# Message test — https://zeropath.com/

After reading your page, 13 of 15 personas could name a reason to pick you over a similar option — and differentiation was the weakest of the four.

- **Page tested:** https://zeropath.com/
- **Audience tested against:** Application security and DevOps leaders
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/zeropath-ai-native-sast-appsec-platform-cuKZid0

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 15/15 | 81% | 2 without hesitation, 13 with reservations |
| 2. Relevance | Can they tell what it solves, and who it's for? | 15/15 | 78% | all with reservations |
| 3. Value | Do they actually want it? | 15/15 | 78% | all with reservations |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 13/15 | 70% | all with reservations |

**Brand alignment** (a side metric, not one of the four layers) — 13/15, 70% strength (all with reservations). Does the page read like the company you actually are?

**Fix first: Differentiation.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Differentiation

**Add a maturity line under each non-GitHub integration naming supported versions and a customer using it.**

Gerrit, Bitbucket and Azure DevOps appear as logos with nothing behind them, so a team on Bitbucket can't tell if support is real or a checkbox. Add one line per integration stating what it does and a named customer running it.

*effort medium · impact high · tested against Proof next to the claim*

**Replace "Agentic AppSec for Everyone" with a line naming reachability-aware triage as the difference.**

"Agentic AppSec for Everyone" is a claim any scanner vendor could print. The one thing buyers found distinctive, reachability-aware analysis that only triages CVEs you actually call, is buried in the SCA product card.

*effort low · impact high · tested against Give a reason to choose you*

**Replace the 12-product grid headline "A complete AI-native security stack" with depth-per-product proof.**

Five scanner types and a twelve-tile grid read as sprawl, which works against the claim of consolidating tools. Lead the section with what each scanner catches that a point tool misses, rather than counting modules.

*effort medium · impact medium · tested against Specifics beat superlatives*

### Clarity

**Move the curl and OSS proof above the 12-product grid and shorten the grid intro.**

The strongest evidence on the page, the named curl maintainer quote, competes with a dozen product tiles that read as feature sprawl. Put the checkable third-party proof first and cut the module count down the page.

*effort medium · impact medium · tested against Proof next to the claim*

### Relevance

**Add a line under the hero naming the buyer: security teams owning AppSec for large codebases.**

Readers have to reverse-engineer who this is for from testimonial job titles and the integration list. Say it outright under the subheading, naming the role and the situation.

*effort low · impact medium · tested against Name the audience*

### Value

**Add a methodology line under the 90% claim stating baseline, measurement period and sample.**

"Cut noise by 90%" sits above a footnote that only says "Average across ZeroPath customers," so buyers treat it as marketing arithmetic. State what it is measured against, over what period, across how many repositories.

*effort medium · impact high · tested against Proof next to the claim*

### Brand alignment (side metric)

**Replace the "Fortune 500 customers / At scale" stat with named logos or a named deployment size.**

An unattributed Fortune 500 mention with no logo next to it reads as hollow and makes the rest of the stats bar suspect. Either show the logos, or state scale concretely, such as repositories scanned at the largest customer.

*effort low · impact high · tested against Proof next to the claim*

**Add a company facts line in the footer: founding year, headcount, funding stage and investors.**

Nothing on the page says how old or how large ZeroPath is, so enterprise readers assume an early-stage startup and discount the enterprise claims. A single line of company facts settles it.

*effort low · impact medium · tested against Answer the live objection*

---

## 03 · What is working

### The core promise — reachability-aware analysis cuts false positives — is understood from…

Five respondents repeated the problem and solution back accurately from the hero line and subheading, and one noted the messaging lands by leading with practitioner pain rather than features.

> The giveaway lines were "AI-native static analysis for real vulnerabilities" and "reachability-aware dependency analysis" — that's SAST and SCA with a noise-reduction angle
> 
> — Director of Application Security, E-commerce, 1001-5000

> It was obvious within the first two lines — "Unify your AppSec and cut noise by 90%" plus "Find and fix exploitable vulns across code, cloud, and runtime" told me the problem (too much noise/false positives across a fragmented AppSec toolchain) and roughly the solution within seconds.
> 
> — Application Security Manager, Software Development, 1001-5000

> the subhead "Unify your AppSec and cut noise by 90%" plus "Instant, agentic security for cloud, hybrid, and on-prem apps. Find and fix exploitable vulns across code, cloud, and runtime" tells me the problem (alert fatigue/noise in AppSec) and roughly who it's for
> 
> — Senior Application Security Manager, Financial Services, 5000+

### The Daniel Stenberg/curl endorsement is the single most credible element on the page

Seven respondents singled out the curl maintainer quote as named, checkable, unpaid third-party proof, rating it more persuasive than generic Fortune 500 testimonials and crediting it with making the noise-reduction claim believable.

> The curl maintainer quote — "even the ones we dismiss often have some insights and the rate of obvious false positive has remained low" — is the one thing that'd tip me toward a shortlist slot over a competitor
> 
> — Application Security Manager, Software Development, 201-500

> The Daniel Stenberg/curl quote is the one thing that'd pull me toward this over a competitor - a named maintainer of a hardened, widely-audited OSS project saying the false-positive rate "remained low" and that dismissed findings "have some insights" is a specific, checkable, low-incentive endorsement, not a logo wall.
> 
> — Senior Application Security Manager, Financial Services, 501-1000

> Daniel Stenberg saying "the rate of obvious false positives has remained low" is a named, credible third party with no commercial reason to flatter them, and that's rarer than the usual anonymous "Security Lead, Fortune 500" quotes.
> 
> — Director of Application Security, E-commerce, 1001-5000

> The testimonials about low false-positive rates from a curl maintainer give it a bit more credibility than most
> 
> — Director of DevOps, E-commerce, 501-1000

> that's a genuinely hard-to-fake signal since curl's maintainer has zero reason to shill for a vendor
> 
> — DevOps Lead, Software Development, 5000+

> The curl maintainer quote and the "90% less noise" line stuck with me as the pitch I'd repeat to a peer
> 
> — Application Security Manager, Software Development, 1001-5000

> it's someone with no commercial reason to flatter them and talking about dismissed findings, not just wins.
> 
> — Director of Application Security, E-commerce, 201-500

> The curl maintainer quote about low false-positive rates and the blog claim of "71-76% reduction with repo context" are the kind of specifics that make me think there's something real here
> 
> — Director of Application Security, E-commerce, 1001-5000

---

## 04 · What the personas said

### The product breadth reads as a bundle of modules, not a consolidated platform

Three respondents said the consolidation claim is undercut by presentation: five scanner types and a 12-product grid that reads as feature-sprawl without depth or substantiation.

> it's not one thing, it's a dozen bolted-on modules (SAST, SCA, Secrets, IaC, PR reviews, DAST, container scanning, AI-BOM) under one brand, which makes me suspicious it's really a single coherent product versus a bundle marketed as one.
> 
> — Senior Application Security Manager, Financial Services, 501-1000

> It's an AI-driven AppSec platform that scans code, dependencies, infra-as-code, and runtime to find and auto-patch vulnerabilities — basically SAST/SCA/secrets/IaC/DAST rolled into one, integrated with GitLab/GitHub/Jira
> 
> — Senior Application Security Manager, Financial Services, 5000+

> the "12 products" grid (SAST, SCA, Secrets, IaC, PR Reviews, Policy Engine, Risk Management, SAST Autofix, DAST, Container Scanning, AI Inventory, AI-BOM) reads like feature-sprawl with one line each and zero depth
> 
> — Senior DevOps Engineer, Financial Services, 201-500

### The 90% noise reduction claim is not believed without methodology or a test on their own…

Eight respondents challenged the headline metric, citing missing baseline, before/after numbers and mechanism; one noted the blog's 71-76% figure is more credible. Several said they need a live demo on their own repos before engaging.

> I'd take a meeting, but only to ask for a real number from a trial against our own Gerrit repos, not their marketing page: false positive rate, time-to-fix, and what breaks when it autogenerates a patch that doesn't compile.
> 
> — Application Security Manager, Software Development, 201-500

> But "90%" has no methodology attached, no baseline defined, no before/after numbers - so yes, it's worth a meeting, but only to make them show me the mechanism behind that number and a live triage example on our own repo, not to buy off the page.
> 
> — Senior Application Security Manager, Financial Services, 501-1000

> which is the right value prop for my actual pain (developer fatigue from false positives), but I'd want that 90% figure sourced before I believed it
> 
> — Senior DevOps Engineer, Financial Services, 201-500

> Worth a meeting, but only to grill them on the 90% number and ask for a reference customer our size doing Bitbucket at scale
> 
> — DevOps Lead, Software Development, 5000+

> It's worth a meeting only if they'll run it against our actual Gerrit repos and show me real before/after numbers, not case studies from curl or Aptos
> 
> — Director of DevOps, E-commerce, 501-1000

> the blog mentions 71-76% false positive reduction from "repo context," which is closer to believable and at least has a number attached
> 
> — Senior Application Security Manager, Financial Services, 5000+

> I'd still want real false-positive and detection-rate numbers against what I already run before I believe the 90% noise claim.
> 
> — Director of Application Security, E-commerce, 201-500

### Integrations outside GitHub/GitLab lack the detail and references to be trusted

Three respondents flagged that Gerrit is buried with no detail on maturity, Bitbucket has no reference customers at their company size, and the messaging skews toward GitHub/GitLab.

> What would rule it out, or at least stall it, is the Gerrit integration being buried in a logo strip with no detail — I run Gerrit, not GitHub/GitLab, and if their real strength is GitHub-native workflows I need to know that before I waste a demo slot.
> 
> — Application Security Manager, Software Development, 201-500

### The page gives no company maturity signals, and the unattributed Fortune 500 claim reads…

Five respondents noted missing funding, headcount and founding date, and read the Fortune 500 mention without logos as hollow; several inferred a Series A/B growth-stage startup rather than enterprise scale.

> it's pitched more at a scrappy security lead at a 200-person company than a director at a 5000+ shop with Bitbucket sprawl
> 
> — DevOps Lead, Software Development, 5000+

> What doesn't fully land yet is company maturity signal — no funding info, no headcount, no "founded in" date, so I'm inferring size from secondary cues
> 
> — Senior Application Security Manager, Financial Services, 5000+

> Reads like a well-funded Series B/C security startup, a few years old, selling upmarket now — the RSAC Innovation Sandbox badge, "Fortune 500 customers," and "300k+ scans run every month"
> 
> — Senior DevOps Engineer, Financial Services, 1001-5000

> I don't see a single Fortune 500 name, just a generic "Fortune 500 customers" claim with no logo attached, which is the kind of unsupported line that makes me discount it.
> 
> — Director of DevOps, E-commerce, 5000+

> Reads like a Series A/B security startup, maybe 50-150 people, a couple years old - RSAC Innovation Sandbox Top 10 nod and "hundreds of others" / "Fortune 500 customers" alongside named logos like Aptos and Riskified
> 
> — Application Security Manager, Software Development, 201-500

### The target buyer is never stated and has to be inferred from logos, integrations and job…

Six respondents said they worked out the intended reader from the integration list and testimonial titles rather than any explicit statement on the page.

> Who it's for is never spelled out explicitly, though - there's no "built for AppSec teams at mid-market or enterprise" line, I had to infer it from the integrations (GitHub, GitLab, Azure DevOps, Jira, Linear, ServiceNow), the "Fortune 500 customers" badge, and quotes from people with titles like "IT Security Manager" and "Security Lead."
> 
> — Senior Application Security Manager, Financial Services, 501-1000

> The intended reader isn't spelled out explicitly anywhere — there's no "built for AppSec teams at mid-large companies" statement — I inferred it from the integrations (GitHub, GitLab, Jira, Linear) and quotes from security leads and CTOs.
> 
> — Director of Application Security, E-commerce, 1001-5000

> the intended reader is inferred from testimonial job titles rather than stated outright, which is a minor gap, not a dealbreaker
> 
> — Senior DevOps Engineer, Financial Services, 201-500

> It was obvious within the first two lines — "Unify your AppSec and cut noise by 90%" plus "Find and fix exploitable vulns across code, cloud, and runtime" told me the problem (too much noise/false positives across a fragmented AppSec toolchain) and roughly the solution within seconds.
> 
> — Application Security Manager, Software Development, 1001-5000

> The "who" I had to infer from context: GitHub/GitLab/Azure DevOps integrations, Jira/Linear/ServiceNow sync, and quotes from "IT Security Manager" and "Security Lead" titles signal this is for AppSec/security teams and DevOps leads managing CI/CD pipelines, not individual devs — but nobody ever writes "this is for security leads at mid-to-large eng orgs" outright, I pieced that together from the integration logos and testimonial job titles.
> 
> — DevOps Lead, Software Development, 501-1000

---

## 05 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **The page's central number is dead on arrival — the headline metric loses more credibility than the rest of the page can recover.** *(high)*
  Eight of 15 challenged the 90% noise reduction for missing baseline, before/after and mechanism, and one caught the blog citing 71-76%. A public number the company's own content contradicts is worse than no number.
- **One borrowed endorsement is carrying the entire proof burden, and that is a single point of failure.** *(high)*
  Seven of 15 named the curl maintainer quote as the most credible element and credited it with making the noise-reduction claim believable, while five read the unattributed Fortune 500 mention as hollow. Strip Stenberg and nothing substantiates the page.
- **Comprehension is not persuasion: people understood the promise and still refused to act on it.** *(high)*
  Five repeated the reachability-aware pitch back accurately, yet eight demanded a live demo on their own repos before engaging. The page has solved explanation and left the evidence gap untouched.
- **The page sells a platform and demonstrates a parts bin, so breadth actively damages the consolidation argument.** *(medium)*
  Three respondents said five scanner types and a 12-product grid read as feature-sprawl without depth or substantiation, undercutting the consolidation claim. Adding products currently subtracts credibility.
- **The page disqualifies every buyer not already on GitHub or GitLab.** *(medium)*
  Gerrit is buried with no maturity detail and Bitbucket carries no reference customers at the reader's company size. Anyone outside the two favored platforms is told, implicitly, that they are not the customer.
- **The page forces readers to self-qualify, which means the ones who guess wrong leave.** *(medium)*
  Six of 15 reconstructed the intended reader from the integration list and testimonial job titles because no statement on the page says who it is for. Inference is a tax the page charges every visitor.

---

## 06 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Application Security Manager | Software Development | 201-500 |
| 2 | Senior Application Security Manager | Financial Services | 501-1000 |
| 3 | Director of Application Security | E-commerce | 1001-5000 |
| 4 | DevOps Lead | Software Development | 5000+ |
| 5 | Senior DevOps Engineer | Financial Services | 201-500 |
| 6 | Director of DevOps | E-commerce | 501-1000 |
| 7 | Application Security Manager | Software Development | 1001-5000 |
| 8 | Senior Application Security Manager | Financial Services | 5000+ |
| 9 | Director of Application Security | E-commerce | 201-500 |
| 10 | DevOps Lead | Software Development | 501-1000 |
| 11 | Senior DevOps Engineer | Financial Services | 1001-5000 |
| 12 | Director of DevOps | E-commerce | 5000+ |
| 13 | Application Security Manager | Software Development | 201-500 |
| 14 | Senior Application Security Manager | Financial Services | 501-1000 |
| 15 | Director of Application Security | E-commerce | 1001-5000 |

---

## 07 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-10-05, then deleted along with the personas and their answers.

