Proof before positioning
Why cyber-risk marketing needs claim state, source coverage, confidence, and publication boundaries next to the strongest copy, and why a product that gates its own outputs should hold its marketing to the same standard.
Security buyers read marketing differently than most audiences. A CISO, a PE operating partner, or a head of application security has spent years being sold tools that promised coverage they did not have, dashboards that aggregated numbers nobody could trace, and risk scores that fell apart the moment someone asked how they were calculated. By the time they reach a vendor page, they are not reading for inspiration. They are reading for the seam where the claim stops being supported. That habit is rational, and it means every confident sentence on a cyber-risk site is taxed before it is believed.
The credibility tax
We call this the credibility tax. It is the discount a skeptical buyer silently applies to anything you assert without showing its basis. The bigger the claim, the steeper the discount, because experienced buyers know that the strongest-sounding copy is usually where the supporting detail is thinnest. The instinctive vendor response is to make the claim louder: more superlatives, more logos, more round numbers. That response makes the tax worse. The only thing that lowers it is putting the basis of the claim directly next to the claim, so the reader can stop hunting for the seam and start evaluating the substance.
What proof before positioning means
Proof before positioning is the discipline of doing exactly that. Concretely, it means four things travel with every strong statement. The claim state: is this live in the product today, in active design-partner use, or on the roadmap. The source coverage: what data the claim rests on, and how much of the relevant surface that data actually spans. The confidence: whether the figure is a measured result, a modeled estimate with a stated range, or an illustrative example. And the publication boundary: what we are willing to say in public versus what lives behind login because it is tenant-specific or sensitive. When those four qualifiers are visible, a confident sentence reads as credible rather than promotional.
Our own output is a claim about money
This matters because a Valty output can influence a funding decision. The public FAIR-aligned worked example reports mean, median and P95 annual gross loss with its assumptions, modeled-control effects and limitations. Those metrics describe different parts of a modeled distribution; they are not earnings adjustments or observed savings. In a platform evaluation, inspect how the proposed workflow exposes sources, freshness, unresolved evidence and claim-review state before relying on an output.
The same discipline applies to marketing. A source file, authentic screenshot or local test does not independently establish a customer outcome or general availability. Strong claims need evidence appropriate to their scope. The public sample establishes a reproducible fictional calculation; the separate application captures show illustrative interfaces. Neither substitutes for a demonstrated company workflow and its acceptance evidence.
The blocked-claim ledger
One practical mechanism we use is a blocked-claim ledger. When we draft a strong line for a page, a deck, or an email, and we cannot attach a defensible claim state, source, confidence, and boundary to it, the line does not quietly get softened until it slips through. It gets written down as blocked, with the reason it failed. Sometimes the reason is that the feature is roadmap, not live. Sometimes the data exists but does not span enough of the surface to support the generality of the wording. Sometimes the number is real but tenant-specific and cannot be published. The ledger turns "we can't say that yet" into an explicit, reviewable decision rather than an argument that the loudest person wins.
The ledger does something else that compounds over time: it becomes a backlog. A claim blocked because a capability is still on the roadmap is a claim we can make the day the capability ships and is verified. A claim blocked for thin coverage is a prompt to widen the source integrations until the generality is earned. Instead of marketing pulling ahead of the product and engineering scrambling to catch up to the copy, the copy trails the proof and advances as the proof advances. The strongest pages get stronger by getting more supported, not by getting more adjectives.
Stage-honesty and enterprise trust
Stage-honesty is the version of this that wins enterprise trust fastest, and it is the one most vendors get wrong. We are early, a design-partner-stage company, and the temptation at this stage is to narrate the roadmap in the present tense, to imply customers and certifications that do not yet exist, to let "will" quietly become "does." Enterprise buyers have a finely tuned ear for that move because they have been burned by it, and the moment they catch one inflated claim they re-discount everything else on the page. Saying plainly what is live versus what is planned, that SOC 2 is on the roadmap and not yet complete, that a capability is in design-partner use rather than a self-serve production rollout, does not read as weakness to this audience. It reads as the one signal they actually trust: a vendor who can be relied on to tell them the unflattering version.
Stage-honesty also sets up the rest of the relationship correctly. The enterprise security sale is long, technical, and adversarial by design. There will be a security review, a data-flow questionnaire, a procurement diligence pass, and often a proof-of-value where the product is measured against the buyer's own environment. Every claim made during marketing is a claim that gets tested in those later stages. A page that overstated coverage becomes a contradiction in the security questionnaire. A roadmap feature described as live becomes a failed checkbox in the POV. Marketing that is honest at the top of the funnel is simply pre-paying for the diligence that is coming anyway, while marketing that inflates is borrowing credibility it will have to repay at the worst possible moment.
An operating discipline, not a copy style
That is the deeper reason proof-before-positioning is an operating discipline and not a copywriting style. In a short transactional sale you can sometimes win on a confident claim before anyone checks. In a multi-month enterprise security cycle, with multiple stakeholders comparing notes, every assertion is eventually reconciled against what the product actually does. Discipline compounds: each honest claim that survives diligence makes the next claim cheaper to believe, until the buyer extends the benefit of the doubt by default. Inflation compounds too, in the other direction. Each caught overstatement makes the next claim more expensive, until the buyer audits everything and the cycle stalls.
So the operating rule is unchanged but the stakes are clearer. Publish what is supported, gate what is sensitive, and block what is stale or inferred. A public page can show a buyer exactly what an artifact (a proof pack, a board brief, a ranked remediation list) looks like, while the login-bound docs carry the implementation detail and the tenant-specific evidence. The strongest Valty pages are not the ones that make the biggest claims. They are the ones that make clean claims with the proof state visible, because for the buyers we are trying to earn, visible proof is the only form of positioning that survives contact with their diligence.
Inspect the fictional sample decision memo, or request a platform demo to explore the supported workflow with illustrative data. Company scope, evidence handling, access, onboarding and commercial terms are agreed separately before evaluation.

