The Methodology
The CISO Filter™ Methodology
Version 1.0
·
Published July 2026
·
Gauteng, South Africa
·
LEX/METH-001
Most agencies have a style. We have a methodology — documented, versioned, and applied identically to every engagement. This page is the canonical reference.
We test your messaging the way an attacker tests your systems: assume nothing, verify everything, and find the weak points before your market does. Four phases, in order, every time. Each phase takes a defined input, runs a defined procedure, and produces a defined output — the output of one phase is the input of the next.
Every statement your company makes in public goes on the table. "Military-grade encryption." "Seamless integration." "AI-powered detection." Nothing is exempt, and nothing is assumed to be fine because it has always been there.
- Input
- Every public-facing claim — homepage, product pages, sales deck, email sequences, one-pagers.
- Procedure
- Verbatim extraction, then classification. Each claim is pulled out of its context exactly as written and classed as one of four kinds: provable (evidence exists and can be shown), demonstrable (a buyer can watch it happen), specifiable (it can be made concrete enough to test), or unfalsifiable (nothing could ever prove it wrong — which means it carries no information).
- Output
- The claim inventory — a complete, classified list of everything your marketing asserts.
- Discipline
- Claims are extracted verbatim, never paraphrased. Paraphrase introduces the auditor's reading before the analysis has begun — you end up auditing what you thought the page said, which is always more coherent than what it actually said.
A claim is only as strong as the evidence a skeptical buyer could actually check. This phase asks, claim by claim, the question a CISO silently asks on the first read: prove it.
- Input
- The claim inventory from Phase 01.
- Procedure
- Each claim is interrogated against the evidence the buyer could actually check — documentation, a demo, a trial, the architecture, published research. Claims that can't survive that interrogation are flagged as attack surface: places where a skeptical reader gains a reason to distrust the whole page.
- Output
- The proof gap map — which claims stand as written, which need evidence attached, and which have to go.
With the weak claims cleared, the message is rebuilt from what survives — and what survives is almost always more persuasive than what it replaces, because it finally says something a buyer can test.
- Input
- The proof gap map, and everything Phase 02 confirmed you can actually prove.
- Procedure
- The messaging hierarchy is reconstructed mechanism-first: what the product actually does leads, specificity replaces adjectives, and every claim carries its evidence with it. The one true thing you can own goes at the top; everything else supports it.
- Output
- The rebuilt messaging system — hierarchy, claims, and evidence, as one structure.
Phase 04
Objection Pressure-Test
Security messaging isn't read by one person. It's read by a buying committee whose job is to find reasons to say no. The rebuilt system is tested against them before it ships.
- Input
- The rebuilt messaging system from Phase 03.
- Procedure
- The messaging is run against the real objections of the security buying committee: the CISO ("prove it"), the practitioner ("will this actually work in my stack"), procurement ("why this price, why this vendor"), and the incumbent question ("why not the tool we already have"). Anything that fails goes back to Phase 03.
- Output
- The hardened final system — messaging that has already survived the arguments it will meet in the market.
Reference
The stamp taxonomy
Phases 01 and 02 end with every extracted claim carrying exactly one stamp. The stamps are the vocabulary of the audit: a finding is not an opinion about a sentence, it is a classification with a stated test behind it — which means you can disagree with a stamp on the record, using the same test we used.
Scroll the table sideways →
The five stamps: definition, the test that applies it, a worked example, and what a security buyer takes away.
| Stamp |
Definition |
The test |
Example |
The buyer concludes |
| UNFALSIFIABLE |
No observation could disprove it, so it carries no information. |
Can you imagine evidence that would contradict this? |
next-generation platform |
Nothing. The sentence deposits no meaning. |
| NO MECHANISM |
An outcome is stated; the method never is. |
Can you explain what the product does, not what it achieves? |
stops threats before they happen |
Every competitor says this. |
| UNVERIFIABLE |
Specific, possibly true, but the buyer cannot check it. |
Could a prospect confirm this without taking your word for it? |
99.99% detection accuracy , no methodology given |
Possibly true. Defaults to discounting it. |
| EMPTY SUPERLATIVE |
A comparative with no comparison, baseline, or scope. |
Is it comparative — most, best, fastest, leading, world’s first, -grade? If so, and no comparison set or metric is given, it is an empty superlative even where it is also weakly unfalsifiable. |
the most advanced XDR |
The vendor is hoping nobody asks. |
| SOUND |
Specific, mechanism-bearing, checkable. It survives. |
All four tests above, passed. |
flags lateral movement in under 90 seconds |
This one is worth a follow-up question. |
SOUND exists because an audit that only finds faults is a sales document, not a diagnostic. If nothing on your page survives, either the page is unusually bad or the auditor is selling you a rebuild. Knowing which claims already work is the part that tells you what to protect.
Precedence — how ties are broken: one stamp per claim. Where two apply, the more fundamental failure wins: NO MECHANISM outranks UNVERIFIABLE, and UNFALSIFIABLE outranks EMPTY SUPERLATIVE. The exception is the comparative test above, which is why military-grade
is stamped EMPTY SUPERLATIVE rather than UNFALSIFIABLE. If we cannot say in one sentence why one stamp applies rather than its competitor, the stamp is wrong — and the competing stamp gets recorded against the claim, because that record is where the taxonomy gets sharpened.
Stamps describe the claim — never the product, the company, or the people who wrote it. This claim cannot be verified
is analysis. This product probably does not work
is something else entirely, and we do not do it.
Reference
The scorecard
Five dimensions, each scored 1–10, each with written anchors so a score means the same thing in your audit as in everyone else's. The anchors below describe what a 3, a 7 and a 9 look like — the points where the difference is worth arguing about.
Claim Integrity
Do the claims survive a sceptic reading them line by line?
- 3
- Most claims are unfalsifiable or unverifiable. The page asserts continuously and evidences nothing.
- 7
- Claims are mostly specific. A handful of superlatives and one or two unbacked numbers remain.
- 9
- Every claim is either checkable by the reader, or explicitly framed as a design goal rather than a delivered result.
Mechanism Clarity
After one read, can the reader say what the product actually does?
- 3
- The reader can describe the outcome but not the method. The product could be anything in the category.
- 7
- The mechanism is stated, but arrives late or sits underneath a layer of category language.
- 9
- A practitioner could explain the mechanism to a colleague, in one sentence, from the page alone.
Audience Precision
Is this written to a named reader, or to the category in general?
- 3
- Addressed to "security leaders". No single reader is spoken to, so no reader feels spoken to.
- 7
- One primary audience is clear. The rest of the buying committee is left to work out their own stake.
- 9
- Each section knows who it is for and what that specific reader needs in order to move.
Proof Architecture
Does the evidence appear where the scepticism peaks?
- 3
- Proof is absent, or quarantined on a resources page the sceptical reader never reaches.
- 7
- Proof exists and is credible, but sits well after the claims it was meant to support.
- 9
- Every high-risk claim carries its evidence within a screen of itself, in the reader's path.
Conversion Logic
Is the next step obvious, and has the page earned it?
- 3
- Competing calls to action, or a single one asking for more commitment than the page has earned.
- 7
- A clear primary action, but the reader arrives at it with the main objection still unhandled.
- 9
- One primary action, positioned directly after the specific objection that would otherwise block it.
The calibration rule: the scale is absolute, not relative to your competitors. A seven is a seven whether or not everyone in your category scores four. Scoring against the category would tell you how you rank among pages a CISO already distrusts — which is not information you can act on.
Scope
What this method does not do
The audit assesses messaging against communication craft and your stated audience. Four things it does not do, stated here so nobody has to discover them on a call:
- It does not measure live conversion data. We assess the page, not its analytics.
- It does not assess the security of your product. We audit words, not systems.
- It does not verify that your technical claims are true. We flag which ones a buyer cannot check; confirming them is your engineering team's work, not ours.
- It does not guarantee a commercial result. Pipeline depends on your offer, price, market and timing — most of which the page does not control.
A method that claimed to do all four would fail its own Phase 02. Publishing the limits is not modesty; it is the same test applied to us.
The mechanism
Run a headline through The CISO Filter
A security headline, audited the way the filter audits every line of a page: each claim stamped with the way it fails, then the sentence rebuilt.
LEX/FILTER · v1.0 · TEMPORARILY OFFLINE
The interactive filter is down for recalibration. Version 1.0 classified two phrases in a way that contradicts the precedence rule published in the methodology: one stamp per claim, and the more fundamental failure wins. We found it, so we pulled it.
It returns when the dictionary matches the published taxonomy. The methodology itself is unchanged and readable in full.
→ Read the methodology
→ See a completed audit
Stamped against the precedence rule — including the two phrases v1.0 got wrong.
Sentinark is an
AI-poweredNO MECHANISM,
next-generationUNFALSIFIABLE
threat detection platform delivering
military-gradeEMPTY SUPERLATIVE
security with
seamlessNO MECHANISM
integration.
4 of 4 phrases carry no verifiable information.
The rebuild
Sentinark flags lateral movement inside your network in under 90 seconds — the attack phase your EDR watches least. Deploys as a single sensor. No agent sprawl.
A completed audit — reconstructed illustration.
That is one sentence. The Breach-Grade Messaging Audit is this, claim by claim, on your entire page — with the rewrite done for you.
Get the audit — $500
See the methodology run on your messaging
The Breach-Grade Messaging Audit is the CISO Filter applied to your homepage or primary sales page — fixed price, fixed scope, one week.