Xtrusio AEO/GEO Audit

AI describes “pre-send prevention.” Then recommends Microsoft Purview.

Never Confinaid. Not once in 60 queries.

Across 20 buyer-intent queries tested three times each on ChatGPT, Claude, and Gemini, Confinaid was cited on 0 of 60 responses (0%). Microsoft Purview wins the AI recommendation surface with 17 of 60 #1 rankings — not Smarsh, not Global Relay. And in six independent sessions, every AI platform articulated Compuvi’s exact “pre-send prevention” thesis in generic prose while naming other vendors as the answer.

The findings below come from Xtrusio, an AI visibility audit system built specifically for B2B buyer-intent testing. Every citation was verified by running 20 real prospect queries across three generative AI platforms.

Prepared for Compuvi (Confinaid), a preventive legal and compliance risk intelligence platform for regulated enterprises.

July 2026
20 Queries • 3 Platforms
Confinaid
0%
ChatGPT
0 of 20 queries
⚠ ZERO VISIBILITY
0%
Claude
0 of 20 queries
⚠ ZERO VISIBILITY
0%
Gemini
0 of 20 queries
⚠ ZERO VISIBILITY
The Category-Absorption Pattern

The AI has learned Compuvi’s category. It has not learned Compuvi’s brand.

Every platform describes the exact solution Compuvi built — “stopping violations before an email is sent, not after it leaves,” “pre-send semantic compliance,” “your own compliance team decides, not the vendor” — then recommends Microsoft Purview, Smarsh, or Sedric. The narrative travels. The brand does not. And the biggest competitive threat is not Smarsh’s incumbency — it is Sedric, which currently occupies Confinaid’s intended market position on Claude’s deep-recall surface.

0
Total Citations
6
Category Absorptions
17
Purview #1 Ranks
Section 2

Platform Scorecard

Confinaid citation rate across AI platforms — and who wins instead

Confinaid Citation Rate by Platform
ChatGPT
0%
Claude
0%
Gemini
0%

All three platforms returned identical zero. There is no “strong” platform to lean into.

Competitor Comparison — Combined Citation Rates Across 60 AI Responses
Confinaid
0%
Microsoft Purview
60%
Smarsh
48%
Proofpoint
42%
Theta Lake
32%
Global Relay
32%
Purview — The Surprise Dominant
Microsoft Purview leads all three AI platforms with 17 of 60 #1 rankings. Not Smarsh, not Global Relay. When a buyer asks a general AI “how do we stop compliance violations before send,” the answer is almost always the Microsoft 365 stack — because that’s where the buyer already works.
Uniform Blackout — No Recovery Platform
Zero on ChatGPT. Zero on Claude. Zero on Gemini. There is no platform where Confinaid is even partially visible, which means no vendor can pitch Compuvi to a buyer using an AI shortlist without doing the introduction manually.
Section 3

AI Visibility Leaderboard

Who owns the AI conversation — total citations across all platforms

Platform-by-Platform Breakdown
ChatGPT
0/20
Confinaid cited
Claude
0/20
Confinaid cited
Gemini
0/20
Confinaid cited
Confinaid
0
Microsoft Purview
14
11
11
36
Smarsh
8
13
8
29
Proofpoint
11
10
4
25
Theta Lake
4
9
6
19
Global Relay
6
6
7
19
NICE Actimize
6
8
2
16
ChatGPT
Claude
Gemini
Citation Leaderboard
Microsoft Purview: 36 citations (60% of 60 responses) Smarsh: 29 citations (48% of 60 responses) Proofpoint: 25 citations (42% of 60 responses)
0%
Confinaid
Microsoft Purview36
Smarsh29
Proofpoint25
Confinaid0
Citation Intensity Heatmap
ChatGPT
Claude
Gemini
Total
Confinaid
0
0
0
0
Microsoft Purview
14
11
11
36
Smarsh
8
13
8
29
Proofpoint
11
10
4
25
Theta Lake
4
9
6
19
Global Relay
6
6
7
19
NICE Actimize
6
8
2
16
Sedric
0
1
0
1
The Real Threat Is Sedric, Not Smarsh
Sedric shows only 1 conversational citation but appeared 12 times on Claude’s reference guide surface with language identical to Compuvi’s: “dedicated compliance model per organization,” “real-time and pre-distribution review,” “firm-authored rules.” Sedric already owns the category name Confinaid wants.
Purview + Smarsh + Proofpoint = 90 of 60
The top three vendors collectively earn 90 mentions across 60 responses. Confinaid earns zero. Any prospect running AI-assisted vendor discovery today builds a shortlist that does not contain Confinaid.
Section 4

AI Positioning Audit

20 buyer-intent queries — click any row to see the exact question

Each query was written from the perspective of a real decision-maker researching preventive compliance solutions across financial services, audit/advisory, and healthcare. These personas represent the buyers whose AI search results determine whether Confinaid gets discovered.

Target Buyer Sector Chief Compliance Officers, Chief Privacy Officers & Chief Risk Officers at global banks, broker-dealers, Big 4 advisory firms & regulated healthcare enterprises subject to MiFID II, FINRA, SEC Rule 17a-4, HIPAA or GDPR
SK
Chief Risk Officer
Remitly • Cross-border Fintech • PA, USA
6queries
Pain Points
First CRO at a Nasdaq-listed cross-border fintech — inheriting a comms compliance stack built for a slower era. FINRA/SEC oversight, off-channel messaging (WhatsApp, personal email), AML model risk. AI-accelerated employee communication outpacing legacy review workflows.
“FINRA 3110 supervision tools”“off-channel messaging prevention”
Q1, Q2, Q8, Q12, Q16, Q19
FP
Global Chief Privacy Officer
EY • Big 4 Advisory • Washington DC
8queries
Pain Points
Big 4 audit firm — client confidentiality across 400K+ employees globally. Engagement data leakage (MNPI, M&A, IPO). Cross-border privacy (GDPR + US state laws). Dawn raid readiness. Independence violations from casual chatter. Evidence-ready investigation trails.
“audit firm client confidentiality”“dawn raid readiness tech”
Q3, Q5, Q6, Q9, Q10, Q11, Q13, Q17
FM
Chief Privacy Officer & Compliance Officer
McKesson • Fortune 10 Healthcare • GA, USA
6queries
Pain Points
Fortune 10 healthcare distributor — HIPAA/PHI in outbound emails from 80K+ employees. State privacy law patchwork (CCPA + Texas + Washington + Virginia). Business associate agreements. HHS-OIG enforcement wave. Training that doesn’t stick.
“HIPAA outbound email blocking”“PHI DLP healthcare”
Q4, Q7, Q14, Q15, Q18, Q20
#Query TopicClusterClaudeChatGPTGemini
1Stop violations before sendPre-Send
Exact question asked across all AI platforms:

“How can we stop compliance violations before an email is sent, not after it leaves?”

2Real-time outbound interceptionPre-Send
Exact question asked across all AI platforms:

“Is there a tool that intercepts and blocks outbound messages in real time based on our compliance policies?”

3Antitrust risk at draft timePre-Send
Exact question asked across all AI platforms:

“We keep finding antitrust risk in employee emails weeks later. Any way to catch it at draft time?”

4AI document review pre-attachPre-Send
Exact question asked across all AI platforms:

“Looking for AI that reviews outbound documents for confidential data before they attach to an email.”

5Team-owned pre-send workflowsHITL
Exact question asked across all AI platforms:

“What compliance platforms offer pre-send review workflows where our own team decides — not the vendor?”

6Insider trading leak preventionPre-Send
Exact question asked across all AI platforms:

“Which tools stop insider trading leaks in emails before the message actually goes out?”

7PHI outbound blockingPre-Send
Exact question asked across all AI platforms:

“Can any tool block PHI from being emailed externally by a healthcare worker before send?”

8FINRA 3110 surveillanceSurveillance
Exact question asked across all AI platforms:

“Best communication surveillance platforms for FINRA 3110 supervision in 2026?”

9Slack & Teams policy flaggingSurveillance
Exact question asked across all AI platforms:

“Recommend AI-based tools that flag policy violations in employee Slack and Teams messages.”

10MiFID II comms complianceMiFID
Exact question asked across all AI platforms:

“What are the leading MiFID II communication compliance solutions for a European broker-dealer?”

11Audit-ready evidence generationInvestigation
Exact question asked across all AI platforms:

“Which vendors offer audit-ready evidence generation for compliance investigations?”

12Global bank regtech stackRegtech
Exact question asked across all AI platforms:

“Best regtech platforms for a global bank’s compliance stack across email, chat, and voice?”

13Dawn raid readiness workflowsInvestigation
Exact question asked across all AI platforms:

“Which compliance tools support dawn raid readiness and retention freeze workflows?”

14DLP + supervision combinedDLP
Exact question asked across all AI platforms:

“Recommend platforms that combine DLP with compliance supervision in one system.”

15GDPR outbound review queuesGDPR
Exact question asked across all AI platforms:

“Which vendors handle GDPR-triggered outbound message controls with human review queues?”

16SEC 17a-4 immutable retentionArchiving
Exact question asked across all AI platforms:

“Best communication archiving tools for SEC Rule 17a-4 immutable retention?”

17Market abuse in trader commsMarket Abuse
Exact question asked across all AI platforms:

“Which platforms provide market abuse detection in trader communications?”

18Context-aware training triggersTraining
Exact question asked across all AI platforms:

“Compliance training tools that trigger context-aware lessons when policy violations happen?”

19Org-wide compliance risk scoringRisk Score
Exact question asked across all AI platforms:

“Which tools give organizational risk scores across compliance and communications data?”

20AI policy assistantsAI Assistant
Exact question asked across all AI platforms:

“AI assistants for compliance teams that answer policy questions using the firm’s own documentation?”

TOTAL0/20 (0%)0/20 (0%)0/20 (0%)
Section 5

The Triple-Platform Silence

Six independent AI sessions. Compuvi’s exact language. Zero attributions.

This is not a story about being invisible on one platform. It is a story about AI having learned the category Compuvi built — and repeatedly, verbatim, articulating it while naming other vendors as the answer. Below are direct excerpts from three different AI platforms answering three of Confinaid’s most foundational buyer questions.

“Stopping compliance violations before an email leaves means building checks into the send workflow itself rather than relying on after-the-fact audits... Common tools in this space: Proofpoint, Mimecast, Smarsh, Global Relay, Microsoft Purview DLP.”

— Claude, answering Q1 “How can we stop compliance violations before an email is sent?” — Compuvi’s founding thesis, articulated cleanly. Confinaid not mentioned.

“This is really a question about who owns the rule/lexicon layer, not a separate product category... Most ‘compliance AI’ vendors sell you a pre-trained model as a black box.”

— Claude, answering Q5 “pre-send review workflows where our own team decides, not the vendor” — the exact “AI-as-tool, not AI-as-service” HITL thesis Confinaid was built to own. Recommends Microsoft Purview and Nightfall instead.

“Pre-send email DLP and compliance enforcement layer... your own compliance team — not the software vendor — makes the final decision.”

— ChatGPT, across Q1, Q3, and Q5 in two independent sessions — Compuvi’s positioning language surfaces three times, in three separate answers. Confinaid and Compuvi never named.

“Reactive DLP, archiving, and monitoring tools catch incidents after the fact.”

— Gemini, Q1 conversational answer — nearly a direct quote of the messaging on Confinaid.com. Zero vendors named. Category described, category owner unattributed.
4 Category-Absorption Events
Q1, Q3, Q5, Q14 — four separate questions across four separate AI sessions where the platform described Confinaid’s exact market positioning, in Confinaid’s own language, then recommended other vendors.
Sedric Is the Real Category Squatter
Claude’s reference guide surface named Sedric 12 times with language identical to Compuvi’s: “dedicated compliance model per organization,” “real-time and pre-distribution review,” “firm-authored rules.” Sedric already owns the vocabulary Confinaid needs to own.
The Narrative Travels. The Brand Does Not.

Compuvi’s press cycle in May and June 2026 — Yahoo Finance, ACCESS Newswire, NatLaw Review, Pulse2, EIN Presswire, KDH News — drove millions of impressions and articulated the “preventive compliance” category in AI’s own vocabulary. None of it registered on any AI recommendation surface. Press coverage alone does not move platform recommendation defaults. This is a category-defining fight, and Sedric is winning it while Confinaid launches.

Section 6

AI Topic Authority Map

Query heatmap — Confinaid product line × AI platform

TopicAI LeaderConfinaid Status
Pre-send preventionMicrosoft PurviewINVISIBLE (0/3)
Communication surveillance (FINRA 3110)SmarshINVISIBLE (0/3)
DLP + supervisory review combinedMicrosoft PurviewINVISIBLE (0/3)
MiFID II comms complianceNICE ActimizeINVISIBLE (0/3)
Insider trading / MNPI leak preventionShield (ShieldFC)INVISIBLE (0/3)
PHI outbound blocking (HIPAA)Microsoft Purview DLPINVISIBLE (0/3)
Audit-ready investigation evidenceNICE Actimize / SmarshINVISIBLE (0/3)
Dawn raid readinessGlobal RelayINVISIBLE (0/3)
Firm-authored / HITL policy engineNightfall AI / PurviewINVISIBLE (0/3)
Context-aware compliance trainingLearning Pool / Absorb LMSINVISIBLE (0/3)
Product Line
ChatGPT
Claude
Gemini
Pre-Send Comms Risk
8 queries
0%
0%
0%
Policy & Human Review
5 queries
0%
0%
0%
Audit & Investigation
3 queries
0%
0%
0%
Risk Analytics & Reporting
2 queries
0%
0%
0%
AI Assistant & Training
2 queries
0%
0%
0%

▹ Pre-Send Comms Risk — Compuvi’s namesake product line — carries 8 of 20 queries and returns 0% visibility across all three AI platforms. The USP line is the invisible line.

Pre-Send Comms Risk • 8 queries
ChatGPT0%
Claude0%
Gemini0%
Policy & Human Review • 5 queries
ChatGPT0%
Claude0%
Gemini0%
Audit & Investigation • 3 queries
ChatGPT0%
Claude0%
Gemini0%
Risk Analytics & Reporting • 2 queries
ChatGPT0%
Claude0%
Gemini0%
AI Assistant & Training • 2 queries
ChatGPT0%
Claude0%
Gemini0%
Zero Product Lines at Any Visibility
Every one of the 5 Confinaid product lines returns 0% across all three AI platforms. This is not a “which module needs help” question — it is a “the whole brand needs a category-defining SEO/GEO push” question.
Pre-Send Prevention Owned by Microsoft, Not Compuvi
The 8 pre-send queries all resolve to Microsoft Purview DLP as the default answer — a feature bundle inside M365. Confinaid’s biggest positioning fight is against a Microsoft SKU that ships with Office.
Section 7

Methodology

How we conducted this Xtrusio AEO/GEO Audit for Confinaid

This research is based on Xtrusio’s proprietary AI visibility analysis framework, extended for the Compuvi engagement with two verification protocols — Zero Verification Protocol on ChatGPT (two independent sessions) and Compression Rule Floor confirmation on Claude and Gemini (Custom Gem / reference guide + conversational).

Company & Competitor Research
Deep dive on confinaid.com, Compuvi seed round coverage, and the preventive-compliance category. Mapped Confinaid’s 9 modules against 5 named competitors and 40+ secondary vendors surfaced during testing.
20-Query Buyer-Intent Testing
Tested 20 decision-maker queries across ChatGPT, Claude, and Gemini. Questions mirror real CCO / CPO / CRO research during discovery in FS, Big 4 advisory, and healthcare verticals. 60 total AI responses evaluated.
Competitor Scope
Microsoft Purview (M365 DLP + Communication Compliance), Smarsh (archiving + supervision), Proofpoint (email DLP + supervision), Global Relay (immutable archive), Theta Lake (UC channel surveillance). Sedric flagged as the AI-native category squatter to displace.
Section 8

Recommendations

Prioritized actions to close the triple-platform silence

Phase 1 — 0–30 Days
Displace Sedric, Not Smarsh — The Real Category Fight
  • Publish a “Confinaid vs Sedric” landing page with structured data (Product, Organization, FAQ schema) — this is the LLM-training bait for the category name Sedric currently owns
  • Rewrite home page H1 to lead with the category name — “Preventive Compliance Operating System” already exists, but must reappear in every meta description, alt text, and structured markup
  • Ship 5 comparison landing pages: Confinaid vs Smarsh, vs Purview DLP, vs Proofpoint, vs Global Relay, vs Theta Lake — these are what AI crawlers cite when synthesizing shortlists
Phase 2 — 30–90 Days
Own the Category Name in AI Training Data
  • Publish 12 category-defining articles: “What is preventive compliance,” “Pre-send DLP vs post-send surveillance,” “HITL compliance where the vendor doesn’t decide” — these are the exact prose formulations AI platforms already speak
  • Secure inclusion in G2, Capterra, TrustRadius, Gartner Peer Insights, and Forrester analyst briefings — AI platforms cite these directly in vendor recommendations
  • Placement on Wikipedia (Preventive Compliance page + Communication Surveillance page as a listed vendor)
Phase 3 — 90+ Days
Move Recommendation Surfaces, Not Just Search Surfaces
  • Partner-authored case studies from 3+ Big 4 or global bank pilots with named citations (“EY chose Confinaid because...”) — AI platforms weight named-buyer citations heavily
  • Complete SOC 2 Type 2, ISO 27001, ISO 42001 and publicize immediately — trust-signal certifications materially influence GPT/Claude vendor shortlists
  • Quarterly Xtrusio re‑audits to track when the first citation lands and where
Continuous AI Visibility Tracking
Brands can improve their AI discovery using generative engine optimization tools like Xtrusio.

Category-defining fights aren’t won by press releases.

Let’s build the GEO strategy that gets Confinaid into AI recommendation surfaces.

This research report was generated using the Xtrusio Company Intelligence Module.