# voice.md

## Communication Style

### Overall Tone and Personality
Manifest's brand voice is **authoritative, expert, and confident**, tempered with an **urgent and solution-oriented** approach. We address complex, high-stakes security challenges with gravitas and precision. While professional, the tone is direct and impactful, aiming to inform, educate, and empower our audience to act. There's an underlying sense of vigilance and a proactive stance against emerging threats.

### Key Stylistic Elements and Patterns
-   **Problem-Solution Framing:** Content consistently begins by highlighting a critical industry problem, risk, or gap, then pivots to how Manifest provides the definitive solution.
-   **Direct and Impactful Language:** We use strong, active verbs and concise sentences to convey urgency and clarity.
-   **Emphasis on Core Values:** Recurring themes include "visibility," "transparency," "continuous," "complete," "real-time," "at scale," and "proactive."
-   **Industry-Specific Jargon:** We speak fluently in the language of cybersecurity, AI, and compliance, assuming a knowledgeable audience (e.g., SBOM, AIBOM, VEX, FOCI, C-SCRM, zero-days).
-   **Cautionary Openings:** Blog post titles and introductions often use slightly alarmist or provocative language to capture attention and emphasize the severity of the issue (e.g., "Bugpocalypse Is Coming," "Life and Death").
-   **Data and Research Integration:** Claims are frequently supported by references to research, regulations, or specific events.

### Vocabulary Preferences and Word Choices
-   **Technical & Security:** SBOM, AIBOM, VEX, zero-days, supply chain, vulnerability, compliance, governance, provenance, risk mitigation, incident response, binary analysis, embedded code, GenAI, AppSec.
-   **Completeness & Control:** Complete, unified, continuous, real-time, at scale, proactive, eliminate, modernize, reinvent, inspect, inventory, analyze.
-   **Clarity & Understanding:** Transparency, visibility, uncover, insights, evidence.
-   **Impact & Severity:** Critical, massive, urgent, board-level, problem, gap, threat, impact, secure, protect, mitigate.

## Content Patterns

### Common Themes and Topics
-   Software supply chain security (open-source software, dependencies, third-party risk).
-   AI risk and governance (AIBOMs, Shadow AI, GenAI models, model provenance).
-   Regulatory compliance (FOCI, NDAA, EO 14028, NIST 800-218).
-   Vulnerability management and risk reduction strategies.
-   The necessity of transparency and visibility in complex digital systems.
-   Automation and efficiency in security and compliance workflows.

### Structural Approaches to Content
-   **Blog Posts:** Typically feature a compelling, problem-focused headline, an introduction that sets the urgent context, a detailed exploration of the issue, and then positions Manifest's role in the solution.
-   **Marketing Copy:** Leads with a clear value proposition, followed by key benefits, specific features, industry applications, and often includes quantifiable results or testimonials.
-   **Scannable Formats:** Utilizes bullet points, numbered lists, and clear headings to break down complex information (e.g., "essential 4-step checklist," "workflow for every user").
-   **FAQs:** Employed to directly address common questions and concerns, reinforcing understanding.

### Call-to-Action Styles and Patterns
-   **Direct and Clear:** "Get a demo," "Read the Research," "Learn more."
-   **Benefit-Oriented:** CTAs are often framed as the next logical step to address the identified problem or achieve a desired outcome.
-   **Educational:** "Download the report" for deeper insights and benchmarking.

## Audience Interaction

### How the Brand Addresses Its Audience
We address our audience (security leaders, AppSec teams, GRC analysts, executives in highly regulated industries) directly, often using an implied "you" or "your organization." We assume a high level of technical sophistication and a shared understanding of the gravity of software supply chain and AI risks.

### Level of Formality and Relationship Style
The relationship is one of a **trusted expert and essential partner**. Our tone is professional and authoritative, yet accessible enough to foster a collaborative and problem-solving dynamic. We avoid overly casual language, maintaining a serious yet helpful demeanor appropriate for critical security discussions.

### Engagement and Conversation Patterns
-   **Challenges Assumptions:** We often reframe conventional thinking to highlight deeper, often overlooked risks ("The real risk isn't open-source software, it's not knowing what you're running.").
-   **Provides Actionable Guidance:** Content frequently includes checklists, frameworks, or clear steps for immediate protection and long-term strategy.
-   **Leverages Credibility:** We use statistics, research, and testimonials to build trust and validate our insights.

## Guidelines & Examples

### Do's and Don'ts for Brand Communication
**DO:**
-   Be authoritative, confident, and precise in your language.
-   Frame content around critical industry problems and offer clear, actionable solutions.
-   Use technical, industry-specific language without excessive simplification.
-   Emphasize visibility, transparency, automation, and continuous improvement.
-   Highlight the urgency and business impact of security risks.
-   Use strong, active verbs to drive home points.
-   Support claims with data, research, or real-world examples (regulations, specific threats).

**DON'T:**
-   Dumb down complex technical concepts or shy away from necessary jargon.
-   Use overly casual, informal, or flippant language.
-   Be vague, abstract, or overly theoretical; be specific about problems and Manifest's role.
-   Over-promise or sound hyperbolic without clear evidence or backing.
-   Focus solely on features without connecting them to tangible benefits and problem-solving.

### Example Phrases and Expressions That Are "On-Brand"
-   "Uncover risk in the software and AI you build and buy."
-   "The OSS Bugpocalypse Is Coming."
-   "Software Supply Chain Security Is a Board-Level Risk."
-   "The real risk isn't open-source software, it's not knowing what you're running."
-   "Complete visibility and transparency."
-   "Manifest automates SBOM generation, manages AI and third-party risks, and enables continuous compliance at scale."
-   "Built for Highly Regulated Organizations."
-   "Prioritized, real-time visibility."
-   "Close the blind spot."
-   "Modernize TPRM," "Reinvent SCA," "Eliminate Shadow AI."

### Content Types and Formats the Brand Uses
-   Blog posts (thought leadership, educational content, industry analysis).
-   Marketing landing pages (product/solution overviews, feature deep dives).
-   Case studies and success stories.
-   Webinars and podcasts.
-   Press releases and news articles.
-   API and user documentation.
-   Research reports (e.g., "Beyond the Black Box").
-   FAQs.