I received this cold email after posting SurfaceMap on Indie Hackers:
"The risk is worse: security researchers may understand the tool, like the idea, and still not try it because the page does not remove enough trust risk."
At first I thought my landing page problem was explaining what SurfaceMap does.
The email made me realize the real problem was different.
In security, people don't adopt tools because they're impressed.
They adopt them because they trust them.
My homepage talked about features:
Subdomain discovery
Screenshots
Tech stack detection
Risk scoring
But it wasn't answering the questions security researchers actually have:
Does this run locally?
What data leaves my machine?
Is it safe to use?
Why should I replace my existing workflow?
So I rewrote a section of the landing page around trust and workflow instead of features.
Before:
"SurfaceMap finds subdomains, screenshots websites and generates reports."
After:
"Stop chaining tools. Start mapping surfaces."
Then I showed the contrast between the traditional recon workflow:
subfinder → httpx → nuclei → custom scripts → spreadsheets
and the SurfaceMap workflow:
surfacemap scan example.com → dashboard → insights
Most importantly, I added a clear privacy statement:
"Your scan results, screenshots, reports and metadata never leave your machine."
The feedback of one post completely changed how I think about positioning SurfaceMap.
Sometimes users don't need more features.
They need fewer reasons to hesitate.
Curious: what's the best piece of feedback you received?