
Security buyers read marketing differently than most audiences. A CISO, a PE operating partner, or a head of application security has spent years being sold tools that promised coverage they did not have, dashboards that aggregated numbers nobody could trace, and risk scores that fell apart the moment someone asked how they were calculated. By the time they reach a vendor page, they are not reading for inspiration. They are reading for the seam where the claim stops being supported. That habit is rational, and it means every confident sentence on a cyber-risk site is taxed before it is believed.
The credibility tax
We call this the credibility tax. It is the discount a skeptical buyer silently applies to anything you assert without showing its basis. The bigger the claim, the steeper the discount, because experienced buyers know that the strongest-sounding copy is usually where the supporting detail is thinnest. The instinctive vendor response is to make the claim louder: more superlatives, more logos, more round numbers. That response makes the tax worse. The only thing that lowers it is putting the basis of the claim directly next to the claim, so the reader can stop hunting for the seam and start evaluating the substance.
What proof before positioning means
Proof before positioning is the discipline of doing exactly that. Concretely, it means four things travel with every strong statement. The claim state: is this live in the product today, in active design-partner use, or on the roadmap. The source coverage: what data the claim rests on, and how much of the relevant surface that data actually spans. The confidence: whether the figure is a measured result, a modeled estimate with a stated range, or an illustrative example. And the publication boundary: what we are willing to say in public versus what lives behind login because it is tenant-specific or sensitive. When those four qualifiers are visible, a confident sentence reads as credible rather than promotional.
Our own output is a claim about money
This matters more in our category than most, because Valty's core output is itself a claim about money. We translate cyber and AI controls into dollar-denominated risk using FAIR-aligned Monte Carlo simulation, and we present results as a distribution (a P10, a base case, and a P90), not a single authoritative number. A loss estimate that arrives without its inputs, its coverage, and its range is not decision-support; it is a guess wearing a suit. So inside the product we enforce a claim-gate: an output that cannot show its sources, its freshness, and its confidence does not get presented as fact. It gets held back, flagged, or marked as an estimate with its boundaries stated.
The integrity argument is simple. If we gate our own product outputs that way, our marketing has to meet the same bar. A vendor that refuses to publish a stale or unsupported risk number to a customer's board, but happily publishes an unsupported coverage claim on its homepage, has two standards and no credibility. The buyer who notices that gap, and security buyers are paid to notice gaps, will reasonably assume the gating they cannot see is as soft as the marketing they can. Holding the marketing to the product's standard is not modesty. It is the most direct proof that the claim-gate inside the product is real.
The blocked-claim ledger
One practical mechanism we use is a blocked-claim ledger. When we draft a strong line for a page, a deck, or an email, and we cannot attach a defensible claim state, source, confidence, and boundary to it, the line does not quietly get softened until it slips through. It gets written down as blocked, with the reason it failed. Sometimes the reason is that the feature is roadmap, not live. Sometimes the data exists but does not span enough of the surface to support the generality of the wording. Sometimes the number is real but tenant-specific and cannot be published. The ledger turns "we can't say that yet" into an explicit, reviewable decision rather than an argument that the loudest person wins.
The ledger does something else that compounds over time: it becomes a backlog. A claim blocked because a capability is still on the roadmap is a claim we can make the day the capability ships and is verified. A claim blocked for thin coverage is a prompt to widen the source integrations until the generality is earned. Instead of marketing pulling ahead of the product and engineering scrambling to catch up to the copy, the copy trails the proof and advances as the proof advances. The strongest pages get stronger by getting more supported, not by getting more adjectives.
Stage-honesty and enterprise trust
Stage-honesty is the version of this that wins enterprise trust fastest, and it is the one most vendors get wrong. We are early, a design-partner-stage company, and the temptation at this stage is to narrate the roadmap in the present tense, to imply customers and certifications that do not yet exist, to let "will" quietly become "does." Enterprise buyers have a finely tuned ear for that move because they have been burned by it, and the moment they catch one inflated claim they re-discount everything else on the page. Saying plainly what is live versus what is planned, that SOC 2 is on the roadmap and not yet complete, that a capability is in design-partner use rather than generally available, does not read as weakness to this audience. It reads as the one signal they actually trust: a vendor who can be relied on to tell them the unflattering version.
Stage-honesty also sets up the rest of the relationship correctly. The enterprise security sale is long, technical, and adversarial by design. There will be a security review, a data-flow questionnaire, a procurement diligence pass, and often a proof-of-value where the product is measured against the buyer's own environment. Every claim made during marketing is a claim that gets tested in those later stages. A page that overstated coverage becomes a contradiction in the security questionnaire. A roadmap feature described as live becomes a failed checkbox in the POV. Marketing that is honest at the top of the funnel is simply pre-paying for the diligence that is coming anyway, while marketing that inflates is borrowing credibility it will have to repay at the worst possible moment.
An operating discipline, not a copy style
That is the deeper reason proof-before-positioning is an operating discipline and not a copywriting style. In a short transactional sale you can sometimes win on a confident claim before anyone checks. In a multi-month enterprise security cycle, with multiple stakeholders comparing notes, every assertion is eventually reconciled against what the product actually does. Discipline compounds: each honest claim that survives diligence makes the next claim cheaper to believe, until the buyer extends the benefit of the doubt by default. Inflation compounds too, in the other direction. Each caught overstatement makes the next claim more expensive, until the buyer audits everything and the cycle stalls.
So the operating rule is unchanged but the stakes are clearer. Publish what is supported, gate what is sensitive, and block what is stale or inferred. A public page can show a buyer exactly what an artifact (a proof pack, a board brief, a ranked remediation list) looks like, while the login-bound docs carry the implementation detail and the tenant-specific evidence. The strongest Valty pages are not the ones that make the biggest claims. They are the ones that make clean claims with the proof state visible, because for the buyers we are trying to earn, visible proof is the only form of positioning that survives contact with their diligence.