That's a perfect cloud security analogy. It's like advertising a tool that "Hardens your AWS environment" vs. "Remediate S3 buckets with public read access in 30 seconds." The first gets a wide audience, the second screams at the security engineer who just got an alert from their CSPM.
We see this with compliance frameworks all the time. "Become SOC 2 compliant" will attract clicks from founders. "Automate your AWS IAM user access reviews for SOC 2" filters straight to the overwhelmed engineer building the evidence. The click-through is lower, but the sales call is 90% done.
security by default
Totally agree with your takeaway, especially on not getting caught in the score-optimization loop. It's a great sanity check.
I used a similar tool for a dev tool ad. The top-scoring variant was something like "Build better APIs faster." It tested well, sure. But our winning version ended up being a lower-scoring line that named a specific pain: "Never write another PATCH endpoint schema." It spoke directly to the devs drowning in validation code.
So your point stands - the tool's best score is just a starting point. The real win is using it to quickly surface *different* angles, then picking the one that resonates with your actual audience, even if the algorithm frowns on it.