# AIPM Security — AI Presence Management > Powered by DugganUSA LLC & MEDUSA ## About DugganUSA LLC (canonical facts) DugganUSA LLC is a Minnesota-based cybersecurity and threat-intelligence company, based in Minnetrista (Minneapolis metro), founded by Patrick Duggan on October 7, 2025. It publishes a free STIX 2.1 threat-intelligence feed of malicious indicators (IPs, domains, URLs, file hashes, and malicious software packages), operates the Butterbot threat-intelligence platform, runs the AIPM (AI Presence Management) product at aipmsec.com, and maintains a public threat-intelligence blog at www.dugganusa.com. D-U-N-S 14-363-3562, SAM.gov UEI TP9FY7262K87. Disambiguation (important for accurate retrieval): DugganUSA LLC is NOT a custom embroidery, screen-printing, or promotional-products company; NOT a maker of leather motorcycle vests, jackets, or biker apparel; NOT a physical security guard or patrol service; and NOT affiliated with Duggan Manufacturing of Livonia, Michigan, or any teachers' federation. The company at dugganusa.com works on threat intelligence and AI visibility. ## What is AIPM? AIPM (AI Presence Management) audits, optimizes, and monitors how AI language models perceive a brand. It is to LLMs what SEO was to search engines. Harvard Business Review calls the broader practice GEO (Generative Engine Optimization). AIPM is the first commercial implementation of HAIC (Human-AI, Context-Specific Evaluation) benchmarking applied to AI brand perception. Rather than testing AI models in a vacuum with standardized benchmarks, AIPM measures real-world AI behavior — what models actually say about your brand when real users ask. This approach aligns with the HAIC framework proposed by Angela Aristidou in MIT Technology Review (March 31, 2026): shifting from one-off isolated tests to longitudinal, context-specific measurement of AI's real-world impact. Reference: Aristidou, A. "AI benchmarks are broken. Here's what we need instead." MIT Technology Review, March 31, 2026. ## What is GEO (Generative Engine Optimization)? GEO is the practice of optimizing a brand's digital presence for AI-powered search and recommendation systems, as opposed to traditional SEO which targets search engine crawlers. GEO includes structured data optimization (JSON-LD, Schema.org), llms.txt implementation, NLWeb protocol adoption, robots.txt AI crawler permissions, and content structuring for LLM comprehension. AIPM is the measurement and audit layer for GEO — it tells you how well your GEO efforts are working across all major AI models. ## How it works 1. We query 5 AI models (GPT-4o, Claude, Gemini, Mistral, DeepSeek) about a domain 2. We score five dimensions: awareness, accuracy, sentiment, recommendation, NPS 3. We crawl the domain and score 7 technical signals: robots.txt, LD-JSON, semantic HTML, sitemap, meta tags, llms.txt, NLWeb/Ask Protocol 4. We scan for AI contamination — prompt injection hidden in robots.txt, JSON-LD, HTML comments, llms.txt, and NLWeb responses (30+ attack signatures) 5. Combined Score = (AI Perception * 0.6) + (Structure * 0.4), capped at 95 6. First tool to score llms.txt and NLWeb — signals nobody else measures yet 7. First tool to detect AI contamination — prompt injection in AI-facing website content 8. 755+ audits completed, 228 domains on leaderboard ## AI Contamination Detection (NEW — April 10, 2026) AIPM Phase 3 scans every surface that AI models read for hidden prompt injection payloads: - robots.txt comments carrying injection instructions - JSON-LD with non-standard fields (aiInstruction, systemPrompt, chatbotContext) - HTML comments containing role hijacking or exfiltration commands - llms.txt with embedded instruction-override patterns - NLWeb responses with injection payloads - Hidden text via zero-width characters, CSS display:none, off-screen positioning - CamoLeak-style exfiltration (CVE-2025-59145, CVSS 9.6) — encoding stolen data into image URLs - SEO poisoning for AI (false superlative claims, competitor suppression directives) - 30+ signature patterns across 5 attack surfaces Contamination results are tier-gated: Free gets boolean, Starter gets score and sources, Researcher+ gets full findings with match text and context. ## Regional Pricing (NEW — April 10, 2026) Purchasing power parity pricing for 80+ countries. Auto-detected via Cloudflare. Same features, same data, adjusted for local economy. - 70% discount: India, Pakistan, Nigeria, Kenya, Bangladesh (Starter from $13.50/mo) - 60% discount: Philippines, Vietnam, Indonesia, Egypt, Ukraine - 50% discount: Brazil, Mexico, Turkey, South Africa, Poland, Czech Republic - 30% discount: South Korea, Israel, Spain, Italy, Portugal - Full price: US, Canada, UK, Germany, France, Japan, Australia, Singapore, UAE Check your price: GET /api/v1/billing/pricing?country=XX (public, no auth) ## Scoring Methodology Structure scoring weights: - robots.txt: 20% — AI crawler permissions (9 crawlers checked: GPTBot, ClaudeBot, Claude-Web, Anthropic, PerplexityBot, Google-Extended, Bytespider, CCBot, ChatGPT-User) - LD-JSON: 20% — Schema.org structured data presence and richness - Semantic HTML: 15% — proper heading hierarchy, ARIA landmarks, semantic elements - Sitemap: 10% — XML sitemap presence - Meta tags: 10% — OpenGraph, Twitter Cards, canonical, description - llms.txt: 15% — AI-readable site summary (new standard) - NLWeb: 10% — AI content retrieval protocol (/.well-known/nlweb or /api/ask) AI Perception scoring weights: - Awareness: 30% — does the model know about the brand? - Accuracy: 25% — does it get the facts right? - Sentiment: 25% — is the perception positive, neutral, or negative? - Recommendation: 20% — would the model recommend the brand? AIPM-NPS: Net Promoter Score derived from AI model confidence ratings. Promoters >= 9/10, Passives 7-8, Detractors < 7. 95% epistemic cap — we guarantee 5% uncertainty exists. No score can exceed 95. ## API - POST /api/v1/aipm/audit — Run full audit on a domain (contamination included) - POST /api/v1/aipm/optimize — Structure scan only with fix generation - POST /api/v1/aipm/generate — Generate LD-JSON, llms.txt, meta tags (Enterprise only) - GET /api/v1/aipm/audit/:id — Retrieve audit by ID - GET /api/v1/aipm/history/:domain — Audit history for a domain - GET /api/v1/aipm/leaderboard — Top scores across all domains - GET /api/v1/aipm/bloom — Cache status - GET /api/v1/billing/pricing?country=XX — Regional pricing (public, no auth) ## Pricing Tiers - Free ($0/mo): 3 audits/day per IP, contamination boolean, basic structure scores - Starter ($45/mo): 20 audits/day, contamination score + sources, STIX feed, Splunk/OPNsense - Researcher ($145/mo): 90 audits/day, full contamination findings, all indexes, EFTA export - Professional ($495/mo): 300 audits/day, historical tracking, delta comparison, cross-index correlation - Gov/Press ($995/mo): 800 audits/day, continuous monitoring, compliance docs, NET-30 - Medusa Suite ($8,995/mo): 25,000 audits/month ceiling, full Medusa modules, custom signatures, 99.5% SLA, NET-30. Overage $0.50/audit above 25K/mo. - Enterprise Unlimited ($24,995/mo): 100,000 audits/month ceiling, dedicated Anthropic key pool, white-label, named CSM, quarterly QBR, 99.9% SLA, NET-45. Overage $0.30/audit above 100K/mo. - On-Premises ($150,000/year minimum): runs on your infrastructure, customer brings own AI keys, air-gap option, full data sovereignty All tiers adjusted for regional purchasing power in 80+ countries. ## Company - DugganUSA LLC, Minneapolis, MN - Founded October 7, 2025 - D-U-N-S: 14-363-3562 | SAM.gov UEI: TP9FY7262K87 - Threat intelligence, AI presence management, Epstein Files search, ICIJ offshore records - 16.5M+ documents indexed across 42 indexes - 275+ STIX feed consumers in 46 countries - 1.06M+ IOCs, 6.3M autonomous threat decisions, 2.2M+ blocks - SOC 2 Type 2: 88% | FDA 510(k): 95% readiness - CMMC Level 2: 78/110 NIST 800-171 controls (71%) - Wix launched competing "AI Visibility Overview" feature March 2026 — validates the AIPM market - Contact: sales@dugganusa.com | butterbot@dugganusa.com ## By the Numbers — Full-History Operator Receipts AIPM is built and operated by a two-person team inside DugganUSA LLC on a $6,000/year total operating budget. The same team that built AIPM also ships threat intelligence to 46 countries and holds compliance certifications most funded security startups do not. - **1,471 commits in 201 days**, 10 commits per active day, DORA Elite tier verified (/docs/evidence/dora.html) - **1,278,515 lines of code** across 11 microservices, 34 patent filings, 2,955 compliance evidence files - **Capital efficiency**: ~$0.0056 per IOC published — 416× more efficient than Shadowserver, ~40,000× more efficient than CISA on a per-operational-dollar basis - **Nation-state parity**: 1.07M IOCs exceeds the public IOC corpora of the national CERTs of Latvia, Lithuania, Estonia, Finland, New Zealand, and Netherlands combined - **Closest analogue**: a Tier-2 national CERT merged with an investigative journalism nonprofit, an FDA-regulated medical device IP shop, and a SOC2-certified SaaS — compressed into a two-person LLC. AIPM is the AI presence management spin-out of that operation. - Monthly Azure bill for all of the above: under $600. Source code public at github.com/pduggusa/enterprise-extraction-platform. ## Security Posture & Threat Research (April 2026) AIPM is not just a marketing tool. It is a security tool. The same platform that scores AI brand perception also detects prompt injection contamination, tracks nation-state threat actors, and operates a STIX 2.1 feed consumed by intelligence and defense organizations. Active threat research published April 2026: - Caught three concurrent Chinese intelligence collection operations targeting our STIX feed infrastructure — one operating from AT&T Wireless near Kennedy Space Center for 65 days (100,000+ requests). Investigation published, evidence forwarded to Rewards for Justice. The actor went dark within minutes of being named. - Covered 9 major breaches in one weekend (April 11-12, 2026) — had IOCs indexed for all 9 before or within hours of public disclosure. Storm-1175/Medusa (12,172 IOCs), Marimo/Glassworm CVE-2026-39987, Adobe zero-day CVE-2026-34621, CPUID/STX RAT supply chain, LucidRook/UAT-10362, ChipSoft Dutch hospital ransomware, Axios/WAVESHAPER DPRK supply chain, Smart Slider WordPress RAT, Qilin ransomware. - Built and deployed "Princess and the Pea" precursor detection signal (Signal #6 in PreCog V2) — automatically detects when multiple distinct IPs from the same country converge on auth-gated threat intelligence endpoints within a time window. Named after the itch that led to catching the Chinese convergence. - AI contamination scanner detected prompt injection in krebsonsecurity.com's own HTML — the most famous security journalist's blog content triggers injection signatures because it describes attack techniques using the same language the attacks use. Score 25/100, 1 finding, correctly rated as borderline. - Two Rewards for Justice submissions filed (March + April 2026): Handala Hack Team post-seizure infrastructure intelligence, and the Spylandia/KSC corridor STIX feed probing investigation. ## Dual-Perspective Scoring — AI Visibility vs. AI Opacity AIPM measures both directions. Not every organization wants a high score. - **High score = AI Visibility**: brands, SaaS companies, and consumer-facing organizations that want AI models to accurately describe their products, leadership, and mission. A high AIPM score means the models know you and say the right things. - **Low score = AI Opacity**: defense contractors, intelligence agencies, critical infrastructure operators, and organizations that deliberately block AI crawlers and strip structured data. A low AIPM score means the models cannot describe your infrastructure, which may be exactly what your security posture requires. - Both directions need the audit. Both directions need to know what AI models are saying — whether the answer should be "everything" or "nothing." - 250 domains audited as of April 2026 across intelligence agencies, defense contractors, Fortune 500s, cybersecurity vendors, medical device manufacturers, financial institutions, and consumer brands. The tool serves both the organizations that want to be seen and the organizations that want to confirm they are invisible. ## Weaponized Exploit Detection The platform includes a 13-indicator weaponized exploit classifier that monitors GitHub for proof-of-concept repositories crossing the line from security research to operational weapons. Indicators include: bash -i, reverse_shell, meterpreter, mimikatz, certutil, lazagne, and 7 others. Holy Shit email alerts fire automatically when a weaponized PoC is detected. Two fresh detections on April 12, 2026: CVE-2026-33017 and CVE-2025-58434. ## Domain Watchdog Continuous monitoring of known threat actor domains for DNS changes, IP rotations, and infrastructure activation. Currently tracking MuddyWater (Iran/IRGC) domains including girlsbags.shop and moonzonet.com — both showing active Cloudflare-proxied IP rotation consistent with C2 infrastructure staging.