send any of these and I'll add them.

Verification Log

Generated: 2026-09-25
Skill: optise-helix-bluf-writer (toolkit 1.4.0)
Session hygiene: Fresh session; this is the first skill run.

Web searches and fetches: None. The skill's own worked examples use ExampleCo as a made-up company, so there is no real brand site to check.

Claims tagged

  • USER-CONFIRMED (4): GDPR compliant, ISO 27001 certified, EU data residency in Frankfurt, signed DPA available on request. These are all your first-party facts. Check them against your actual certificate and DPA before publishing.
  • INFERRED (1): ISO 27001 described as "the international standard for information security management (systems)". This is general knowledge about the standard, not a claim about ExampleCo.
  • VERIFIED (0)

Verification gaps: You have to confirm the ISO 27001 certificate's scope and that it's still valid, and whether Frankfurt residency covers all customer data.


⚠ Disclaimer

This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


The Microsoft 365, Netlify and Zap integration connectors need to be authorized in your claude.ai connector settings before they can be used. This task didn't need them.

EU Trust Centre: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-eu-trust-centre):

Generate a Trust Centre page for ExampleCo, an HR software platform serving EU customers. Data is hosted in Frankfurt, Germany. We are ISO 27001 certified. We use AWS as our cloud provider.

I've drafted the ExampleCo Trust Centre page, but it isn't ready to publish yet. It still has [User to add: …] placeholders wherever you haven't given me the facts. Two of the four required inputs are among them: GDPR status and how customers get a DPA.

The draft is in [a file on the test computer].

What's filled in from what you told me:

  • Hosting: an opening summary stating that customer data is hosted on AWS in Frankfurt. I've named the region as eu-central-1, which AWS's own docs list as its Frankfurt region. That's my guess from "Frankfurt" plus "AWS", so please confirm it's the one you use.
  • Security standards: a table showing ISO 27001 as certified. Certificates on the older 2013 edition expired on 31 October 2025, so a current certificate should be on the 2022 edition. The page asks you to add the edition, the certifying body and what the certificate covers.
  • Subprocessors: AWS is the first row. The other rows are placeholders.
  • AI rules for HR software: under the EU AI Act, AI used for hiring, performance evaluation or worker management counts as "high-risk". A 2026 amendment (Regulation (EU) 2026/1744) moved those obligations from August 2026 to 2 December 2027. The page doesn't say ExampleCo complies. Legal needs to classify your features first.
  • Retention: a data retention table with suggested row categories for an HR platform, such as employee records, sick-leave data, logs and backups.
  • Also included:
  • All eight standard EU buyer questions, in the order procurement reviewers usually read them.
  • A "Need a DPA?" call-to-action.
  • Structured page markup (JSON-LD) that Google accepts for this kind of page, plus an FAQ version with a note that Google no longer shows FAQ results for compliance pages.
  • A checklist for your data protection officer to run before publishing.
  • A log of the sources I checked.

Three answers would fill most of the gaps:

  1. GDPR and DPA: Is ExampleCo GDPR-compliant, and does it act as a processor, a controller, or both? Is a DPA available to all customers, and do they download it or request it by email?
  2. Where data goes outside Frankfurt: Where are backups and failover copies stored? Does any data leave the EU, for example through support staff, monitoring, email tools or AI features?
  3. Subprocessors and AI: Which other subprocessors do you use? Does the product use any third-party AI providers, and does it make any AI-assisted HR decisions such as hiring or performance evaluation?

I couldn't check anything against ExampleCo's website because I don't have a domain for it, so every link on the page is a placeholder.

Sources:


File the skill saved (exampleco-trust-centre.md), shown as written:

Built for: Security / Privacy / Legal (the default for this skill; signals: ISO 27001, EU data hosting, EU customers)
Company: ExampleCo, an HR software platform serving EU customers
Inputs used (stated by user): HR software platform · EU customer base · data hosted in Frankfurt, Germany · AWS as cloud provider · ISO 27001 certified
Inputs missing (placeholders inserted): GDPR status and controller/processor role · DPA availability and route · backup and failover region · residency exceptions (support, analytics, AI) · full subprocessor list and change-notice policy · retention periods · third-party AI providers · DPO contact · ISO 27001 scope and certification body · all page URLs

Required inputs still missing: 2 of 4. You haven't confirmed GDPR compliance status or DPA availability yet. The draft uses placeholders for both. The Q1 and Q4 answers can't be published until you fill them in.

Trust & Compliance

ExampleCo is [User to add: GDPR status, e.g. "GDPR-compliant"] and certified to ISO/IEC 27001 [User to add: certification body and scope]. Customer data is hosted on Amazon Web Services in Frankfurt, Germany (AWS Europe (Frankfurt), eu-central-1). Our Data Processing Agreement is [User to add: how to get it], and our subprocessors are listed at [User to add: link].

(BLUF: 49 words once placeholders are filled; stays inside the 40-60 word target.)


Is ExampleCo GDPR compliant?

[User to add: Yes / In progress]. ExampleCo [User to add: GDPR status exactly as confirmed] and acts as [User to add: Data Processor, Data Controller, or both. For HR platforms this is usually a processor for customer employee data and a controller for its own account and billing data] under EU Regulation 2016/679. [USER-CONFIRMED · awaiting input]

[User to add: confirm which obligations to describe. Candidates: Article 28 (processor), Article 30 (records of processing activities), Article 32 (security of processing), Article 33 (notifying the supervisory authority of a personal data breach)] [VERIFIED · gdpr-info.eu: article titles]. [User to add: confirm whether ExampleCo processes special category data under Article 9, such as health or sick-leave records or trade union membership, which HR systems often hold]. [User to add: DPO name and contact].

Where to verify: [User to add: link to DPA page] · [User to add: link to privacy policy]

Is customer data stored in the EU?

Yes. Customer data is hosted on Amazon Web Services in Frankfurt, Germany. [USER-CONFIRMED · user stated "Frankfurt, Germany" and "AWS"]

ExampleCo's production environment runs in the AWS Europe (Frankfurt) region, eu-central-1 [VERIFIED · docs.aws.amazon.com: eu-central-1 = Europe (Frankfurt), Germany] [INFERRED · basis: eu-central-1 is the only AWS region in Frankfurt. User to confirm this is the region in use]. Backups are stored in [User to add: backup and disaster-recovery region. Don't write "EU" without naming the region]. [User to add: whether customer data ever leaves Frankfurt, e.g. for support access from outside the EU, monitoring, analytics, email delivery or AI features, and under what safeguards].

Where to verify: [User to add: link to data residency page] · [User to add: link to subprocessor list with regions]

Does ExampleCo offer EU data residency?

[User to add: e.g. "Yes. All customers are hosted in Frankfurt by default" OR "EU residency is available on [plan]"]. [USER-CONFIRMED · awaiting input]

EU data residency means customer content, processing and backups all stay inside the EU. ExampleCo delivers this through AWS in Frankfurt, Germany [USER-CONFIRMED]. [User to add: whether residency applies to all plans or only some, and whether customers need to request it]. [User to add: exceptions, if any, for support, analytics, or AI processing, and whether customer consent is required].

Where to verify: [User to add: link to data residency page] · [User to add: link to plan comparison, if residency varies by plan]

What security standards does ExampleCo meet?

ExampleCo is certified to ISO/IEC 27001. [USER-CONFIRMED · user stated "ISO 27001 certified"]

StandardStatusVerification
ISO/IEC 27001Certified [USER-CONFIRMED]. [User to add: edition. It should be ISO/IEC 27001:2022, because 2013-edition certificates expired on 31 October 2025] [VERIFIED · SGS / LRQA transition notices][User to add: certification body, certificate number, scope (e.g. "all production systems and supporting processes"), expiry date, and whether the certificate is shared publicly or under NDA]
GDPR[User to add: status][User to add: evidence, e.g. DPA, records of processing]
SOC 2[User to add: Certified / In progress / Not pursuing][User to add: evidence]
EU AI Act[User to add: whether any ExampleCo feature is an AI system, and its risk category]See the AI section below
NIS2[User to add: applicable / not applicable],

[User to add: penetration testing frequency and whether a third party runs it]. [User to add: how quickly ExampleCo notifies customers of a personal data breach. Note that GDPR Article 33 sets a 72-hour deadline for notifying the supervisory authority, not customers] [VERIFIED · gdpr-info.eu Art. 33]. [User to add: security contact, e.g. security@…].

Where to verify: [User to add: link to security page] · [User to add: link to request the ISO 27001 certificate or security pack]

Can I get a DPA for ExampleCo?

[User to add: Yes / Enterprise only / No]. [User to add: who can sign it and when, e.g. before contract signature]. [USER-CONFIRMED · awaiting input]

[Keep each sentence only if confirmed:] The ExampleCo DPA [User to add: whether it includes the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for any transfers outside the EU/EEA]. It is [User to add: pre-signed by ExampleCo / signed by both parties]. It covers [User to add: processing instructions, technical and organisational measures, subprocessor list, data subject rights assistance]. Negotiated DPAs are available for [User to add: tier or threshold, or "not offered"].

How to get it: [User to add: DPA request email OR self-serve download link]

Who are ExampleCo's subprocessors?

ExampleCo uses [User to add: number] subprocessors, listed below. [User to add: how, and how far in advance, customers are notified of new subprocessors, or "no notice commitment"].

SubprocessorServiceData processedLocation of processingTransfer mechanism
Amazon Web Services [USER-CONFIRMED]Cloud hosting and infrastructure[User to add: e.g. all customer content]Frankfurt, Germany (eu-central-1) [INFERRED · see Q2][User to add: contracting AWS entity and any transfer safeguards]
[User to add][User to add: e.g. email delivery][User to add][User to add][User to add]
[User to add][User to add: e.g. customer support tooling][User to add][User to add][User to add]
[User to add][User to add: e.g. payments / billing][User to add][User to add][User to add]
[User to add][User to add: e.g. error monitoring / analytics][User to add][User to add][User to add]

Where to verify: [User to add: link to live subprocessor page] · [User to add: link to change-notification sign-up]

What data does ExampleCo collect and how long is it retained?

ExampleCo collects [User to add: data categories] and keeps it for [User to add: retention rule, e.g. contract term plus X days].

Data typePurposeRetentionDeletion
Employee HR records (customer content)[User to add][User to add][User to add]
Special category data, if any (e.g. sick leave, health)[User to add][User to add][User to add]
Customer admin account information[User to add][User to add][User to add]
Usage telemetry / logs[User to add][User to add][User to add]
Support tickets[User to add][User to add][User to add]
Backups[User to add][User to add][User to add]

(Row labels are suggested categories for an HR platform [INFERRED · basis: typical HRIS data model]. Delete any that don't apply.)

Customers can export and delete their data through [User to add: self-service export/delete or request route].

Where to verify: [User to add: link to privacy policy] · [User to add: link to data deletion request flow]

Does ExampleCo use third-party AI providers?

[User to add: Yes / No]. [If yes: which providers, which features, what data is sent, whether customer content is excluded or anonymised, whether the provider keeps or trains on the data, the processing region, and how to opt out]. [USER-CONFIRMED · awaiting input]

EU AI Act note for an HR platform: AI systems used in employment and worker management count as high-risk under Annex III of the AI Act. This covers systems used for recruitment and candidate screening, promotion or termination decisions, task allocation, and performance monitoring and evaluation. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) moved the main obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027 [VERIFIED · Hunton, White & Case, K&L Gates client alerts, July 2026]. [User to add: whether any ExampleCo feature falls into these use cases, and whether ExampleCo is the provider, the deployer, or both. Don't publish an "AI Act compliant" claim until Legal confirms the classification] [Legal team to verify before publishing].

Where to verify: [User to add: link to AI features / data flow page] · [User to add: link to subprocessor list showing AI providers]


Need a DPA now?

[User to add: "Download our DPA: <link>" OR "Email <address> to request our DPA"]. [User to add: turnaround time, only if you commit to one.]


JSON-LD schema

Recommended (eligible for Google): Organization + hasCredential + WebPage. Rule 4: FAQPage rich results aren't shown for corporate compliance pages.

{
  "@context": "https://schema.org",
  "@type": "WebPage",
  "name": "Trust & Compliance | ExampleCo",
  "url": "[User to add: canonical Trust Centre URL]",
  "dateModified": "[User to add: publish date, YYYY-MM-DD]",
  "about": {
    "@type": "Organization",
    "name": "ExampleCo",
    "url": "[User to add: homepage URL]",
    "hasCredential": [
      {
        "@type": "EducationalOccupationalCredential",
        "name": "ISO/IEC 27001 [User to add: edition, e.g. 2022] certification",
        "credentialCategory": "Information security management system certification",
        "recognizedBy": {
          "@type": "Organization",
          "name": "[User to add: certification body]"
        }
      }
    ]
  }
}

Optional (other AI parsers): FAQPage. [Note: this schema is no longer eligible for Google rich results on corporate compliance pages (since August 2023). It's included because some AI answer engines read FAQ markup.] Each text repeats the one-sentence answer shown on the page. Replace every placeholder before publishing.

{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    { "@type": "Question", "name": "Is ExampleCo GDPR compliant?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: confirmed GDPR status and controller/processor role]" } },
    { "@type": "Question", "name": "Is customer data stored in the EU?",
      "acceptedAnswer": { "@type": "Answer", "text": "Yes. Customer data is hosted on Amazon Web Services in Frankfurt, Germany." } },
    { "@type": "Question", "name": "Does ExampleCo offer EU data residency?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: residency offering, e.g. Frankfurt by default for all customers]" } },
    { "@type": "Question", "name": "What security standards does ExampleCo meet?",
      "acceptedAnswer": { "@type": "Answer", "text": "ExampleCo is certified to ISO/IEC 27001." } },
    { "@type": "Question", "name": "Can I get a DPA for ExampleCo?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: DPA availability and how to get it]" } },
    { "@type": "Question", "name": "Who are ExampleCo's subprocessors?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: number of subprocessors and link to the list]" } },
    { "@type": "Question", "name": "What data does ExampleCo collect and how long is it retained?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: data categories and retention rule]" } },
    { "@type": "Question", "name": "Does ExampleCo use third-party AI providers?",
      "acceptedAnswer": { "@type": "Answer", "text": "[User to add: Yes/No, providers, and data flow]" } }
  ]
}

What your DPO should check before publishing

  • [ ] Production and backup/DR regions are both Frankfurt (or named explicitly), and no support, monitoring or AI tool moves data outside the EU without disclosure
  • [ ] The AWS region code is confirmed as eu-central-1
  • [ ] The ISO 27001 certificate is on the 2022 edition, is current, and its scope covers the HR platform (not just a corporate office)
  • [ ] The subprocessor list is complete, including email, support, billing, monitoring and any AI providers
  • [ ] The controller/processor role and any Article 9 special category processing are described accurately
  • [ ] The DPA link resolves and the SCC reference matches the signed version
  • [ ] The DPO contact is correct
  • [ ] Legal has confirmed the AI Act classification of any AI feature (Annex III employment use cases)
  • [ ] Every [User to add: …] placeholder and every inline verification tag has been removed

⚠️ Before publishing

This draft still contains [User to add: ...] placeholders, including GDPR status, DPA availability, subprocessors, retention and AI providers. Don't publish with placeholders visible. Fill each one with real facts from Engineering, Legal and Security, or hold the page until those facts are known. A Trust Centre with unfilled placeholders does more harm than having none: EU buyers will assume something is being hidden.

Suggested next step

Collect the missing facts, fill the placeholders, and remove the inline tags. After the page is live, run optise-helix-fitq-audit on the URL to check it is AI-citation ready, and optise-helix-prompt-pack-builder to find the EU-privacy prompts this page should answer.


Verification Log

Generated: 2026-09-25
Skill: optise-helix-eu-trust-centre (optise-helix-aeo-toolkit 1.4.0; operating principles v1.3)
Session hygiene: Confirmed fresh (first task in session)

Web searches executed
  1. "EU AI Act high-risk Annex III employment obligations application date digital omnibus delay 2026" → Gibson Dunn, CSA, regulation-ai.eu: Annex III stand-alone systems deferred to 2 Dec 2027
  2. "ISO/IEC 27001:2022 transition deadline 31 October 2025 ISO 27001:2013 certificates" → SGS, LRQA: 2013 certificates expired 31 Oct 2025
  3. "Digital Omnibus AI Regulation published Official Journal 2026 Annex III 2 December 2027 eur-lex" → Hunton, White & Case, K&L Gates, Lewis Silkin: Reg. (EU) 2026/1744 published in the OJ on 24 Jul 2026, in force 27 Jul 2026
Web fetches executed
  1. https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions.html → 200 OK; eu-central-1 = Europe (Frankfurt), Germany
  2. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ → 200 OK; 2 Dec 2027 date (article dated 27 May 2026, before adoption, so it was cross-checked with search 3)
  3. https://gdpr-info.eu/ → 200 OK; titles of Articles 28, 30, 32, 33 confirmed
Claims tagged in output
  • VERIFIED (5): eu-central-1 = Frankfurt (AWS docs); ISO 27001:2013 expiry on 31 Oct 2025 (SGS/LRQA); GDPR article mappings 28/30/32/33 (gdpr-info.eu); Art. 33's 72 hours applies to the supervisory authority (gdpr-info.eu); Annex III deadline of 2 Dec 2027 under Reg. (EU) 2026/1744 (Tier 3 law-firm alerts)
  • INFERRED (3): ExampleCo uses eu-central-1 specifically; the certificate is on the 2022 edition; the retention table row categories
  • USER-CONFIRMED (3 stated + ~25 awaiting): stated = Frankfurt hosting, AWS, ISO 27001 certified; awaiting = everything marked [User to add]
Verification gaps
  • Brand verification (Rule 9, step 1) not performed: no domain was provided for ExampleCo. Every URL is a placeholder and none was fetched (Rule 1).
  • The SCC decision reference (2021/914) comes from background knowledge and was not re-fetched this session. Legal to confirm it against the signed DPA.
  • The EU AI Act classification of ExampleCo's own features can't be determined without product details.

⚠ Disclaimer

This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


AEO Tracker: real output

Prompt used in the test run (Claude Code 2.1.281, fresh session, plugin installed from GitHub; skills Claude used: optise-helix-aeo-toolkit:optise-helix-aeo-tracker):

Set up weekly AEO tracking for ExampleCo, an expense management software company, across ChatGPT and Perplexity. Track these 5 buyer prompts: 'best expense management software for mid-market companies in Germany', 'expense management tools with DATEV integration', 'ExampleCo vs Competitor A', 'how to automate employee expense approvals', 'is ExampleCo GDPR compliant'.

I've set up the weekly tracker for ExampleCo on ChatGPT and Perplexity. The week-1 sheet is saved at [a file on the test computer]. It already has all 10 rows (5 prompts × 2 engines), so on Monday you only fill in the answers.

Built for: Marketing / Growth Lead (the default, since you didn't name a role)
Tracker ID: exampleco-2026-09-25 · First measurement: Monday 2026-09-28 · Cadence: weekly, every Monday
Session hygiene: fresh session, so no reset was needed.

Tracking template

CSV columns

ColColumnTypeWhat to enter
AweekdateThe Monday of that week
BengineenumChatGPT / Perplexity
CpromptstringThe prompt exactly as written. Never reword it.
DcategoryenumAlready filled in (see below)
EbrandedboolAlready filled in: TRUE if ExampleCo's name is in the prompt
FmentionedboolDoes the answer name ExampleCo?
Gcited_with_linkboolDoes the answer link to ExampleCo's website?
Hprominenceint 1 to 41 = first, 2 = top 3, 3 = after the top 3, 4 = only at the end or in a "see also" line. Leave blank if not mentioned.
Icompetitor_a_mentionedboolIs Competitor A named in the answer?
Jtarget_pagestring[User to add: the ExampleCo page that should win this prompt, or "TO BUILD"]
KnotesstringWhich websites the answer cites, and any wrong claims about ExampleCo

Category assignments:

#PromptCategoryBranded?
1best expense management software for mid-market companies in GermanyShortlistNo
2expense management tools with DATEV integrationIntegrationNo
3ExampleCo vs Competitor AShortlist (you vs a competitor)Yes
4how to automate employee expense approvalsImplementationNo
5is ExampleCo GDPR compliantEU PrivacyYes
  • Assumption: prompt 4 is a general how-to question and doesn't fit any of the 6 categories cleanly, so I put it under Implementation. Buyers who ask it are often still learning about the problem, so it may be less likely to decide a deal than the other four.
Example row (made up, only to show the format)
2026-09-28,Perplexity,"expense management tools with DATEV integration",Integration,FALSE,TRUE,TRUE,2,TRUE,[User to add],"#2 of 6; cited exampleco integrations page"

Week-1 instructions (Mon 2026-09-28)

  1. Use a separate browser profile, logged out wherever possible, so your own history doesn't affect the answers.
  2. Open ChatGPT and run all 5 prompts, each in a new chat. Then do the same in Perplexity.
  3. Type each prompt exactly as written. Fill in columns F, I and K for each row.
  4. For prompt 5, write down exactly what the engine says about ExampleCo and GDPR, and which source it cites. A wrong answer here can quietly get you dropped from a shortlist.
  5. Save each week's file as aeo-tracker-YYYY-MM-DD.csv, or append the rows to one master sheet.

It should take roughly 10 to 15 minutes a week. I got that by scaling down the time the method quotes for 100 rows.

Weekly checklist (every Monday)

  • [ ] Run the 10 measurements: 5 prompts on ChatGPT, then 5 on Perplexity
  • [ ] Do it at the same time of day and in the same logged-out state each week
  • [ ] Calculate the 3 KPIs (formulas below)
  • [ ] Note any prompt whose prominence changed or whose citing website changed
  • [ ] Report only the 3 KPIs to the team, not the raw rows

The 3 KPI formulas (Excel / Google Sheets, where wk = the week's date)

  • Citation Rate: =COUNTIFS(A:A,wk,F:F,TRUE)/COUNTIF(A:A,wk)
  • Prominence Score (lower is better; the target is below 2.0): =AVERAGEIFS(H:H,A:A,wk,F:F,TRUE)
  • Competitor Delta (you vs Competitor A): =COUNTIFS(A:A,wk,F:F,TRUE)-COUNTIFS(A:A,wk,I:I,TRUE)

Also report Citation Rate for unbranded prompts only (1, 2 and 4):
=COUNTIFS(A:A,wk,E:E,FALSE,F:F,TRUE)/COUNTIFS(A:A,wk,E:E,FALSE)

Prompts 3 and 5 contain ExampleCo's name, so the answer will almost always mention you. On those two, a "mention" doesn't tell you much. The real signal is whether the answer is accurate and which website it cites. That's why the notes column matters.

Grade bands (from Optise customer data)

The grade is based on Citation Rate:

  • A: above 40%
  • B: 20 to 40%
  • C: 10 to 20%
  • D: 5 to 10%
  • F: below 5%

I'm not predicting where ExampleCo will start. Week 1 is your baseline.

Where this setup departs from the standard method

  • 2 engines instead of 4: you asked for ChatGPT and Perplexity only. The standard method also covers Gemini and Claude, because engines often differ from each other. Adding them is one column of work each.
  • Longer wait before you can judge prompts: the method needs 16 measurements per prompt before calling it "working" or "dead." With 2 engines, you reach that at week 8 (2026-11-16), not week 4. You can still read the trend at week 4 (2026-10-19).
  • Small sample: with 10 rows a week, each row moves Citation Rate by 10 points. Read trends across weeks, not single-week swings.
  • One competitor: only Competitor A was named, so the delta compares against it alone. On prompt 3 both brands are always named, so its delta will usually be 0. Adding a second competitor would give you a more useful delta.
  • ExampleCo pages not linked yet: I don't know which ExampleCo pages should win each prompt, so target_page is marked [User to add] in the table.

Suggested next step

Run this for 4 weeks, then run this tracker in analysis mode with your sheet for a trend check. Dead prompts will be swapped for new ones in the same category. Prompts where Competitor A is winning will get a FITq page audit.

Verification Log

Generated: 2026-09-25 · Skill: optise-helix-aeo-tracker (toolkit 1.4.0) · Session hygiene: confirmed fresh

Web searches and fetches run: none.

  • "ExampleCo" and "Competitor A" are placeholder names. There is no real website to check, and fetching exampleco.com could pull in an unrelated company.
  • I made no factual claims about any product, price, integration or compliance status.
  • The DATEV and GDPR wording appears only inside prompts, not as claims.

How the claims in this setup are tagged:

  • Verified (0).
  • Inferred (3):
  • The 10 to 15 minute time estimate, scaled down from the method's 100-row figure
  • The week-8 date for judging prompts, derived from the 16-measurement rule
  • The prompt 4 category
  • Waiting on you (3):
  • The target page URLs
  • A second competitor (optional)
  • Whether to add Gemini and Claude

What I couldn't verify: anything about the real brand. If ExampleCo is a stand-in for a real company, tell me the domain and competitor. I'll check both and fill in the target pages.


⚠ Disclaimer: This Helix-Optise skill is AI based, directionally correct in 75% time but can make mistakes. Please double-check cited sources.


I can also publish this as a shareable tracker page for your team.


File the skill saved (aeo-tracker-2026-09-28.csv), shown as written:

week,engine,prompt,category,branded,mentioned,cited_with_link,prominence,competitor_a_mentioned,target_page,notes
2026-09-28,ChatGPT,"best expense management software for mid-market companies in Germany",Shortlist,FALSE,,,,,,
2026-09-28,ChatGPT,"expense management tools with DATEV integration",Integration,FALSE,,,,,,
2026-09-28,ChatGPT,"ExampleCo vs Competitor A",Shortlist,TRUE,,,,,,
2026-09-28,ChatGPT,"how to automate employee expense approvals",Implementation,FALSE,,,,,,
2026-09-28,ChatGPT,"is ExampleCo GDPR compliant",EU Privacy,TRUE,,,,,,
2026-09-28,Perplexity,"best expense management software for mid-market companies in Germany",Shortlist,FALSE,,,,,,
2026-09-28,Perplexity,"expense management tools with DATEV integration",Integration,FALSE,,,,,,
2026-09-28,Perplexity,"ExampleCo vs Competitor A",Shortlist,TRUE,,,,,,
2026-09-28,Perplexity,"how to automate employee expense approvals",Implementation,FALSE,,,,,,
2026-09-28,Perplexity,"is ExampleCo GDPR compliant",EU Privacy,TRUE,,,,,,

Licence, source and privacy

All connectors and plugins