# Yaya > Yaya is a brand and website studio for cybersecurity companies. It builds positioning, messaging, visual identity and agent-native websites using the Cult Products Framework, and the two founders deliver the work themselves. Founded 2019, based in London, working across North America, Europe, the Middle East and Asia. [Website](https://yaya.co) ## Audience - The Cybersecurity Founder (Founder or co-founder of a cybersecurity startup): Three to eighteen months past a seed round of roughly six to twelve million dollars, with a team of eight to twenty five that is almost all engineers and no marketing hire. Usually a second-time founder or a deeply credentialed operator. Approaching a launch, a stealth exit or a conference deadline, and needing positioning, brand and a website that match the quality of what they have built. - The Marketing Leader (First or only senior marketer at a cybersecurity company): The first marketing hire at a late-seed to Series B cybersecurity company of thirty to a hundred and twenty people, often with a team of nought to three. Frequently inherited a founder-built brand and a website that reads as a brochure rather than a funnel. Needs a system they can run in-house without queueing behind product for every change. - The VC Platform Partner (Platform or portfolio lead at a cybersecurity venture fund): Runs the vendor bench for a specialist cybersecurity fund and refers portfolio companies to people they trust. Every referral stakes their own credibility, so they want a structured process, an end-to-end scope, and a vendor who can manage a founder rather than the other way around. ## Research - [The Cybersecurity Cult Products Awards report](https://yaya.co/resources/whitepapers/cult-products-awards-report): The first annual Cybersecurity Cult Products Awards report scores the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage against Yaya's Cult Products Framework: Revolutionary Vision, Radical Story, and Fanatical Followers. Key findings: almost 70% of startups use blue as their primary brand color, roughly seven in ten write in the same informative register, the median website requires a postgraduate reading level while user behavior shows heavy skimming, seven in ten sites run on Webflow or WordPress rather than a codebase they own, and only 42% offer value before requesting contact details. Token scored highest overall with 73 points, followed by Aim Security and Seal Security on 69, with winners named across seven categories. ## Pages ### Services - [What We Do](https://yaya.co/what-we-do): Yaya's services span positioning and messaging, brand identity, and website design and build, delivered as the Cult Products Programme in two shapes: the Cult Products Sprint and the Cult Products Classic. The work is sold only to cybersecurity companies. ### Glossary - [Glossary](https://yaya.co/glossary): A glossary of brand strategy, positioning and answer engine optimization terms as Yaya uses them, written for cybersecurity founders and marketing leaders. Each entry leads with a direct definition and states a position rather than repeating a dictionary. ### Company - [About](https://yaya.co/about): Yaya is a brand and website studio founded in 2019, working only with cybersecurity companies. Both founders work on every project. Clients include Twine, Aryon, Geordie, Zest, Kusari, Tenet and Aizome. - [Contact](https://yaya.co/contact): Contact Yaya about a cybersecurity brand or website project. Enquiries reach the founders directly. ### Optional - [AI visibility](https://yaya.co/glossary/ai-visibility): AI visibility is how often, and how favorably, a brand appears in the answers AI assistants give. It replaces rank as the metric when a buyer asks a model for a shortlist rather than reading a page of links. Measuring it means running the buyer's real prompts across the engines the buyer actually uses. - [Answer engine optimization](https://yaya.co/what-we-do/aeo): Answer engine optimization (AEO) is the practice of making a company legible and quotable to AI answer engines so it is named when a buyer asks for a recommendation. Yaya builds it into the brand and website from the first commit for cybersecurity companies, covering positioning, machine-readable structure, structured data, llms.txt and the sources models cite. - [Answer engine optimization (AEO)](https://yaya.co/glossary/answer-engine-optimization): Answer engine optimization (AEO) is the practice of making a company legible and quotable to AI answer engines so it is named when a buyer asks for a recommendation. It covers positioning, machine-readable site structure, structured data and presence in cited sources. Positioning, not markup, decides most of it. - [Book a meeting](https://yaya.co/book-a-meeting): Book a call with Yaya's founders to discuss positioning, brand, website and launch timing for a cybersecurity company. - [Brand architecture](https://yaya.co/glossary/brand-architecture): Brand architecture is how the names in a company relate to each other: the parent brand, the products, and any sub-brands. For a security startup it usually answers whether a new capability is a feature, a product, or a company. A named product earns its name when it can be bought, sold, or asked for separately. - [Brand guideline](https://yaya.co/glossary/brand-guideline): Brand guidelines are the documented standards for how a brand's visual identity, voice and messaging are applied. They are decision memory that prevents each project from starting from guesswork, keeping a brand coherent as it grows. - [Brand narrative](https://yaya.co/glossary/brand-narrative): A brand narrative is the story that explains why a company exists and why a buyer should believe its claims. It is the connective tissue between insight and brand identity, turning positioning from assertion into belief. - [Brand positioning](https://yaya.co/glossary/brand-positioning): Brand positioning is the place a company deliberately occupies in a buyer's mind relative to alternatives: who it is for, what it removes, and what it will not claim. It is a decision about what to give up rather than a statement of ambition. The test is whether a competitor could claim the same position without changing a word. - [Branding](https://yaya.co/what-we-do/branding): Yaya builds cybersecurity brands: niche and positioning, messaging, naming, tone of voice and visual identity. The method is the Cult Products Framework, whose three pillars are Revolutionary Vision, Radical Story and Fanatical Followers. - [ChatGPT SEO](https://yaya.co/glossary/chatgpt-seo): ChatGPT SEO is optimization to be cited by ChatGPT specifically, distinct from broader answer engine optimization targeting all AI systems. Because ChatGPT dominates business queries, being cited in its answers matters as much as ranking in search results. - [Cookie Policy](https://yaya.co/cookie-policy): Every cookie yaya.co can set, named, with its owner and duration. One consent cookie, one analytics vendor, no advertising, no session replay. - [Cybersecurity branding agency in Tel Aviv](https://yaya.co/cybersecurity-branding-agency-tel-aviv): Yaya builds brands and websites for Israeli cybersecurity startups. The team is in London and works the Tel Aviv to US corridor: positioning validated with the American buyers the company is actually selling to, then brand and website built to carry a launch. - [Events](https://yaya.co/events): Yaya attends RSA Conference, Black Hat USA and the Gartner Identity and Access Management Summit. This page lists those events with notes from each, and explains how the cybersecurity conference calendar shapes launch timing. - [For investors](https://yaya.co/for-investors): Specialist cybersecurity funds refer Yaya across their portfolios. One team, end to end, in ten to twelve weeks, with a process that manages the founder. - [Generative engine optimization (GEO)](https://yaya.co/glossary/generative-engine-optimization): Generative engine optimization (GEO) is answer engine optimization aimed specifically at generative results such as AI Overviews and chat assistants. In practice the terms are interchangeable and the work is the same. It differs from classical SEO in target and measurement: citation rather than rank. - [Home](https://yaya.co): Yaya is a brand and website studio working only with cybersecurity startups. It builds positioning, messaging, visual identity and agent-native websites using the Cult Products Framework, and the two founders deliver the work themselves. - [How to rank in ChatGPT](https://yaya.co/glossary/how-to-rank-in-chatgpt): To rank in ChatGPT means to be selected and cited as a source when a buyer asks a related question. Unlike search ranking, there is no visible position; the model selects sources based on domain authority, topical relevance, and how strongly the domain is associated with the topic. - [LLM SEO](https://yaya.co/glossary/llm-seo): LLM SEO is a loose term for optimizing to be cited by large language models rather than ranked by a search engine. Answer engine optimization is the more precise name for the same work. It does not replace search: buyers still search and organic links still convert, but a generated answer now sits above them on most commercial queries. - [Modern Slavery Statement](https://yaya.co/modern-slavery): Yaya Digital's voluntary modern slavery statement. We sit below the Section 54 threshold and publish anyway, with the real risk named and what we check. - [Our Work](https://yaya.co/our-work): Yaya's case studies cover brand strategy, messaging, visual identity and agent-native websites for cybersecurity companies including Geordie, Twine, Aryon, Zest, Aizome, Tenet, Kusari, Hypernative, EveryCloud, BastionZero. Two clients reached the RSA Innovation Sandbox final and Geordie won it in 2026. - [Pricing](https://yaya.co/pricing): Yaya does not publish prices. Work is delivered as the Cult Products Programme, in two shapes: the Cult Products Sprint and the Cult Products Classic. Every project is a fixed fee quoted against scope and agreed before work starts, payable up front or across a payment plan, with a percentage of the fee placed at risk against agreed outcomes. Engagements typically run twelve weeks. - [Privacy Policy](https://yaya.co/privacy-policy): What Yaya collects on yaya.co, which processors see it, how long we keep it, and how to make us stop. Written from the site's actual configuration. - [Rebranding](https://yaya.co/glossary/rebranding): Rebranding is changing how a company presents itself through some combination of name, positioning, identity and messaging. In cybersecurity it is usually triggered by a pivot, a funding round, or a proposition that has outgrown the original brand. Cost is driven by how much remains undecided rather than how much has to be designed. - [Terms and Conditions](https://yaya.co/terms-and-conditions): Terms covering yaya.co use. No account creation, no software licensing. Client work is governed by a separate agreement. - [Webinar](https://yaya.co/resources/webinar): A free on-demand training for cybersecurity founders on selling to enterprise CISOs: why buyers avoid vendor conversations, and how proposition, brand and website change that. - [Website](https://yaya.co/what-we-do/website): Yaya designs and builds websites for cybersecurity companies on React and a Sanity headless CMS, delivered as a codebase the client owns. Sites are agent-native: editable by AI agents over MCP and structured to be cited by answer engines. - [llms.txt](https://yaya.co/glossary/llms-txt): llms.txt is a plain-text file at the root of a site that tells AI crawlers what the site is and points them at the pages that matter. It is a convention rather than a standard. A generated stub is worse than none. A useful one names who you serve, what you do, what you will not take on, and the pages that answer real questions. ## Case Studies - [Aryon](https://yaya.co/our-work/aryon): Yaya took Aryon from stealth to launch in 2025 with a brand and website built around prevention rather than detection. Aryon has since raised a Series A. - [Geordie](https://yaya.co/our-work/geordie): Yaya built the brand and website for Geordie from inception in 2025, working with founders from Darktrace and Snyk. Geordie won the RSAC 2026 Innovation Sandbox a year later. - [Twine](https://yaya.co/our-work/twine): Yaya partnered with the ex-Claroty founders from inception in 2024 to brand and launch Twine, which builds AI digital employees for security teams. Twine reached the RSAC 2025 Innovation Sandbox final. - [Zest](https://yaya.co/our-work/zest): Yaya branded and launched ZEST Security out of stealth in 2024, then rebuilt the story for a relaunch timed to Black Hat. TechCrunch named ZEST one of the top cybersecurity startups of Disrupt 2025. ## Podcasts - [Building Action1: Mike Walters on Patch Management, AI Vibe Coding, and the Power of Focus](https://yaya.co/resources/podcasts/building-action1-patch-management-and-the-power-of-focus): Mike Walters had to kill his own products to find the one that scaled. He explains why vibe coding is about to make distribution matter more than code. - [AI is Your New Salesperson: Deepak Gupta on Going From SEO to GEO](https://yaya.co/resources/podcasts/ai-is-your-new-salesperson-from-seo-to-geo): Buyers increasingly describe a problem to a model rather than search a keyword. Deepak Gupta on what that does to your website, plus a three-step fix. - [The Logic of Deny by Default: Building the Ultimate Security Guardrail](https://yaya.co/resources/podcasts/the-logic-of-deny-by-default): Rob Allen spent two decades cleaning up after trust but verify. Why a 15 percent error rate makes AI unfit for the final allow or deny decision. - [Hacked CEO to Cybersecurity Author: Scott Schober on Transparency, Branding, and the End of Passwords](https://yaya.co/resources/podcasts/hacked-ceo-to-cybersecurity-author-scott-schober): A targeted attack cost Scott Schober 65,000 dollars. He wrote a book about his own mistakes, and built more trust than advertising had ever bought him. - [Cyber is a business problem that needs a business partner](https://yaya.co/resources/podcasts/cyber-is-a-business-problem-that-needs-a-business-partner): Green KPIs, patching reports and a CISO in post. Matthew Treagus on why organizations with all three still cannot say what is critical to the business. - [From CISO to Founder: How Itzik Alvas Built Entro by Solving the Problem He Lived](https://yaya.co/resources/podcasts/from-ciso-to-founder-how-itzik-alvas-built-entro): For every human identity there are about 144 non-human ones. Itzik Alvas had been breached by that problem as a CISO before he built Entro to solve it. - [Inside the CISO Mind: Trust, Culture, AI, and the Sales Moves That Backfire](https://yaya.co/resources/podcasts/inside-the-ciso-mind-trust-culture-ai-and-the-sales-moves-that-backfire): Ryan Lindley has sat in the CISO seat. He is specific about what earns a vendor trust, and about the sales behavior that gets a company quietly blocked. - [Founder-Led Sales and the Reality of B2B Trust](https://yaya.co/resources/podcasts/founder-led-sales-and-the-reality-of-b2b-trust): Dr. Damodar Sahu treats privacy as a trust problem rather than a compliance one, and explains why founder-led sales is not a stage you get to skip. - [Building Overwatch: AI Agents for Threat Intelligence at Attacker Speed](https://yaya.co/resources/podcasts/building-overwatch-ai-agents-for-threat-intelligence-at-attacker-speed): Arjun Bisen went from diplomacy and Google to building Overwatch Data. Why proof of value beats polished messaging in a market vendors overpromised to. - [Unboring Cyber: How Sara and Kelly Bring Human and Neurodiverse Thinking Into Cybersecurity Marketing](https://yaya.co/resources/podcasts/unboring-cyber-human-and-neurodiverse-thinking-in-cybersecurity-marketing): Padlocks, hoodies and fear-driven copy are still the default in cybersecurity marketing. Kelly Allen and Sara Carty on why, and what replaces them. - [From Claroty to Twine: Building a Top-Down Security Company](https://yaya.co/resources/podcasts/from-claroty-to-twine-building-a-top-down-security-company): Justin Woody ran 250 validation conversations before Twine settled on identity risk. Why trust closes enterprise security deals, and focus beats breadth. - [How Cult Products Win Big: Mastering Crowded Markets and Building Devoted Fans](https://yaya.co/resources/podcasts/how-cult-products-win-big): The Cult Products Framework in full: Revolutionary Vision, and why attracting the right buyers means being willing to repel the wrong ones. - [Brand Part 3: From Plan to Impact - The Journey of Turning Strategy into Branding Success](https://yaya.co/resources/podcasts/branding-part-3-from-plan-to-impact): Strategy on a slide is not a brand. How positioning becomes identity, with the Jaguar rebrand as the cautionary case. Part three of the branding series. - [Brand Part 2: Unstoppable Branding - Crack the Code with Blue Oceans & Archetypes](https://yaya.co/resources/podcasts/branding-part-2-blue-oceans-and-archetypes): Blue Ocean strategy and brand archetypes, the two tools behind a category of one. Part two of the branding series, for founders in crowded markets. - [Branding Part 1: Before the Flashy Logos - The Must-Know Foundations of Branding!](https://yaya.co/resources/podcasts/branding-part-1-foundations-before-the-logo): Before the logo: the positioning and audience work that decides whether a cybersecurity brand lands. Part one of the branding series for founders. - [Be marmite, not butter: Why divisive brands attract the biggest fans.](https://yaya.co/resources/podcasts/be-marmite-not-butter): Why a brand some buyers reject beats one nobody remembers, and what that means for a cybersecurity founder who is afraid of standing out. ## Optional ### Blog posts - [Your team page is a security control](https://yaya.co/resources/your-team-page-is-a-security-control): This article establishes that buyers of early-stage cybersecurity products treat the founding team as a proxy for a product they know is immature. Drawing on Yaya's generalized CISO and analyst research, it reports that a missing team page is an active gap in the buying journey, that domain lineage (prior experience selling into security or operating the software class now being secured) addresses the buyer's fear of being bluffed, and that career-exposed CISOs respond to de-risking language rather than urgency. It also covers the founder-as-face trade-off: personal visibility drives inbound, but company credibility must outlast one person's feed. - [How to stand out in agentic security when everyone is agentic](https://yaya.co/resources/how-to-stand-out-in-agentic-security): This article addresses differentiation in agentic security, the most crowded corner of the cybersecurity market, where the pitch 'AI for security, security for AI' has become the category default. It argues that real differentiation sits one level below the headline claim, in each team's distinct philosophy of the problem, citing Justin Woody of Twine on frontier AI labs as container ships and vertical slivers as the moat, Rob Allen of ThreatLocker on refusing to ship an 85%-accurate AI deny feature, and Geordie's agent-native framing. It concludes that memorable vendors win shortlists while forgettable ones are compared on price, applying Yaya's category-of-one argument. - [250 conversations before a line of code](https://yaya.co/resources/250-conversations-before-a-line-of-code): This article documents how cybersecurity founders validate before building. Justin Woody of Twine planned 100 buyer conversations, held 250, learned that identity was a bigger pain than vulnerability, and pivoted before writing code; his noted regret was not asking whether the pain justified a purchase tomorrow. Itzik Alvas of Entro Security ran over 200 practitioner conversations and used a referral test to separate politeness from real pain. The article covers The Mom Test, a survey method for testing proposition understanding, desire, and price sensitivity, and research findings that design partnerships with major companies are attainable when value is two-way and no sales hook hides in the research. - [How bold is too bold? The CFO-forward test](https://yaya.co/resources/how-bold-is-too-bold): This article addresses how bold a cybersecurity brand can be before boldness hurts sales. Evidence for boldness: in Yaya's Cult Products Awards report scoring the 77 startups at RSA's Early Stage Expo and Next Stage, the outliers increased trustworthiness by taking risks, and unmemorable brands are forgotten. The ceiling: a security-focused VC observed deliberately irreverent brands creating measurable go-to-market drag, including a CISO privately asking whether presenting the vendor internally would be embarrassing. Because security buying is consensus-driven, the proposed test is whether a champion can forward the vendor's website to a finance stakeholder without wincing. Boldness must trace to a real differentiator and fit the founding team, operationalized through a weighted archetype mix and a creative-review rule. - [When to launch: the cybersecurity market calendar](https://yaya.co/resources/when-to-launch-cybersecurity-market-calendar): This article argues that cybersecurity launch timing should follow the market calendar rather than product readiness or funding milestones. It maps the buying year: September, when US buyers return and set quarterly priorities; December, when nothing moves; and the early months, when RSA dominates attention. It introduces a role-reversal readiness test, describes a two-track stealth approach in which the product stays private while the founder publishes research and opinion, cites Itzik Alvas of Entro Security on releasing early, and summarizes events discipline from Rob Allen of ThreatLocker and Justin Woody of Twine: go big or go deliberate, never the middle. Brand work takes about three months, counted backwards from the chosen window. - [AI is your salesperson now](https://yaya.co/resources/ai-is-your-salesperson-now): The article explains how security buyers discover vendors through LLMs, based on the public Cult Products podcast episode with Deepak Gupta of Grakka. Buyers describe a use case in context rather than asking for a category, and models return three to five recommendations rather than twenty links. Different engines cite different sources, with enterprise and regulated buyers often using Copilot because of Microsoft's penetration. The article argues that specific positioning beats breadth, that the website must convert trust for both the model and the referred human, that community participation should educate rather than promote, and that an owned, machine-readable codebase outperforms the rented site platforms most of the category uses. - [The enterprise contradiction: adopt AI faster, secure it later](https://yaya.co/resources/the-enterprise-contradiction): This article describes the structural contradiction defining the agentic-security market: enterprises incentivize employees to adopt AI as fast as possible in domains they understand least, while that same adoption is the fastest-growing attack surface. It cites Geordie founders Hanah-Marie Darley and Henry Comfort on the split between organizations that block agents and those already running them without visibility, and their Geordie lamp framing of security as line of sight that lets innovation continue. It concludes that agentic-security vendors should sell enablement rather than gatekeeping, positioning the CISO as the AI champion who helps the business say yes safely. - [CISOs don't want more tools. They want fewer.](https://yaya.co/resources/cisos-dont-want-more-tools): This article argues that cybersecurity startups misread their buyer by pitching additions to an already overloaded security stack. Drawing on Yaya's webinar research, including interviews with CISOs and senior security buyers at companies such as Apple, Yahoo, and Red Hat, it establishes that every tool is an operational job, that security budgets work by replacement rather than addition, and that the buyer's dominant fear is purchasing the wrong product. It recommends replacement-led positioning, de-risking language over urgency, and resolving the narrow-versus-broad contradiction by claiming one lane and publishing the roadmap as an explicit journey. - [Security brands all sound the same too](https://yaya.co/resources/security-brands-all-sound-the-same): This article examines tone-of-voice convergence in cybersecurity branding, drawing on Yaya's Cult Products Awards report, which scored all 77 startups exhibiting at RSA's Early Stage Expo and Next Stage. Nearly all write in the same technical, professional, informative register. Wiz is presented as the counter-example, pairing personality with bold, Apple-like copy. The article explains the brand archetype method: cybersecurity gravitates to the Sage, and differentiated voices pair Sage credibility with a bolder archetype in a weighted combination of about three. It also defines the boldness ceiling from CISO research: brand character must survive being forwarded to non-security stakeholders, and imposed playfulness reads as fake. - [Nobody wants to book your demo](https://yaya.co/resources/nobody-wants-to-book-your-demo): The article establishes that demo-centric cybersecurity websites serve only the smallest segment of visitors. Drawing on Yaya's interviews with CISOs and senior security buyers, and on its Cult Products Awards analysis of the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage, it shows that most category marketing targets buyers who are ready now, while only 42% of startups offer value before requesting contact details. It recommends experience-led alternatives: self-serve trials, low-friction scans, product tour videos, and no-strings proofs of concept, plus ungated case studies, and explains why cold outbound damages future revenue in a small, well-networked buyer community. - [Category of one: the business case for niching down](https://yaya.co/resources/category-of-one): This article argues the commercial case for narrow positioning in cybersecurity startups. It explains how easy comparison drives decisions to price and erodes margins, why early-stage companies cannot afford broad positioning, and how the Blue Ocean method (eliminate, reduce, raise, create) locates a position where comparison becomes impossible, citing Figma's real-time collaboration bet as a public example. It distinguishes table-stakes capabilities from brand story, and adds a machine-readability argument: LLMs asked for vendor recommendations return three to five options matched to a described buyer context, and generalist positioning fails that match. It closes with a five-step value proposition method. - [The five-second homepage](https://yaya.co/resources/the-five-second-homepage): This article establishes that cybersecurity buyers evaluate startup homepages in roughly five seconds by attempting to place the product against a category they already know. Drawing on Yaya's CISO research, it reports that the most common reaction to startup homepages is 'I still don't know what you do,' that abstract benefit-led hero lines fail live messaging tests because they could describe multiple unrelated products, and that lines describing a concrete mechanism succeed. It identifies 'platform' and 'governance layer' as ineffective vocabulary, frames category creation as a multi-year commitment, and offers the value proposition formula 'We help X to achieve Y by doing Z, unlike everyone else.' - [Why every cybersecurity website looks the same (and what it costs you)](https://yaya.co/resources/why-every-cybersecurity-website-looks-the-same): This article analyzes visual convergence among cybersecurity startups using data from Yaya's Cult Products Awards report, which scored all 77 startups exhibiting at RSA's Early Stage Expo and Next Stage. Almost 70% use blue as their primary brand color, and secondary colors barely widen the spectrum. The article identifies three quality tiers, explains the stock-library dynamics behind category sameness, and connects visual sameness to commercial outcomes: buyers half-remember vendors days later, easy comparison defaults decisions to price, and undifferentiated brands get commoditized. Outliers in the research demonstrate that visual risk-taking can increase perceived trustworthiness. - [Your website reads like an academic paper](https://yaya.co/resources/your-website-reads-like-an-academic-paper): This article reports a finding from Yaya's Cult Products Awards report: Flesch-Kincaid grade-level analysis of the Home, About, Product, and Blog pages of all 77 startups at RSA's Early Stage Expo and Next Stage shows the majority require a post-graduate reading level, comparable to an academic paper. It contrasts this with behavioral research (screen recordings, eye tracking, heatmaps) showing visitors skim and scroll rapidly. Citing Yaya's CISO research, it argues complexity is not credibility, notes that forwarded pages reach non-technical stakeholders such as CFOs, and prescribes fixes: one idea per section, immediate jargon translation, short declaratives, and headings that carry the argument. - [The best cybersecurity websites, scored](https://yaya.co/resources/best-cybersecurity-websites): An annotated ranking of the highest-scoring cybersecurity company websites from Yaya analysis of all 77 startups exhibiting at RSA 2025. Ranked on brand differentiation: Prelude Research, Token, Seal Security, Aim Security, Reality Defender, CovertSwarm and Cygence. - [We scored the 77 cybersecurity startups exhibiting at RSA. Here is what we found.](https://yaya.co/resources/cult-products-awards-what-we-found): This article summarizes Yaya's Cult Products Awards report, which scored all 77 cybersecurity startups exhibiting at RSA's Early Stage Expo and Next Stage on three pillars: Revolutionary Vision, Radical Story, and Fanatical Followers. Findings include a three-tier quality distribution topped by Token (73 points), Aim Security (69), and Seal Security (69); almost 70% of startups using blue as their primary brand color; near-universal convergence on a technical, professional, informative tone of voice with Wiz as the public counter-example; majority post-graduate reading levels despite skim-heavy visitor behavior; and paid media concentrated on LinkedIn and aimed at buyers already ready to purchase, with only 42% offering genuine value first.