Message test · Joon

Only 5 of 15 buyers could say why they would pick Joon over an alternative.

https://joon.co/15 AI-simulated buyers

Your message needs work: they know what it is, who it's for, and why it's worth their time, but not why to pick you.

Simulated responsesNo humans answered these questions. Every quote below was written by an AI model role-playing a buyer profile.
Saved report, kept for 60 days — expires in 60 days. Re-opening it is free.
01

Your verdict

  • Clarity

    Do they understand what you do?

    Strong13 of 14

    13 could name what kind of product this is, unprompted.

  • Relevance

    Can they tell what it solves, and who it's for?

    Strong12 of 15

    12 could quickly tell what problem it solves and who it is for.

  • Value

    Do they actually want it?

    Strong14 of 15

    14 would take a meeting to learn more.

  • Differentiation

    Fix first

    Is there a reason to pick you over the alternatives?

    Weak5 of 15

    5 could name a reason to pick you over a similar option.

See what they thought you were

Your page describes: security operations automation. They said:

  • 1×Agentic AI SOC / managed detection and responsewrong
  • 1×Agentic AI SOC / security operations automationmatches

12 couldn't name one; 1 named the wrong one; 1 got it right.

Four separate measures, not stages: all 15 personas answered all four questions. Each square is one persona.

Additional signalBrand alignment13 of 15StrongShow finding ▸

Two respondents found no healthcare references, outcomes, or compliance detail covering PHI, HIPAA, or clinical segmentation. Not one of the four layers, and it does not affect the scores above or the order to fix them in.

These are 15 simulated buyers. Want 15 real ones?

Test with humans
02

Fix these first

Fix these first

Three edits, in the order that matters.

The first is on your weakest layer, the second on the next, the third on the layer the most buyers had a problem with. Each says what to change on the page and why, with one simulated answer behind it.

  1. Replace "Outcomes are measured and delivered under strict SLA's" with the actual metric and penalty.

    Why: A guarantee with no number and no remedy is not a guarantee. State the committed coverage or response time, how it is measured, and what the customer gets if Joon misses it.

    Moves Differentiation
    Specifics beat superlatives
  2. Add a line under the hero naming the buyer: security leaders at companies with small SOC teams.

    Why: Nothing on the page says who it is for, so readers reverse-engineer it from logos and CISO titles. Write one line naming the role, the team size, and the situation.

    4 of 15 raised this

    “Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a…” Show full quote
    “Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a compliance deadline, it's more generic "AI evolves, keeping up isn't enough" language”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
    Moves Relevance
    Name the audience
  3. Add source and baseline under the "20x Operational Speed" stat.

    Why: Twenty times faster than what, measured how, is unanswerable from the page. Name the baseline, the measured task, and the customer or test the figure comes from.

    8 of 15 raised this

    “The "0% Alert Coverage" and "20x Operational Speed" stats have no baseline or source, so I can't tell if that's real lift over what I do today.”
    Security Operations Manager, Hospitality · 501-1000 employeessimulated
    Moves Value
    Proof next to the claim

Keep these · 2

These landed. Keep the wording when you edit around it.

  1. Keep · Clarity

    The hero line and four function tiles land immediately

    “The headline "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four blocks - Tune Detection, Validate Defenses, Investigate & Respond, Hunt Adversaries -…” Show full quote
    “The headline "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four blocks - Tune Detection, Validate Defenses, Investigate & Respond, Hunt Adversaries - told me in about ten seconds this is SOC work done by AI agents instead of hiring or using an MSSP.”
    Security Operations Manager, Hospitality · 501-1000 employeessimulated
  2. Keep · Differentiation

    Named CISO testimonials and founder pedigree are the only differentiators respondents…

    “"We invented SOAR, built Google SecOps, and trained Sec-Gemini." That's specific and checkable, and in a category full of vague AI claims, a team that literally built the…” Show full quote
    “"We invented SOAR, built Google SecOps, and trained Sec-Gemini." That's specific and checkable, and in a category full of vague AI claims, a team that literally built the category's prior tools is a real differentiator”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
03

All recommendations

Differentiation

Weak5 of 15
Moves DifferentiationConcrete over abstract

Rewrite "We Keep AI's True Promise. Hands-on." to say what Joon does that tool vendors cannot.

Why: That heading and the four tiles under it — Guaranteed, Tailored, Supervised, Seamless — could sit on any security AI site unchanged. Name the difference: Joon delivers staffed outcomes under contract, not software you operate.

Moves DifferentiationGive a reason to choose you

Move the founder line about SOAR, Google SecOps and Sec-Gemini into the H1 area with dates.

Why: The founder pedigree is the most convincing thing on the page, but it sits as a floating line above the hero and reads as decoration. Put it directly under the headline with the specifics of who built what and when.

Moves DifferentiationProof next to the claim

Add company size and stack next to each CISO quote.

Why: Buyers cannot tell whether the CAVA or H2O.ai deployment resembles theirs. Add the team size, SIEM, and what changed after deployment beside each testimonial.

Relevance

Strong12 of 15
Moves RelevanceSpecifics beat superlatives

Replace the "0% Alert Coverage" stat with a labelled before/after figure.

Why: A zero next to "Alert Coverage" reads as a broken page, not a claim. Show the gap it describes as a comparison, such as alerts untriaged before Joon versus after.

4 of 15 raised this

“Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a…” Show full quote
“Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a compliance deadline, it's more generic "AI evolves, keeping up isn't enough" language”
Chief Information Security Officer, Financial Services · 201-500 employeessimulated
Moves RelevanceProblem before solution

Add a sentence above "Tune Detection" naming the daily pain: unworked alerts and open roles.

Why: The page opens with Joon's answer before naming the problem in the buyer's own words. Lead with the backlog, the vacant analyst seats, and the nights nobody is watching.

4 of 15 raised this

“Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a…” Show full quote
“Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a compliance deadline, it's more generic "AI evolves, keeping up isn't enough" language”
Chief Information Security Officer, Financial Services · 201-500 employeessimulated

Clarity

Strong13 of 14
Moves ClarityAnswer the live objection

Add a line under "Human Overwatch" stating which actions need human approval before execution.

Why: Readers cannot tell where the agents act alone and where a person signs off. Say what Joon workers do unattended, what waits for approval, and who can stop an action.

5 of 15 raised this

“nothing on the page says what the human actually does versus what the agent does on a given alert, so I can't tell if I'm buying a tool…” Show full quote
“nothing on the page says what the human actually does versus what the agent does on a given alert, so I can't tell if I'm buying a tool or outsourcing my SOC”
Information Security Director, Technology · 1001-5000 employeessimulated
Additional signal

Brand alignment

Strong13 of 15
Moves Brand alignmentProof next to the claim

Add named outcome numbers to one testimonial block as a short case study.

Why: Every quote is sentiment with no measurement, so the proof stops at goodwill. Pick one customer and publish alerts handled, time to contain, and headcount avoided.

2 of 15 raised this

“nothing on the page addresses PHI, HIPAA-equivalent EU health data rules, or clinical network segmentation”
CISO, Healthcare · 1001-5000 employeessimulated
04

Buyer evidence

Biggest risks

A deliberately adversarial read of the same answers. Each claim was checked back against what the personas said and dropped if nothing supported it.

  • high

    The page's entire evidentiary foundation collapses under scrutiny, leaving only borrowed credibility to carry the sale.

    Eight respondents found the statistics unsourced with no baseline or methodology, and four found the guaranteed SLA unbacked by metrics or penalties. The only differentiators named were third-party testimonials and founder pedigree — not the product's own…

  • high

    Clarity at the surface masks the fact that the product itself is unexplained.

    Four respondents praised the hero line and function tiles for landing without interpretation, yet five could not determine where autonomous action ends, when approvals occur, or how data is ingested. The page communicates a category, not a mechanism.

  • high

    A statistic was read as a rendering bug, which means the numbers actively damage credibility rather than merely failing to help.

    One respondent saw a zero percent alert coverage figure and interpreted it as broken, not as a claim. With no baseline or direction given across eight respondents' objections, readers default to the least flattering interpretation.

  • high

    The page outsources its targeting work to the reader and gives them no reason to finish the job.

    Four respondents had to infer the intended buyer from logos and CISO quotes because the page never states who it is for, and one found no reason to act now. Audience ambiguity plus zero urgency means no next step.

  • high

    Nothing on the page survives a buyer's internal business case.

    Three respondents acknowledged the staffing pain is real but demanded before/after metrics from a comparable shop or a pilot on their own data, and four named a contractual SLA with verified metrics as the actual decision trigger. The page supplies neither.

  • medium

    Regulated verticals are locked out entirely, not just underserved.

    Two respondents found no healthcare references, outcomes, or compliance detail on PHI, HIPAA, or clinical segmentation. Combined with the unnamed buyer, the page offers regulated prospects no path in.

Differentiation

  • Named CISO testimonials and founder pedigree are the only differentiators respondents…

    4 of 15 · what worked

    “"We invented SOAR, built Google SecOps, and trained Sec-Gemini." That's specific and checkable, and in a category full of vague AI claims, a team that literally built the…” Show full quote
    “"We invented SOAR, built Google SecOps, and trained Sec-Gemini." That's specific and checkable, and in a category full of vague AI claims, a team that literally built the category's prior tools is a real differentiator”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
    See all 3 comments
    “We invented SOAR, built Google SecOps, and trained Sec-Gemini" - that's a specific, checkable claim and it's the kind of thing that makes me think ex-Google/Chronicle people”
    Chief Information Security Officer, Financial Services · 1001-5000 employeessimulated
    “The thing that would actually pull me toward this one versus a competitor is the named CISO testimonials with real companies attached - Cava, H2O.ai, Marriott Vacations -…” Show full quote
    “The thing that would actually pull me toward this one versus a competitor is the named CISO testimonials with real companies attached - Cava, H2O.ai, Marriott Vacations - that's rare enough in this space to be a differentiator”
    Director of Security Operations, Retail · 1001-5000 employeessimulated

Relevance

  • The intended buyer is never named and has to be inferred from logos and testimonials

    4 of 15

    “Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a…” Show full quote
    “Where it got vaguer was the "why now" — nothing on the page gives me a trigger like a new threat, a stat on breach costs, or a compliance deadline, it's more generic "AI evolves, keeping up isn't enough" language”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
    See all 3 comments
    “the intended reader is never explicitly named - no "for CISOs at mid-market companies" or similar - I inferred it from the quotes being CISOs”
    CISO, Healthcare · 501-1000 employeessimulated
    “the intended reader is never named outright - no "built for CISOs at mid-market companies" or similar - I inferred it from the testimonials”
    Security Operations Manager, Hospitality · 201-500 employeessimulated

Clarity

  • The mechanism is opaque — how agents ingest data, decide, and hand off to humans is…

    5 of 15

    “nothing on the page says what the human actually does versus what the agent does on a given alert, so I can't tell if I'm buying a tool…” Show full quote
    “nothing on the page says what the human actually does versus what the agent does on a given alert, so I can't tell if I'm buying a tool or outsourcing my SOC”
    Information Security Director, Technology · 1001-5000 employeessimulated
    See all 4 comments
    “I can't tell from them whether a human approves actions before they happen or only reviews logs after, which is the actual distinction that matters.”
    CISO, Healthcare · 501-1000 employeessimulated
    “It's agentic AI "workers" that sit on top of your existing security stack and run SOC functions - detection tuning, attack simulation/validation, alert triage and investigation, and threat…” Show full quote
    “It's agentic AI "workers" that sit on top of your existing security stack and run SOC functions - detection tuning, attack simulation/validation, alert triage and investigation, and threat hunting - with humans supervising the agents rather than doing the work themselves.”
    Director of Security Operations, Retail · 1001-5000 employeessimulated
    “The mechanism of how it actually ingests my data and makes decisions was never spelled out”
    Security Operations Manager, Hospitality · 201-500 employeessimulated
  • The hero line and four function tiles land immediately

    4 of 15 · what worked

    “The headline "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four blocks - Tune Detection, Validate Defenses, Investigate & Respond, Hunt Adversaries -…” Show full quote
    “The headline "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four blocks - Tune Detection, Validate Defenses, Investigate & Respond, Hunt Adversaries - told me in about ten seconds this is SOC work done by AI agents instead of hiring or using an MSSP.”
    Security Operations Manager, Hospitality · 501-1000 employeessimulated
    See all 2 comments
    “It was fast enough — the hero line "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four worker cards (Detection, Validate Defenses, Investigate…” Show full quote
    “It was fast enough — the hero line "Joon guarantees continuous defense - without growing headcount or outsourcing overhead" plus the four worker cards (Detection, Validate Defenses, Investigate & Respond, Hunt Adversaries) told me within seconds this is for SOC leaders drowning in staffing constraints, which is literally my problem.”
    CISO, Healthcare · 201-500 employeessimulated

Value

  • The statistics are unusable because no baseline, methodology, or source is given

    8 of 15

    “The "0% Alert Coverage" and "20x Operational Speed" stats have no baseline or source, so I can't tell if that's real lift over what I do today.”
    Security Operations Manager, Hospitality · 501-1000 employeessimulated
    See all 7 comments
    “the page gives me stats like "0% Alert Coverage" and "24/7 Proactive Defense" with no baseline or methodology, and claims "Outcomes are measured and delivered under strict SLA's…” Show full quote
    “the page gives me stats like "0% Alert Coverage" and "24/7 Proactive Defense" with no baseline or methodology, and claims "Outcomes are measured and delivered under strict SLA's - not estimated" without showing me a single SLA metric”
    Information Security Director, Technology · 1001-5000 employeessimulated
    “"0% Alert Coverage" and "20x Operational Speed" sitting there with no methodology or baseline behind them tells me nothing”
    CISO, Healthcare · 501-1000 employeessimulated
    “"0% Alert Coverage, 20x Operational Speed, 24/7 Proactive Defense, 360° Validation" — reads like a template that forgot to fill in the number; "0%" next to "Alert Coverage"…” Show full quote
    “"0% Alert Coverage, 20x Operational Speed, 24/7 Proactive Defense, 360° Validation" — reads like a template that forgot to fill in the number; "0%" next to "Alert Coverage" is either a bug or means nothing”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
    “the page gives me zero on mechanism - how it actually ingests my SIEM data, what "0% Alert Coverage" and "20x Operational Speed" are measured against, or what…” Show full quote
    “the page gives me zero on mechanism - how it actually ingests my SIEM data, what "0% Alert Coverage" and "20x Operational Speed" are measured against, or what the SLA actually guarantees”
    Security Operations Manager, Hospitality · 201-500 employeessimulated
    “What would rule it out, or at least knock it down the list, is that "0% Alert Coverage" stat sitting there with no number filled in - if…” Show full quote
    “What would rule it out, or at least knock it down the list, is that "0% Alert Coverage" stat sitting there with no number filled in - if that's a template bug nobody caught, it tells me something about their QA”
    Director of Security Operations, Retail · 1001-5000 employeessimulated
    “the stats like "0% Alert Coverage" and "20x Operational Speed" are unsourced and meaningless to me without a methodology”
    Chief Information Security Officer, Financial Services · 1001-5000 employeessimulated
  • The 'guaranteed' SLA is not credible without numbers or enforcement terms

    4 of 15

    “Until I see an actual SLA metric (MTTR, false-positive reduction, coverage %) tied to a dollar penalty, that's just a slogan.”
    Director of Security Operations, Retail · 1001-5000 employeessimulated
    See all 2 comments
    “the page gives me zero on mechanism - how it actually ingests my SIEM data, what "0% Alert Coverage" and "20x Operational Speed" are measured against, or what…” Show full quote
    “the page gives me zero on mechanism - how it actually ingests my SIEM data, what "0% Alert Coverage" and "20x Operational Speed" are measured against, or what the SLA actually guarantees”
    Security Operations Manager, Hospitality · 201-500 employeessimulated
  • Respondents want a case study or pilot on their own data before they would buy

    3 of 15

    “A documented case where a mid-market team my size kept the same headcount for a year while audited alert coverage and MTTR numbers actually improved - something with…” Show full quote
    “A documented case where a mid-market team my size kept the same headcount for a year while audited alert coverage and MTTR numbers actually improved - something with before/after figures I could show my board”
    Chief Information Security Officer, Financial Services · 201-500 employeessimulated
    See all 2 comments
    “A measured drop in MTTR or a measured reduction in analyst hours spent on tier-1 triage, with my own data, during a pilot - not a vendor benchmark.”
    Director of Security Operations, Retail · 1001-5000 employeessimulated

Brand alignment

  • There is nothing on the page for healthcare buyers

    2 of 15

    “nothing on the page addresses PHI, HIPAA-equivalent EU health data rules, or clinical network segmentation”
    CISO, Healthcare · 1001-5000 employeessimulated
05

How this works

Who we simulated (15 personas)

15 AI-simulated personas matched to your target market. Each answered independently, without seeing your goal, the scoring criteria, or each other’s answers. Attribution is role, industry and company size only.

Security Operations ManagerHospitality · 501-1000 employeesUS
Information Security DirectorTechnology · 1001-5000 employeesEU
Chief Information Security OfficerFinancial Services · 201-500 employeesUS
CISOHealthcare · 501-1000 employeesEU
Director of Security OperationsRetail · 1001-5000 employeesUS
Security Operations ManagerHospitality · 201-500 employeesEU
Information Security DirectorTechnology · 501-1000 employeesUS
Chief Information Security OfficerFinancial Services · 1001-5000 employeesEU
CISOHealthcare · 201-500 employeesUS
Director of Security OperationsRetail · 501-1000 employeesEU
Security Operations ManagerHospitality · 1001-5000 employeesUS
Information Security DirectorTechnology · 201-500 employeesEU
Chief Information Security OfficerFinancial Services · 501-1000 employeesUS
CISOHealthcare · 1001-5000 employeesEU
Director of Security OperationsRetail · 201-500 employeesUS
Methodology

Every answer on this page was written by an AI model role-playing a buyer profile, scored on Wynter’s B2B Message Layers framework. The personas were sampled in code across role, industry, company size and behavioral traits; the model wrote only the answers. Scores arrive through fixed verdict categories and the counts are computed in our own code, so no number here was written by a model.

Score details: the count and the strength

The count is how many personas cleared the bar on each question. A yes can be unhesitating or come with reservations; the scorecard counts both as a yes, and this is the only place the difference is shown. Per layer:

  • Clarity: 13 of 14, all with reservations
  • Relevance: 12 of 15, 1 without hesitation, 11 with reservations
  • Value: 14 of 15, all with reservations
  • Differentiation: 5 of 15, all with reservations

These answers are AI-simulated and directional. Validate anything you’re betting on with real buyers, your ICPs.

Your next 3 moves

  1. 1.Replace "Outcomes are measured and delivered under strict SLA's" with the actual metric and penalty.
  2. 2.Add a line under the hero naming the buyer: security leaders at companies with small SOC teams.
  3. 3.Add source and baseline under the "20x Operational Speed" stat.

See what real buyers say.

A detailed, section-by-section message test report from verified B2B professionals who are actually in-market for what you sell.

Test with humans
Trusted by
HubSpotRingCentralShopifyCognismPaddleVeeamRipplingMiro
RetentionThis report is kept for 60 days, until 4 Dec 2026, then deleted along with the personas, their answers and everything derived from them. The link stays live for that whole period so it can be shared or revisited, and stops working afterwards.

The email address it was requested from is kept beyond that, because it subscribes you to the newsletter — that was the price of the report. You can unsubscribe in one click from any issue, which stops the email without affecting a report still inside its 60 days. The public report page never shows the requester’s address.