Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.
Phill Keaney-Bolland
Here is how a security product actually gets found now. A buyer does not type a category name into a search engine and wade through twenty links. They open an LLM and describe their situation: we are a 100-person company with 10 IT staff, our emails keep going to spam, give me the top five options. The model answers with a shortlist, and the buying journey starts from there.
That description comes from Deepak Gupta, the second-time founder behind Grakka, on our Cult Products podcast, and it matches what we see across the security startups we work with. "They don't say that, give me a CNAP solution or give me an email security solution," he told us. "They specifically ask about the specific use case." Buyers do not ask for categories. They describe use cases in context and let the model translate.
A search results page gave you twenty chances to be seen, with a long tail of pages behind it. An LLM gives three to five recommendations. That is the entire surface. If you are one of the five, you are on the shortlist before you have spoken to anyone. If you are not, you do not exist for that buyer, and there is no page two to rescue you.
Being one of five is the new page one. The mechanics change with it. The model is not matching keywords; it is matching the buyer's described situation against everything it can read about you: your site, your documentation, and what other people say when you are discussed.
Run the exercise on yourself. Write the prompt your best customer would have typed the month before they found you: their company size, their team, their symptom. Ask it in each engine your buyers use and read what comes back. That shortlist is your real competitive set, and it rarely matches the one on your battle cards. If you are not on it, the rest of this article is your to-do list.
Gupta's research points at a wrinkle that catches founders out: different engines cite different sources. "So the big challenge or what we have seen when we do the AI search is each LLM works differently," he said on the episode. Some read your website for messaging and positioning, some lean on third-party sources, some go to video. The material that earns you a recommendation from one model is not automatically the material that earns it from another. And the engines are not evenly distributed across buyers. Enterprise and regulated buyers are often on Copilot, in his words "because Microsoft has a good penetration in a lot of regulated industry". If you sell to banks, insurers, or government, the model reading about you is probably Microsoft's. Ask it about your problem space today and see whether you appear.
Think about what the model does with that use-case prompt. It looks for vendors whose public record matches a 100-person company, a small IT team, and an email problem. A vendor whose website claims to secure everything for everyone gives the model nothing to match against. A vendor who plainly states who they are for and what problem they remove is easy to recommend, because the fit is legible.
Specificity beats breadth. The narrow claim, the named buyer, and the concrete mechanism win the recommendation for the same reason they win with a human reader: the model can tell what you are. A machine deciding between five slots has no room for a maybe.
This is the argument for a category of one carried to its logical end. Claim one lane with total clarity and both audiences can act on you in seconds: the human buyer can place you against something they know, and the model can match you to a described situation. Vagueness fails both. A wide, hedged proposition does not make you eligible for more shortlists. It makes you eligible for none of them.
Gupta's sharpest point is about what happens after the recommendation. The website is the front door, and it gets used twice. The model reads it first, when deciding whether you belong on the shortlist. Then the human reads it, arriving warm from a referral the model just made. If the design is dated, the UX clumsy, or the messaging vague, the trust conversion fails at the second door and the referral is wasted.
This raises the stakes on craft. A recommendation from a model arrives with borrowed credibility, and a site that looks unloved spends it instantly. Buyers of security products are professionally suspicious; a front door that does not match the promise of the referral confirms their suspicion rather than easing it.
That second visit behaves like any other first visit. You have about five seconds to land who you are for and why you are different. And once the visitor is convinced enough to act, do not route them into a demo-only dead end, because nobody wants to book your demo. A buyer referred by a machine still wants to verify you on their own terms.
Communities are now ranking inputs. Reddit, LinkedIn, Quora, and Hacker News feed the models' picture of who is credible on a topic. The instinct to go and promote yourself there is exactly wrong. Those communities detect and punish self-promotion, and the models learn from how communities respond. Contribute real answers. Educate. Take positions you can defend. The presence that earns trust with practitioners is the same presence that earns citations from machines.
Our CISO research points the same way from the demand side. Research and education with an opinion attached drive inbound before any marketing function exists, and taking a contentious position beats contributing politely to the conversation. The models amplify that effect. A vendor with a distinctive, defensible position gets discussed, quoted, and linked, and the model reads all of it. A vendor who says what everyone else says gives the machine no reason to pick them out of the chorus.
There is an infrastructure question underneath all of this. When we scored the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage for our Cult Products Awards report, we found a category standardized on rented website platforms: most sites are built and hosted on Webflow, WordPress sits in second place, and HubSpot dominates the marketing stack. That is the status quo, and it is worth naming plainly: the layer AI reads is a layer most security startups do not own.
A codebase you own, structured for machine readability, is the version of your site that AI can actually read and your team can extend. Clean semantics, fast pages, structured data, and content a crawler can parse without fighting a page builder's output. This is why we build client sites in code the client owns: a React front end, Sanity as the content layer, and a repo in the client's GitHub, designed for AEO and AI tooling from the start. The machines reading your site will keep changing. Owning the code is what lets you keep up with them.
On the podcast, Gupta landed on the line the whole argument turns on.
"AI is your salesperson. AI is your affiliate manager. They are linking you to the customer."
Asked what follows from that, he was specific. "You just need to train the AI that this is what I'm selling, this is what I do, this is the problem I'm solving, and AI is gonna go and sell it for you." The training material is everything the model can read: your homepage, your documentation, your community answers, and the structure of the pages that carry them. Most of your future buyers will meet this salesperson before they ever meet you. It is already giving its pitch. Decide what it says.

Phill Keaney-Bolland
Co-founder and Designer, Yaya
Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.
The latest news, technologies, and resources from our team.
Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.
Phill Keaney-Bolland
AI for security, security for AI is now the default pitch. Differentiation in the most crowded corner of the market lives one level down, in philosophy, refusal, and story.
Phill Keaney-Bolland
Justin Woody planned 100 buyer conversations for Twine and did 250. Nearly all of them pointed at a different problem, and the company pivoted before writing code. Here is how validation actually works.
Phill Keaney-Bolland
Cybersecurity founders want to stand out and fear standing out. Both instincts are right. There is a working test for where the line sits, and it involves your champion's CFO.
Phill Keaney-Bolland
Founders debate launch timing endlessly: before or after the raise, before or after the product feels ready. There is no perfect moment. There is a market calendar, and it should set your date.
Phill Keaney-Bolland
Employees are being told to adopt AI as fast as possible in the domain they understand least. That contradiction is the market every agentic-security founder is selling into.
Phill Keaney-Bolland