Independent read · 30 July 2026 · published openly, corrections welcome
Nobody asked us to look. We read your public surface for a day, as a customer and then as a crawler, and checked what we found against the registries and the chain. This is not a scorecard and there is nothing to buy at the end of it. Every item below comes with the thing you would paste.
01 · The short version
ship.erewhon.com is Shopify, and Shopify has quietly handed you a complete machine surface. Your main site has none of it.
ia_archiver was retired around 2014. You are not blocking GPTBot, ClaudeBot or PerplexityBot, so the agents that would send you customers are welcome. There is simply nothing on the page telling them what matters, and no sitemap pointing at it.
So the 439 shelf stable things anyone can buy anywhere are fully machine readable, and the stores, the hours and the twenty one dollar smoothie are invisible. When an agent is asked about Erewhon it finds postmates.com/brand-city/beverly-hills-ca/erewhon-market and instacart.com/store/erewhon/storefront, because those have addressable URLs and you do not. It routes the customer to the commissioned channel.
Replace robots.txt entirely, and add an llms.txt. The Sitemap: line is the part doing the work; without it a crawler has no entry point at all.
02 · Four doors
The location cards render the labels Store Hours, Cafe Hours and Tonic Bar Hours with no values behind them. The hours live in click triggered tooltips built as images. We clicked one as a customer: the page body grew by 148 characters and the card still showed no hours. There is no OpeningHoursSpecification anywhere on the site.
The single most asked question about a grocery store cannot be answered by any machine, from any of your pages.
Which store you are looking at is held in localStorage, never in the URL. /browse/tonic is the same address for every location, so every crawler, every shared link and every agent sees the Grove and only the Grove. Nobody can link to a store, and nobody can cite one.
Accept a ?store= parameter that seeds the selection, and give each store a canonical URL. The state machine you have already works; it just needs to be readable from the address bar. Everything else on this page gets easier once a store has a URL, including the JSON-LD above.
/browse/tonic returns 200 and renders the full priced menu as plain unmarked text. Strawberry Glaze Skin Smoothie $21.00, Malibu Mango $21.00, Cafe Latte $5.75. The page title is the single word Tonic. There is no JSON-LD of any kind, and no sitemap exists to lead anything there.
A Menu with hasMenuSection and MenuItem entries carrying offers.price and priceCurrency. Same shape your Shopify property already emits correctly for the 439 packaged goods, applied to the items with the actual margin on them.
The smoothie is $21.00 today. The press an agent reads says seventeen, eighteen, nineteen and twenty dollars, so an agent asked what it costs will confidently quote a number you have not charged in some time. And searching hailey bieber on your own site returns (0) RESULTS, because the name was retired when the collaboration ended and nothing was left in its place. Searching strawberry glaze skin returns the item correctly.
A Product block with offers.price, and an alternateName of "Hailey Bieber smoothie". The price becomes the single machine readable source of truth, and the name people actually search still finds the thing they mean without you having to re-run the collaboration.
/locations, loads a 5,715,017 byte image. Twelve of your other stores sit near 0.1 MB on the same page, so your pipeline already works and five files went around it. And the wrapper holding your logo, navigation, store selector, search and cart carries aria-hidden="true" in the markup that is served before any script runs, which means a screen reader and an accessibility tree driven agent both see a page with no navigation at all. It sits next to a data-acsb-hidden attribute, so we are not going to guess whose code wrote it, only that it ships.03 · Sourcing
You are listed in the Regenerative Organic Certified public directory with seventeen products. Chocolate, dates, coffee, coconut oil, eggs. ROC is the strongest thing behind the word regenerative anywhere: soil health, animal welfare and farmworker fairness, with certified organic as the floor rather than the goal. There are only about 253 brands in that directory worldwide. That is genuinely near the front, and we could not find it stated anywhere a machine looks.
Across your 438 product public feed there are zero certificate numbers. Your own certifications line names USDA Organic, Global Animal Partnership, Marine Stewardship Council, HACCP and Demeter, and lists none of them on any individual product. ROC, the one that is checkable in a public registry today, is not on that line at all.
The gap is not that the standards do not exist. schema.org/Certification and the GS1 web vocabulary already carry the certifying agency, the certificate identifier, the grade, the status, the expiry and a URI pointing back into the certifier's own registry. hasCertification is already a Product property. The fields exist and are empty across the entire industry.
Widen the attribute object you already render. Your product bundle emits attributes: [{_id, name}] as bare text chips. Every value below is transcribed from a certificate PDF already sitting in a vendor folder. No audit, no new supplier, no research project.
claimType is the whole thing. Three values: certified, supplier_asserted, erewhon_asserted. It costs you an enum, and a grocer who voluntarily marks its own claims unverified reads as more trustworthy, not less. Everyone else's silence starts looking like the choice it is.
04 · The record nobody reconciles
Since January 2022, California law has required Tier One edible food generators to keep a monthly log: each recovery partner's name and contact, the types of food, the frequency, and the quantity, measured in pounds recovered per month. Separately, the receiving organization must keep its own record of the same poundage for the same month.
Two independent legal records of one number. Nobody, anywhere, reconciles them against each other. And no record in the system covers whether the food was eaten.
This is not a theoretical hole. In January 2024 Tesco, the most transparent food waste reporter in the industry, found through an internal audit that food it believed had gone to animal feed had gone to anaerobic digestion instead, and restated its reduction from 45 percent to 18 percent. It had been wrong for six years. It was caught by a one off audit rather than by any framework, and the error ran in the flattering direction.
Publish the monthly record you are already required to keep, and ask your recovery partner to publish theirs. No new law, no new measurement, no new system. It is a publication decision, and it turns two unreconciled private records into one number any member of the public can check.
Your current public figure is "over 25 tons of food each year." The richer numbers people cite trace back to a press release dated November 2022, when you had eight stores. You have thirteen. A dated record with a real denominator would make you the first US grocer anyone could actually verify, and Trader Joe's, Sprouts and Kroger all publish bigger numbers with no way to check any of them.
Method, and what we could not check
One day, 30 July 2026. Published files, pages loaded in a real browser, and clicks a customer would make. Registries and regulatory text read directly at their own public addresses, never faster than one request per second. Nothing was probed, fuzzed, scanned or exploited, no account was made, no order was placed, no form was submitted, and nobody at Erewhon, at any supplier, at any certifier or at any recovery organization was contacted.
Things we could not verify, listed rather than guessed at: your certificate number in the USDA organic INTEGRITY database, because its front end was returning an application error; whether you hold Marine Stewardship Council chain of custody, because the supplier directory redirected and then 404'd; your current B Corp status, because the directory returned 403; and the widely quoted "140 integrity standards" document, which appears only in secondhand press. We have not seen it.
One correction we made to our own work before publishing: an earlier pass described the aria-hidden wrapper as your application code. It sits beside a third party accessibility vendor's attribute, so the honest statement is that it is present in the served markup before any script runs, and we are not going to assert who wrote it.