Where they started
The product was solid and the mid-market was buying, but every deal above a certain size hit the same wall: the prospect’s security team sent over a questionnaire, and the answers lived nowhere public. Google their SOC 2 posture, their PCI scope, how reconciliation handled a failed settlement, and you found nothing. A payments buyer’s security reviewer told them, on a lost-deal call, that “we couldn’t find anything, so we assumed there was nothing.” Meanwhile the blog had 60 posts about product launches and funding news, tuned for press, not for the person quietly deciding whether the company was safe to route money through.
What we did
- Mapped the real security-review queries, not keyword-tool queries. We pulled the actual language buyers use (“SOC 2 Type II payments”, “PCI DSS scope reduction”, “settlement reconciliation controls”) from lost-deal notes and support tickets, then built a page for each. Low volume, high intent: these are read by two people and one of them signs the contract.
- Wrote the compliance content straight, with their security team. Each page answered a questionnaire item in full (what’s in scope, what’s attested, how the control works), reviewed by their CISO so it held up under scrutiny. This is what turned a stalled review into a link a rep could send.
- Placed the story in finance and payments press. 55 links over the year, weighted to trade outlets a procurement team recognizes. That credibility, more than the DR bump, is why the pages got trusted as answers.
- Rebuilt internal linking so the money pages caught the equity. The compliance hub pulled authority from the news archive that had been sitting idle, lifting rankings on the queries that actually mattered.
The traffic chart here is the least interesting thing on the page: a slow, steady climb from 9k to 16k. The number that mattered never showed up in Analytics: enterprise demo requests roughly quadrupled quarter over quarter, because deals stopped dying in a review nobody could answer.