<?xml version="1.0" encoding="UTF-8"?>
<!--
  Public, canonical routes only. Deliberately excluded:
    /welcome, /welcome4, /landing   — legacy homepage variants kept for rollback; indexing them
                                     would compete with / as duplicate content
    /login, /auth/callback, /signup — auth plumbing, nothing to index
    /scan/*, /scan2/*               — per-scan and per-share URLs, not stable public content
    /dashboard, /scans, /monitoring, /settings, /scan/new — authenticated app, nothing to index
    /guardduck-learning             — Coming Soon placeholder with no content; add it back when
                                     it ships real content

  The three welcome-4 marketing routes below (/what-we-check, /vs-code-review, /pricing) carry
  the marketing argument and were missing until 2026-08-17. /scan-md, added 2026-08-26,
  documents GET /scan/{domain}.md, which had been live since 2026-07-14 with nothing on the
  web saying so. All four and / are served as prerendered HTML (client/scripts/prerender.mjs),
  so a crawler that does not run JavaScript sees their real content.

  scripts/check-sitemap.mjs runs on every build and fails it if this file and the route table
  in src/app/routes.tsx disagree. A new public route must be added here, or listed as
  non-indexable there.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://guardduck.co/</loc>
    <lastmod>2026-08-20</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://guardduck.co/what-we-check</loc>
    <lastmod>2026-08-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://guardduck.co/vs-code-review</loc>
    <lastmod>2026-08-20</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://guardduck.co/pricing</loc>
    <lastmod>2026-08-11</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://guardduck.co/scan-md</loc>
    <lastmod>2026-08-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://guardduck.co/waitlist</loc>
    <lastmod>2026-08-11</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://guardduck.co/bot</loc>
    <lastmod>2026-08-26</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://guardduck.co/contact</loc>
    <lastmod>2026-06-13</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://guardduck.co/privacy</loc>
    <lastmod>2026-06-24</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://guardduck.co/terms</loc>
    <lastmod>2026-06-13</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://guardduck.co/acceptable-use</loc>
    <lastmod>2026-06-12</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
