AI Site Grade
heist-studios.com — AI Site Grade
Heist-studios.com blocks all AI crawlers with a Cloudflare JS challenge, leaving LLMs with a hallucinated design-consultancy identity instead of the actual tights e-commerce brand.
The site is completely inaccessible to AI crawlers, has zero external signals, and lacks schema, causing LLMs to fabricate a false brand narrative.
- Findings
- 9
- Evidence checks
- 38
- Completed
- 30 May 2026
Analysis
Cloudflare Wall, Zero External Presence, and a Cold-Knowledge Hallucination
The site at heist-studios.com is a Shopify-hosted tights and shapewear e-commerce brand called "Heist," yet the leading LLM model describes it as a UK-based design consultancy that prototyped the Oura Ring and Zettle card reader — a hallucination that the site's own inaccessibility cannot correct.
Crawler Access
Every single AI crawler tested — GPTBot, ClaudeBot, PerplexityBot, Google-Extended, OAI-SearchBot, Applebot-Extended, Bytespider, ChatGPT-User — receives a 403 status from Cloudflare's JS challenge wall. The homepage, robots.txt, llms.txt, and sitemap.xml all return the same "Verifying your connection..." shell with zero visible content. No robots.txt directives exist to inspect because the file itself is blocked. DNS records point to 23.227.38.65 (Shopify's CDN), confirming the platform, but the Cloudflare layer sits in front and blocks all non-JS-capable clients.
Cold-Knowledge Gap
The LLM's prior knowledge describes "Heist Studios" as a design consultancy founded in 2014 by ex-IDEO talent, with work on the Oura Ring and PayPal Zettle. The actual site — visible only via Wayback Machine snapshots — sells tights, shapewear, bodysuits, and underwear under the tagline "Revolutionary Foundationwear." The homepage from January 2024 shows product listings with prices in GBP, a "Buy 3, save 20%" promotion, and Klarna checkout. The March 2026 snapshot confirms the same e-commerce identity. The LLM's design-consultancy narrative is a complete fabrication with no basis in the site's actual content.
External Signals
The domain has zero discoverable external footprint. Searches for the brand name, the domain, and related product terms return no results across general web search, reviews, press mentions, or social media. No Trustpilot, no Reddit threads, no LinkedIn company page surfaced. The site's only accessible historical record exists in the Wayback Machine. This total absence of off-domain signals means AI models have no corrective data to override the hallucinated design-consultancy narrative.
Schema Posture
Neither the January 2024 nor the March 2026 Wayback snapshots contain any JSON-LD schema on the homepage. The site uses Shopify's default HTML structure with no Product, Organization, WebSite, or BreadcrumbList structured data. Heading structure is flat (multiple H2s, no nested hierarchy), and the site relies on JavaScript for product quick-buy modals — content that would be invisible to crawlers even if they passed the Cloudflare wall.
Findings
Cloudflare JS challenge blocks all AI crawlers High
Every tested AI crawler (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, OAI-SearchBot, Applebot-Extended, Bytespider, ChatGPT-User) receives a 403 status from Cloudflare's JS challenge wall. The homepage, robots.txt, llms.txt, and sitemap.xml are all blocked, returning only a 'Verifying your connection...' shell with no visible content.
What to change: Remove the Cloudflare JS challenge for known AI crawler user agents, or serve a static HTML version of the homepage and key pages to bots.
LLM hallucinates Heist Studios as a design consultancy High
The leading LLM model describes Heist Studios as a UK-based design consultancy that prototyped the Oura Ring and Zettle card reader, but the actual site sells tights and shapewear. This hallucination persists because the site is inaccessible to crawlers and has no external signals to correct the false narrative.
What to change: Make the site accessible to AI crawlers and publish accurate structured data to establish the correct brand identity.
Zero discoverable external footprint High
Searches for the brand name, domain, and product terms return no results across general web search, reviews, press mentions, or social media. No Trustpilot, Reddit threads, or LinkedIn company page surfaced. This total absence of off-domain signals means AI models have no corrective data to override the hallucinated narrative.
What to change: Build an external presence through press coverage, social media profiles, backlinks, and listings on review platforms.
No JSON-LD structured data on homepage High
Neither the January 2024 nor the March 2026 Wayback snapshots contain any JSON-LD schema on the homepage. The site uses Shopify's default HTML structure with no Product, Organization, WebSite, or BreadcrumbList structured data.
What to change: Add JSON-LD structured data for Organization, WebSite, Product, and BreadcrumbList to the homepage and product pages.
Robots.txt is blocked by Cloudflare High
The robots.txt file returns a 403 status, preventing crawlers from reading any directives. This means the site cannot communicate crawl preferences or sitemap locations to bots.
What to change: Ensure robots.txt is accessible to all crawlers by excluding it from the Cloudflare JS challenge.
Sitemap.xml is blocked by Cloudflare High
The sitemap.xml file returns a 403 status, preventing crawlers from discovering the site's URLs. This severely limits indexing.
What to change: Ensure sitemap.xml is accessible to all crawlers by excluding it from the Cloudflare JS challenge.
LLMs.txt is blocked by Cloudflare Medium
The llms.txt file returns a 403 status, preventing AI crawlers from accessing any guidance or content summary.
What to change: Ensure llms.txt is accessible to AI crawlers by excluding it from the Cloudflare JS challenge.
JavaScript-dependent product quick-buy modals Medium
The site relies on JavaScript for product quick-buy modals, which would be invisible to crawlers even if they passed the Cloudflare wall. This hides product details from AI crawlers.
What to change: Ensure product details are available in static HTML, not just via JavaScript.
Flat heading structure with no hierarchy Low
The homepage uses multiple H2s with no nested hierarchy, which reduces semantic clarity for crawlers and accessibility tools.
What to change: Implement a proper heading hierarchy with a single H1 and nested H2s/H3s.
Track heist-studios.com across AI search
This is one snapshot. Open the interactive report to inspect evidence, or grade another site free.