Your team page is a security control

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya6 min read

Key takeaways

  • Early-stage buyers use the team as a proxy for the product they know is not finished.
  • An industry analyst we interviewed flagged a missing team page as an active gap in the buying journey.
  • Domain lineage answers the buyer's real fear, which is being bluffed on things the vendor does not understand.
  • CISOs are career-exposed and professionally suspicious, so de-risking language beats urgency every time.
  • A visible founder drives inbound, but the business has to survive beyond one person's feed.

You are asking a career-exposed executive to bet part of their reputation on a product that is eighteen months old. They know it is not finished. You know it is not finished. The question your website has to answer is not whether the product is mature. It is whether the people behind it can be trusted to close the gaps in the right order.

That is why the team page, the most neglected page on most startup sites, is doing security work. It is a control. It reduces the buyer's risk, and the buyer knows it.

The proxy: people stand in for the product#

Buyers of early-stage security products are not naive. They understand exactly what stage you are at, and they price the immaturity in. What they cannot price in from a feature list is judgment. Will the roadmap bend toward their reality? Will the gaps close in the order that matters? Will the vendor still exist in two years?

Since the product cannot answer those questions, the people have to. In our CISO research, buyers of early products consistently described getting comfortable with the team as the substitute for getting comfortable with the product. The founders' history, their depth in the domain, the specificity of how they talk about the problem: these carried the weight the product could not yet carry.

An industry analyst we interviewed put it more bluntly. A missing team page is not a cosmetic omission. It is an active gap in the buying journey. The buyer goes looking for the people, finds nothing, and draws a conclusion. Silence about the team reads as something to hide, or worse, as a team that does not understand what its buyers need to see.

If the product is immature, the team is the product. Hiding it is hiding your strongest asset.

What domain lineage answers#

The team page is not a vanity wall. It exists to answer one specific fear: being bluffed.

Security buyers have all been burnt. Arjun Bisen of Overwatch made this point publicly on our podcast: "everyone is burnt by vendors over-promising and under-delivering." Buyers have seen the slick marketing campaign, then met the product. "The delta between what they said and what they delivered is huge." Which is why radical honesty about what you can and cannot do earns disproportionate credit. The buyer's nightmare with an early-stage vendor is discovering, mid-deployment, that the vendor never really understood the environment they claimed to secure.

Domain lineage is the antidote, and it has two forms. The first is having sold into security before: you know the procurement gauntlet, the proof-of-concept rituals, the way a security team actually evaluates. The second is having operated the class of software you now secure: you were on the other side of the desk, running the thing, feeling the pain first-hand.

Either one tells the buyer that when they ask a hard question, they will get a real answer instead of a bluff. Both together are close to unfair. So say it plainly on the page. Not a paragraph of adjectives, but the specific history: where the team sold, what the team ran, what they saw break.

The psychology you are selling into#

To understand why this matters so much, look at the job you are selling into.

A CISO is professionally suspicious by design and career-exposed by structure. Nobody thanks them for the ten thousand attacks that were stopped. One miss defines a career. And in the current market the dominant fear is not missing out on a hot new product. It is buying the wrong thing: spending budget and political capital on a vendor that fails, disappears, or turns out to be a feature the incumbent ships next quarter.

Every element of your site lands on that psychology. Urgency plays, countdown energy, and pressure tactics do not read as momentum to this buyer. They read as risk. The vendor pushing hardest is the vendor with the most to hide.

See it in action.

De-risk, do not pressure#

The alternative to pressure is subtraction. Take risk off the table, visibly, on the page.

Three de-risking moves came through our research again and again. Say what you replace: budgets are mostly replacement, not incremental, and the buyer is silently asking what comes out of the stack if you come in. Say what you do not claim: scoping your own product honestly is rare enough that it functions as a differentiator, and buyers notice when a website describes a product that does not exist yet. And say how fast they can verify: how quickly a skeptical practitioner can see the product working on their own environment, without a meeting.

The team page is the fourth de-risking move, and it compounds the other three. An honest claim from an anonymous vendor is just a claim. The same claim from a named team with visible domain history is evidence.

The founder as the face#

There is a nuance here worth getting right, because founders tend to swing to one of two extremes.

The first extreme is invisibility. The founder stays out of the marketing entirely, the site speaks in corporate first-person plural, and the buyer meets no humans until the sales call. For an early-stage security company this throws away the inbound engine. In our research, education with an opinion attached drives interest before any marketing function exists, and a founder taking a contentious position beats a company contributing politely to the conversation. Buyers of early products want to see who they are betting on, and founder-led sales is the reality of this stage anyway.

The second extreme is total identification. The company becomes one person's feed, one person's face, one person's voice. It works right up until it becomes the risk. The buyer committing to a multi-year vendor relationship is quietly asking what happens if that one person burns out, leaves, or simply stops posting.

The resolution is sequencing. Lead with the founder now, because at this stage the founder is the most credible asset you have. But build the team's credibility on the same page, in the same register, so that trust attaches to the company and not only to the individual. The founder opens the door. The team page proves there is a company behind it.

The control, implemented#

Treat the team page like any other control: define what it must prove, then implement.

It must prove domain lineage, so name the specific history rather than the adjectives. It must prove judgment, so link the thinking, the research, the opinions the team has published. It must prove honesty, so let its tone match a product page that states plainly what you do and do not yet cover. And it must prove there are humans, so use real photography and real words, not a grid of logos and stock smiles.

None of this works, though, if the visitor never gets that far. The team page is the second question a buyer asks. The first is what you actually do, and most security homepages fail it in the opening seconds, which is the subject of the five-second homepage. And if you want the deeper version of how founders build domain credibility before there is any product to show, start with the validation work itself in 250 conversations before a line of code.

The product will mature. The category will shift. But the reason an early buyer says yes to you, rather than waiting a year for the safe choice, is almost always the same. They believed the people. Give them a page that makes believing easy.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

  • CISOs and buyers

    Justin Woody planned 100 buyer conversations for Twine and did 250. Nearly all of them pointed at a different problem, and the company pivoted before writing code. Here is how validation actually works.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Cybersecurity founders want to stand out and fear standing out. Both instincts are right. There is a working test for where the line sits, and it involves your champion's CFO.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Founders debate launch timing endlessly: before or after the raise, before or after the product feels ready. There is no perfect moment. There is a market calendar, and it should set your date.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Website

    Buyers describe a use case to an LLM and get a shortlist of three to five names. How security startups earn a place on it, and why the answer runs through a website you own.

    Phill Keaney-Bolland

    Phill Keaney-Bolland