A FedRAMP compliance-automation platform, indexed for the old web and structured for the new one. This is how iExcel made Knox Systems visible in both search and AI answers.
Every workstream on the Knox engagement ran through platforms the team already trusted. No proprietary black boxes — the stack Knox saw is the stack Knox can run against next quarter.
FedRAMP is the door. A SaaS company that wants to sell into the U.S. federal government — Department of Defense, civilian agencies, the entire GovCloud footprint — needs FedRAMP authorization to get past procurement. The process is technical, expensive, and long. It is also the single fastest-growing search category in cloud compliance.
Knox Systems builds into that gap. A compliance-automation platform that shortens the authorization runway for SaaS companies pursuing FedRAMP status. The product is real. The buyer is real. The traffic engine that connects them wasn't.
When iExcel picked up the engagement, the pattern was clean. Strong technical audience. Real product depth. And a search surface that was leaking on all three fronts — site health errors that kept the crawler working harder than it should, metadata that didn't map to how buyers actually query, and zero schema instrumentation for the AI-answer layer that had quietly become the second front of federal-buyer research.
The engagement opened with a full SEMrush technical audit — crawl coverage, sitemap integrity, canonical logic, indexability, page-speed signals — cross-referenced against Google Search Console for what the crawler was actually reporting back. Then a backlink-and-competitor-keyword pass: which FedRAMP-adjacent domains were consolidating referring domains, which query clusters competitors were ranking on that Knox wasn't showing up for, and where the defensible click-share sat inside the existing footprint.
The output wasn't a slide deck. It was a ranked, dated, ownership-assigned backlog: what to fix, what to write, what to schema, what to leave alone. Every item pinned to a workstream — dev checklist, metadata, on-page copy, blog reoptimization, schema deployment — and paced against a launch window the team could hit.
The audit set the baseline. Everything after Chapter 02 is what happened when the backlog started clearing.
The keyword research collapsed the FedRAMP category into a single working universe: 141 rows, roughly 51,000 monthly searches in aggregate, 55 of them already triggering an AI Overview in the SERP. That last number is the tell. More than a third of the theme was being answered by a generative summary before the reader ever clicked a blue link — which meant the on-page work had to do two jobs at once. Rank the page. Feed the answer.
The top of the list looked like the category itself. The head term. The marketplace query. The definitional queries a buyer types on the way in. The certification and compliance queries a buyer types once they know they need it.
The work ran on five parallel lanes. Every lane had an owner, a checklist, and a status pill that only moved to LIVE when the change was pushed to production and verified in Search Console. This is the board the team ran against — pinned in the shared workspace, updated on every merge, closed out on 11/13/2025.
The dev-SEO checklist was the least glamorous part of the engagement and the most consequential. Site-health signals compound. A duplicate title on a hub page doesn't just hurt the hub — it dilutes internal linking, splits ranking equity, and confuses the crawl budget on every URL that pointed into it. The audit surfaced five error classes with counts attached, ordered by blast radius.
Every one of them was cleared by 11/13/2025. The checklist below is the before-and-after Knox's dev team was working against — the same report we handed over on kickoff, marked closed on the same run.
Of the tracked ranking positions in the position-change export, 9% landed in the top three results against the program's own pre-engagement baseline — the same technical, metadata, and schema work that cleared the crawler also moved the needle where buyers actually click.
The blog reoptimization ran on a simple rule: the reader still comes first, and the answer engine reads exactly what the reader reads. That meant Key Highlights sections at the top of every long-form post — the same summary a reader skims and the same summary an AI Overview cites. FAQ blocks at the bottom, written against the queries the keyword universe surfaced, matched to FAQ schema so the answer engine could ingest them without guessing.
Site-wide, four schema types went in — the GEO-readiness prerequisites. Business schema so the brand entity is machine-legible. FAQ schema on every post that carried a Q&A. Breadcrumb schema across the blog so the crawler and the answer engine both understand the hierarchy. Article schema on long-form so citations round-trip correctly.
None of it changed how the pages read to a human. All of it changed how the pages read to everything else.
Organization identity, contact points, and service graph — deployed on every page so the brand entity is unambiguous to the answer engine.
Every blog FAQ block matched to structured markup. The reader sees the Q&A. The answer engine sees the JSON-LD underneath it.
Hierarchy exposed for every long-form URL — cleaner crawl paths, cleaner SERP breadcrumbs, cleaner citation surface for AI Overviews.
Author, publish date, and body structure marked up so the piece can be cited as an article rather than as a generic web page.
If you sell into a regulated market — FedRAMP, HIPAA, SOC 2, ISO 27001, PCI, StateRAMP — and your buyer's research motion starts with a query typed into a Google box and a generative answer engine, the Knox engagement is the shape of what to do about it.
Audit the site health that the crawler is quietly downgrading you for. Rewrite the metadata so the pages match how the buyer actually asks. Deploy the four schema types that make the brand, the FAQs, the hierarchy, and the long-form legible to the answer engine. Instrument the AI-Overview surface with the same discipline you apply to the blue-link surface.
The position-change export told the same story from a different angle. Against the pre-engagement baseline, 86% of the tracked keyword positions were entirely new — pages that didn't rank at all, now indexed and ranked. 20% of that footprint reached page one; roughly 9% broke into the top three. None of it happens without the site-health, metadata, and schema work landing first.
Most agencies still sell one search era at a time. The buyer is already living in both.
If your buyer starts research in Google and finishes it in an AI answer, your on-page needs to survive both surfaces. Book a 15-minute sanity check on your setup — we'll tell you where the traditional-search work is already covering the GEO work, and where it isn't.
Book a 15-min sanity check →