Between landing on your site and contacting you, a serious buyer runs a quiet assessment. They rarely describe it as such, and they almost never tell you the result. They simply leave, or they don't.
The assessment is about whether you look like a real company that will still exist in two years and can be safely given data, money, or a dependency. It is not about design.
The order they check in
Buyers do not work through a formal list, but the sequence is consistent enough to plan around.
1. Is anyone actually here?
The fastest signal is evidence of recent human activity. A blog whose latest post is eighteen months old, a copyright notice showing a past year, a “careers” page with no roles, a changelog that stops abruptly — each says the same thing, and it is not a good thing.
This check costs the buyer about four seconds and it is the one most often failed.
2. Who are you?
An About page with no names on it reads as evasive. Buyers look for real people, real roles, and ideally a real legal entity. They are not necessarily looking for an impressive team — they are looking for an accountable one.
A registered company name somewhere on the site does a surprising amount of work here. Its absence is conspicuous to anyone who has been burned before.
3. What happens to my data?
A privacy policy that exists, is specific, and is dated. A terms page that matches the product actually sold. For anything touching business data, a buyer will look for a security page — and increasingly, for whether you have anticipated a security questionnaire at all. See what to have ready before it's asked.
4. What does this cost?
Hidden pricing is read as one of three things: expensive, negotiable, or not yet decided. All three cost you buyers at this stage, and the third is the most damaging.
Published pricing is not always possible. Published ranges, or a clear statement of the pricing model, usually are, and they close most of the gap.
5. Has anyone else done this?
Named customers, specific outcomes, third-party reviews. The operative word is specific. “Trusted by leading companies” above a row of grey logos is understood by every experienced buyer as a claim with nothing behind it.
The asymmetry that makes this worth fixing
Trust signals are cheap to add and expensive to lack, and the loss is invisible. Nobody emails to say they left because your privacy policy was three years out of date. The deals you lose here never enter your pipeline, so they never appear in your win/loss analysis, and the problem is therefore self-concealing.
This is the core reason trust work gets deprioritised: everything else has a measurable cost of inaction, and this does not.
The signals that carry the most weight per unit of effort
Ranked by what they buy you relative to what they cost:
- A current date somewhere visible. A recent post, a changelog entry, an accurate copyright year.
- Named humans. Even two or three, with real roles.
- A specific, dated privacy policy. Generic boilerplate is better than nothing but not by much.
- A pricing model, stated plainly. Even without numbers.
- One detailed customer story. One real story outperforms twelve logos.
- A working contact route. An address that receives mail and is answered.
None of these require a redesign. Most are an afternoon. We look at which of them actually move a deal forward in trust signals that reduce deal friction.
What buyers discount
Worth knowing where effort is wasted:
- Unexplained badges. A compliance logo with nothing behind it is now background noise, and a fabricated one is a serious problem.
- Anonymous testimonials. “Great product! — CTO, Fortune 500 company” is read as invented, usually correctly.
- Vague scale claims. “Thousands of users” without a number invites the reader to assume the lowest plausible one.
- Stock imagery of teams. Recognisable, and it undercuts the page it sits on.
Auditing your own site
The difficulty is the same as with any self-assessment: you cannot un-know your own company. You look at the About page and see the team; a stranger sees three sentences and no names.
A workable substitute is to open your site in a private window and give yourself ninety seconds to answer four questions: Who runs this? Is it still maintained? What does it cost? What happens to my data? Anything you cannot answer, a buyer cannot either.
Our Trust & Security Audit runs this assessment from the outside — a passive external read of public trust signals, policy surface and questionnaire readiness, with each gap ranked and a fix plan. It is not a penetration test and involves no intrusive testing.