Questions

The questions that decide it, answered against us where that is the truth.

A naming platform is bought on trust and the trust is spent the first time it turns out to have overstated something. So the first answer on this page is that it does not check trademarks, and the numbers in the rest of them are read out of the shipping modules rather than typed here.

16 of 28 consonants252 attested roots12 TLDs verified by RDAP9 sources that refuse
The names

What is actually being made, and what the method costs to make it.

Are the names really new, or is this handing me a word that already exists?

New by construction, and the construction is why that claim can be checked rather than asserted. A name here is a consonantal root poured through a wazn — a morphological template — so it has two named inputs instead of being a lucky string. Nothing in the naming path is generated by a language model: the same brief with the same seed returns the same names every time.

The way a root-and-pattern generator ships an existing word is by using a productive pattern. fāʿil, the active participle, exists for every verb in the language; pour a root into it and Arabic has already made the word — kāshif is real, wasīla is real, and no blocklist can cover them because the pattern produces real words faster than anyone can enumerate them. So the 27 productive templates are marked and kept out of the naming path, and a shortlist of 3 waznu carries the coining, each with a stated sense the name inherits.

What comes out is then screened rather than trusted. Candidates are checked against an English wordlist, against the Arabic lexicon and against a curated brand corpus, folded across spelling variants so that Kajabee and Kajabi are treated as one name. Surviving that screen means “not caught”, which is not the same as “clean” — the corpus is finite, and the results say so rather than implying otherwise.

Separately, every shortlisted name is screened for existence against sources that answer: Wikipedia and Wikidata for encyclopaedic collisions, GitHub organisations, the App Store, npm, PyPI and crates.io. That is existence screening, not trademark clearance — see the trademark question below.

The waznu a name may be coined in
PatternWaznWhat the shape itself claims
1I2u3fīʿula name built on X that claims nothing further about it — the long ī carries it, and Arabic derives nothing in this shape
1I2i3fīʿilX held between a long vowel and a short one — a name on X, and no predication over it
1u23I4fuʿlīla four-consonant name shape — nothing in Arabic reads it as a derived form of anything

Is the Arabic correct?

The Arabic is generated, not translated. The script form places the same root consonants into the same template that produced the Latin spelling, so the wordmark and the name are two renderings of one derivation rather than a transliteration performed afterwards by a different system. That is why they always agree with each other.

The lossy direction is romanisation, and it is where the caveat lives. Roots are stored in Latin letters, and several Arabic letters collapse onto the same Latin one: ḥāʾ and hāʾ both arrive as h, ṣād and sīn both as s, ṭāʾ and tāʾ both as t. Where a hand-checked letter table records which letter a particular root really uses, that letter is used. Where it does not, the common letter is used and the name carries an explicit ambiguity note — printed on the name, never suppressed, because one confident Arabic wordmark with the wrong letter in it is the version that gets carved into a sign.

Short vowels are not written in Arabic. A name whose pattern uses only short vowels shares its written skeleton with every other short-vowel word on the same root, and the reader supplies whichever one they already know; a name built on a long vowel keeps its alif, wāw or yāʾ when the ḥarakāt come off. The rubric scores that difference rather than footnoting it at the end of the report.

None of this is a scholar's approval, and it is not offered as one. 7 of the 252 attested roots neighbour religiously loaded vocabulary and are held back from generation entirely, and a deliberately conservative rejection list screens what is left — but that list is maintained by engineers. Have any Arabic-derived name reviewed by a qualified Arabic scholar before you use it publicly, on any plan.

Why are only 16 of the 28 Arabic consonants usable?

Because a coined name has to survive being typed by someone who does not read Arabic, and romanisation is where that is decided. Roots are written in Latin letters throughout the engine, and only 16 consonants have an unambiguous Latin slot. A root containing anything else is dropped from the dictionary before generation rather than quietly producing a name nobody can spell back.

What that costs is specific, and it is most of the language. qāf, ʿayn, ghayn, khāʾ, thāʾ and ḍād are unreachable, which puts qamar (the moon), ʿilm (knowledge), ghayth (rain), khayr (good), thamar (fruit) and nahḍa (a renaissance) outside the search entirely. Roughly four in five Arabic roots cannot be used at all, and no amount of dictionary access changes that.

Five more — ḥāʾ, ṣād, ṭāʾ, ẓāʾ and dhāl — are reachable only where a hand-checked override records the true letter for a given root. What is left is a curated inventory of 252 attested roots, which is the honest size of the search space rather than the whole of Arabic.

The alternative is worse than a smaller inventory. Accept a root the generator cannot spell back, and the Arabic it prints will be confidently wrong — and confidently wrong is the state that reaches a sign, a filing and a set of business cards before anyone notices.

Labial
bfmw
Coronal obstruent
tdszsh
Coronal sonorant
lnr
Dorsal
kj
Guttural
h
Glide
y
Never reachable, and what it costs
ق
qāfcosts qamar — the moon
ع
ʿayncosts ʿilm — knowledge
غ
ghayncosts ghayth — rain
خ
khāʾcosts khayr — good
ث
thāʾcosts thamar — fruit
ض
ḍādcosts nahḍa — a renaissance
Verification and the legal question

The answers here are deliberately unflattering. They are also the ones that cost money to get wrong.

Does Nituj check trademarks?

No. There is a trademark section in every result and it is a screen for existence, not a clearance search. It asks whether anyone is visibly using a name, of sources that answer an unauthenticated request, and it names every register it could not reach.

Not one trademark register is searched. USPTO, EUIPO, UKIPO, WIPO's Global Brand Database, SAIP and the GCC Trademark Office are all key-gated or behind a challenge, and each is returned in your results as an explicit NOT VERIFIED row carrying the response it actually gave when it was last tested. All 9 refusing sources are printed rather than omitted, because an omitted row reads as a clean row and that misreading is the entire failure this is built to prevent.

What the screen cannot see is worth stating plainly: phonetic similarity as an examiner would assess it, Nice classes, territories, pending applications, common-law rights, and anything outside the corpus it holds. A screen with no findings is not a clear name.

The sentence the engine itself attaches to every result set is reproduced below in full. It is the operative one, and this page does not soften it.

This is a screen, not a clearance search. It queries public sources that answer an unauthenticated request and it names every register it could not reach; it does not search USPTO, EUIPO, UKIPO, WIPO, SAIP or the GCC office. No result here — including one with no findings at all — means a name is registrable, unregistered or safe to use. A clearance search by a registered trademark attorney covering the relevant Nice classes and territories is required before this name is adopted, filed or spent against.

lib/engine/trademark.ts — returned as the first check of every result set and printed on every exported document
9 sources that refused, printed in every result
Trademark and company sources that cannot be checked
SourceVerdictWhat it actually did when tested
USPTO (United States)refusednot verified

Tested 2026-08-03: tsdrapi.uspto.gov -> 401 with the body 'you'll need to register for an API key'; api.uspto.gov -> 403 {"message":"Missing Authentication Token"}; tmsearch.uspto.gov/api-v1-0-0/tmsearch -> 405 MethodNotAllowed (a static asset host, not a search API).

Would need: A registered USPTO API key, or an attorney-run TESS/TSDR search.

EUIPO (European Union)refusednot verified

Tested 2026-08-03: api.euipo.europa.eu/trademark-search -> 401 {"title":"Unauthorized","detail":"Invalid client id or secret."}. TMview (tmdn.org) DOES answer and does discriminate — see the note below on why it is nonetheless not used.

Would need: EUIPO developer-portal OAuth credentials (client id and secret).

UKIPO (United Kingdom)refusednot verified

Tested 2026-08-03: ipo.gov.uk trade mark text search -> 403 serving a "Service Captcha" interstitial; the search-for-trademark service API host did not complete a connection.

Would need: A human-solved captcha session, or the UKIPO bulk data service.

WIPO Global Brand Database (Madrid system)refusednot verified

Tested 2026-08-03: branddb.wipo.int returns 200 but serves an ALTCHA proof-of-work challenge page (HTML loading altcha.min.js), not search results. A 200 here is a challenge, not an answer — reading it as one is exactly the trap probe.ts was written to stop.

Would need: A challenge-solving client or WIPO's licensed data feed.

SAIP (Saudi Arabia)refusednot verified

Tested 2026-08-03: saip.gov.sa/en/trademarks -> 308 then 404 from the site's own application shell. No public search endpoint responds without an authenticated portal session.

Would need: A SAIP e-services account, or a Saudi trademark agent.

GCC Trademark Officerefusednot verified

Tested 2026-08-03: gccpo.org answers (200/301) with an ASP.NET portal shell. There is no JSON search endpoint and no unauthenticated query path.

Would need: A GCC portal session, or a national agent in the relevant member state.

Crunchbaserefusednot verified

Tested 2026-08-03: crunchbase.com/organization/stripe -> 403 and crunchbase.com/organization/zqxjwvbf9x7k-nonexistent -> 403. The endpoint refuses a known company and an invented one identically, so it cannot distinguish a hit from a miss and can never be gated.

Would need: A Crunchbase Enterprise API key.

LinkedIn company pagesrefusednot verified

Tested 2026-08-03: the endpoint does answer (stripe -> 200, zqxjwvbf9x7k-nonexistent -> 404) but it answers about a VANITY SLUG, not a company name: /company/saudi-aramco -> 301 while Saudi Aramco trades at /company/aramco, and /company/alphabet -> 200 for a company called Alphabet® that is not Alphabet Inc. A 404 therefore proves the slug is unclaimed and nothing about the name, which is not a question worth answering on a trademark page. (lib/omega/presence.ts uses this endpoint for handle availability, where the slug IS the question.)

Would need: The LinkedIn Marketing or Sales Navigator API, which is entity-keyed.

Product Huntrefusednot verified

Tested 2026-08-03: producthunt.com/products/stripe -> 403 and producthunt.com/products/zqxjwvbf9x7k-nonexistent -> 403, both a Cloudflare "Just a moment..." interstitial. api.producthunt.com/v2/api/graphql -> 404 without a bearer token.

Would need: A Product Hunt developer token for the v2 GraphQL API.

The 8 sources that do answer — Near-miss screen (offline corpus), Wikipedia (English), Wikidata, GitHub organisations, npm registry, PyPI, crates.io, Apple App Store — contribute existence findings only. Each carries its provenance Measured — computed from the name itself or a verified lookup in the report, and the refusals above carry theirs too: their claim is not “this mark is free”, it is “this register refused an unauthenticated request”, and that was measured.

What does “not verified” mean? Is it a soft yes?

It means we do not know, and it is the opposite of a soft yes. There are exactly three verdicts — free, taken, and not verified — and the fourth state a naming tool usually has, the reassuring maybe, does not exist here. It is drawn as a dashed, unfilled grey outline rather than in amber, because amber reads as a qualified yes and gets acted on.

Before any source is trusted for a single name it has to pass a control gate. It is handed a subject that is definitely taken and must report it taken; where an anti-control exists it is then handed one that is definitely free and must report it free. A source that fails either test is not consulted at all, and every name it would have answered for comes back not verified. A host that returns 404 for everything would otherwise report every name in the world as available, which is the most expensive way this system can be wrong.

Domains are checked by RDAP against 12 endpoints that each have a control and an anti-control recorded against them. Ask for any other TLD and the answer is “not verified”, because there is no endpoint — a refusal that has to reach you rather than arriving as silence.

Availability also expires. Results older than thirty minutes are discarded rather than re-shown, so a page will tell you it does not know instead of repeating an answer it can no longer stand behind. Re-run verification before you spend anything against a name.

example.comfreeexample.iotakenexample.sanot verified
Platforms that cannot be checked honestly, named in every run
Threads
threads.net 301s every handle to threads.com before looking it up; and threads.com's 302 only means 'no rendered Threads profile', which a taken Instagram handle with Threads never activated also returns (@hm, @bbcnews). Threads shares Instagram's namespace, so read the Instagram result as the Threads answer.
Product Hunt
Cloudflare challenge on every path, including robots.txt: 403 for a known product and for a coined slug alike, unchanged under Chrome and Googlebot UAs. The v2 GraphQL API requires an OAuth token.
Crunchbase
returns 403 to unauthenticated clients, including for known companies
Google Play
no public search endpoint reachable without a key
Trademark registries
USPTO, EUIPO, WIPO, SAIP and GCC require dedicated access

Do I own a name this generates?

We claim no rights in the names your runs produce. The output of your brief is yours to use, and that is the easy half of the question.

The hard half is that nobody owns a name because software coined it. Rights in a brand name come from registration and from use in commerce, and whether this particular string is registrable in your classes and territories is precisely the question this platform refuses to answer. Coining the word is the first step; the clearance search by a registered trademark attorney is the one that decides.

The engine is also deterministic, which cuts both ways: the same brief and the same seed produce the same names for anyone who runs them. A name that has appeared in your results is not reserved by having appeared there.

Plans and billing

Every limit quoted here is read from the same table the entitlement gate consults.

What counts against my monthly limits?

Two things are metered: discovery runs and live availability checks. Everything else on a plan is a capability rather than a quota — a feature is either included or it is not, and the comparison table on the pricing page is generated from the same entitlements the gate enforces.

Both meters are per calendar month and reset on the first. They are counted per organisation rather than per person, so a workspace with ten seats shares one allowance rather than getting ten.

Live checks are the calls that cost: the RDAP lookups and platform probes behind an availability answer. When a limit is reached the request is refused with the number used, the number your plan includes and the fact that the counter resets on the first of the month — rather than silently returning fewer names, which would look like a worse product instead of a reached limit.

Free is metered like everything else and is not a crippled demo: 10 names a run, 5 runs a month, 20 live checks a month, and the full derivation, phonetics, psychology and all ten explained scores on every name it shows you.

Can I cancel?

On this deployment there is nothing to cancel. Billing is not configured, so no card is ever charged and every account sits on the Free plan. What follows describes a deployment where billing is switched on.

Where it is configured, cancelling is done from billing settings and opens Paddle's own portal, so card details never touch this application. It takes effect at the end of the period already paid for rather than immediately: the subscription is flagged not to renew and the plan drops to Free when that period ends.

Downgrading deletes nothing. Projects, runs and saved names stay where they are; the Free plan's limits apply to what you create next — 3 projects, 10 names a run, 5 runs a month.

Refunds are the operator's policy rather than something the software decides, so this page will not invent one. If a refund window matters to your decision, ask before you buy — that is a better outcome than assuming one exists.

Why does Enterprise have no price?

Because what it costs depends on things a pricing table cannot see: how many seats, whether it runs in your infrastructure, which identity provider it has to sit behind, and what the audit and retention requirements are. Printing a number that every deal then renegotiates is worse than admitting the number is a conversation.

Everything else on the page is priced and self-serve. Enterprise adds API access, white labelling, SSO and the audit log on top of Business, and unlimited seats and checks — the comparison table lists it line by line like every other plan.

If the “Talk to us” button brought you to this answer rather than opening a message, this deployment has not published a contact address: the operator sets CONTACT_URL or CONTACT_EMAIL and the button then goes straight there. That is a configuration gap, not a price being withheld from you.

Your data, and this software

The answers below are written for the deployment you are looking at right now.

What happens to my data?

Projects, runs, saved names and comments are rows in Postgres, scoped to the organisation that created them. Row level security is the access control, not the application code: every table is deny-by-default and each policy names exactly who may read and write it, so a bug in a page cannot hand your project to another tenant, because no policy exists that would allow it.

Runs are stored whole rather than as a seed. A seed only reproduces a result while the engine's tables are unchanged, and a corpus update would silently rewrite a presentation you had already shown a client. Availability is stored alongside the timestamp it was measured at, so nothing old is ever re-presented as current.

Deleting an organisation cascades to its projects, runs, saved names and comments. The audit log is the exception: it has no update or delete policy at all, because an audit log a tenant can edit is not an audit log.

Availability checks still leave this server. RDAP registries, GitHub, npm, Wikipedia and the other probed sources see the coined name being looked up — that is what makes the answer a measurement rather than a guess.

The naming engine calls no language model. It is dictionaries, morphology, a phonetic model and a scoring rubric, so your brief is not sent to a model provider in order to produce names. The one optional model call in the product writes a prose summary of a brief, and it only happens where the operator has configured a key for it.

Is this AI?

Not in the part that makes the names. The naming path is deterministic: root dictionaries with attested glosses, morphological templates, a phonetic model, and a rubric with published weights. Run the same brief with the same seed and you get the same names, which is not a property a model has.

That determinism is also why every score can show its working. Each of the ten factors is required by the type system to carry a sentence explaining what it measured, and the sentence is the product — the number only summarises it. 19.05% of the total is openly editorial and is marked as such everywhere it appears, so you can discount a judgement instead of having it blended into a measurement.

There is no memorability probability and no success likelihood anywhere in the engine, because a calibrated number needs a labelled corpus of outcomes and no such corpus was available. An uncalibrated number dressed as a prediction is the failure this whole system is built against.

Can I run this myself, without an account?

Yes. With no environment configured the app runs in solo mode: no sign-in, no billing, everything unlocked, and work kept in the browser session. It is a real mode rather than a degraded one — it is what a fresh clone gives you — and every engine on the pricing page runs in it.

The one thing solo mode refuses to do is pretend in production. If the app is started in production without Supabase configured, it declines to boot rather than quietly serving every project to every visitor with no sign-in, because that particular failure looks like nothing being wrong at all.

Still the wrong question for you?

/method is the long version: the same mechanism, worked live by the engine while the page renders, with the weights, the wazn table and the source register printed in full.