Red flags that get a creator rejected in vetting

Influous vets every creator by hand. We are pre-launch, so what follows is a description of our standard rather than a report on a mountain of applications. We would still rather publish the standard than let people guess at it.

Rejection in creator marketing is normally silent. You apply, you hear nothing, and you never learn whether the problem was your audience size, your niche, or something you could have fixed in an afternoon. That is a bad experience for the creator and it makes the market harder to trust for everyone. So here is the list.

Identity we cannot verify

We check that a person is who they say they are. That means verifiable current or former employment, and at least one piece of traceable public work: a conference talk, a CVE credit, a maintained repository, published research, a technical blog with a history.

Pseudonymous researchers are welcome. Some of the best work in this field is published under a handle, and we are not going to demand a legal name from someone whose threat model rules it out. What does not pass is a handle with nothing verifiable behind it. If the only evidence that your expertise exists is the account claiming it, we cannot put you in front of a brand that is about to send money.

Engagement that does not look human

We read comment sections. Bought followers are the obvious version of this problem, but the more common one is an engagement pod: the same twelve accounts leaving the same approving one-liners under every post, on a schedule.

What we look for instead is friction. People correcting you. People arguing about your methodology. Someone asking a follow-up question that only a person who has actually run the tool would think to ask. A large account with a dead comment section is worth less to a brand than a small one where engineers show up to disagree.

Borrowed expertise

Some patterns that end an application:

  • Restating someone else’s research without crediting them.
  • A feed of advisory summaries with no added analysis, no reproduction, no opinion.
  • Generated explainers on subjects the author plainly does not work in, which read fluently and get the operational details wrong.
  • Claiming credentials, certifications, or CVE credits that are not yours.

The first three are correctable with attribution and a narrower focus. The last one is a permanent no. Falsified credentials are the single thing we will not revisit.

A history of undisclosed paid posts

We look at past sponsored content. If a post was clearly paid and carries no #ad, no “sponsored”, nothing a reader could reasonably notice, that is a problem we have to raise. The FTC’s position is that a disclosure has to be clear and hard to miss, and the UK and EU regulators take similar lines. A creator who has run paid content unlabelled either does not know the rules or decided they did not apply. Both are fixable. We want to see the fix before a campaign, not during one.

Conflicts you did not mention

Plenty of technical creators have day jobs at vendors. That is usually part of why they are worth reading. It is not a disqualifier.

Not telling us is. Promoting a direct competitor of your employer, reviewing a product your company resells, holding equity or an advisory seat with a sponsor’s rival: none of these are automatically fatal, and all of them are damaging when they surface halfway through a campaign. So we ask upfront about employment, advisory roles, equity, and bug bounty relationships. Withholding one of those is a trust problem, and trust is the only thing we are actually selling.

Fear as the business model

There is a genre of security content whose whole move is to make the reader feel unsafe and then gesture at a purchase. Breach counts with no context. Threat inflation. A vulnerability described as unstoppable when a patch shipped last week.

Practitioners recognise it instantly, and a brand that sponsors it inherits the credibility hit. We would rather not broker that transaction.

Things that are not red flags

Worth being explicit, because these are what people worry about most:

  • A small audience. Four thousand of the right practitioners beats four hundred thousand of the wrong ones.
  • A narrow niche. If you only write about Kubernetes admission control, that is a feature.
  • Posting rarely. Six good posts a year is a fine cadence.
  • Being hard on vendors. Including on sponsors. Creators who name limitations are the ones whose recommendations carry weight.
  • Rough production. A terminal recording with no editing is fine. We are vetting substance, not polish.

Being declined is not a verdict

Almost everything above is a fixable state rather than a permanent judgement. Add attribution. Leave the pod. Label the old paid posts, or at minimum label the next one. Tell us about the advisory seat. When we decline someone, we say what failed and what would change the answer, and we mean it when we say apply again.

Manual vetting is slow and it does not scale gracefully, which is the trade we have chosen. A brand should be able to assume that anyone they find through us has been checked by a person who understood what they were looking at.

If you write for security practitioners and none of the above worries you, apply as a creator at influous.io. If something on the list does worry you, email info@influous.io and ask. We would rather answer the question than have you assume the answer.

Follow

Be in the founding cohort

One managed campaign, run end to end

Influous runs influencer campaigns for security and tech brands with hand-picked, vetted creators. Pre-launch, founding cohort forming now.

Discover more from Influous

Subscribe now to keep reading and get access to the full archive.

Continue reading