Koi's Confess Your Sins

A quick note: Everything I’m sharing here is my subjective take on Koi’s Confess Your Sins campaign as I’m not privy to their performance metrics or strategy. The recommendations at the end are offered with deep respect for the Koi marketing team and is purely a thought exercise in how I might have approached certain elements differently.
I have a confession to make… sorry I had to.
I’ve been studying marketing campaigns in the security space for nearly a decade. Hundreds of them. I’ve seen a lot. And it’s very rare for me to think, “If I gave out scores, this would receive a perfect score.”
Not because there aren’t many great campaigns. There are. But because the standard for a perfect score should be impossibly high. Think of it like Dave Portnoy reviewing pizza. He’s been to thousands of places. He has a number for everything. But a perfect 10? That happens maybe once in a long while, and when it does, you know he means it.
Koi’s Confess Your Sins campaign is one of my few perfect 10s.
Let me tell you why.
First, Who is Koi?
Before I get into the breakdown, some context. Koi is an enterprise security company that gives orgs complete visibility and control over every piece of software their teams rely on: extensions, packages, apps, and AI models.
In February 2026, Palo Alto Networks announced its intent to acquire Koi for $400 million. I mention that not as a footnote but as important framing. This campaign did not exist in a vacuum. It was part of a go-to-market motion that helped build enough market credibility and momentum to attract one of the largest acquirers in the industry at a mammoth number.
Keep that in mind as we walk through everything Koi did here.
What Koi Was Launching and Where
The Confess Your Sins campaign was built to announce the launch of Koidex, specifically on Product Hunt. If you are not familiar with Product Hunt, here is the short version: it is a platform where makers launch new products to a community of early adopters, developers, investors, and tech enthusiasts.
For a security company, launching on Product Hunt is a deliberate signal: we are building something developers and practitioners will actually want to use, not just something a CISO will buy.
Koidex is not Koi’s core enterprise product. It is a free, no-setup tool built to answer one very specific question: “Is this safe to install?” It covers extensions, packages, and AI models across VS Code, JetBrains, npm, and Hugging Face. That scope is telling. Those are developer environments. This is a tool built for the people writing code and installing packages every single day, not the security team managing policy from a dashboard.
The strategic logic here is product-led growth, and Koi is executing it almost perfectly. You get the individual practitioner to adopt a free, lightweight version of your product. They experience the value firsthand. They become an internal champion. And they pull the enterprise deal from the bottom up rather than a sales team pushing it from the top down.
But there is a second layer here that makes this even more interesting. The Koidex audience, developers installing packages and running AI models in Cursor and Windsurf, are not just future internal champions. They are the exact people creating the risk that Koi’s enterprise product is designed to address.
So Koidex is simultaneously a PLG wedge and a way for Koi to make the problem visceral and personal to the people closest to it. You are not telling a developer that software supply chain risk is a problem. You are showing them, in their own environment, in real time.
What Koi Executed Brilliantly
The Video is a Masterpiece
Let’s start with the campaign video, because it is exceptional and I want to give it the attention it deserves.

The setting is a confessional booth inside a Catholic church. The video rotates through four people confessing their sins, which turns out to be the software they installed that happened to be malware. The music is high-tempo orchestral, the kind you would hear in a thriller. The lighting is dark and cinematic. And in the top left corner of the first frame, in small yellow text: “*Based on a true story.”
But here is what I think is the most important creative decision in the entire video. A confessional is a place where you admit something you know you should not have done. That is the exact emotional state Koi wants their audience in when they think about unsafe software installs. “I grabbed it from the Chrome Web Store” is not a technical confession. It is a human one. And every developer watching that video has done exactly that. The setting makes the behavior feel recognizable and slightly shameful, without ever being preachy or accusatory about it.
That distinction matters enormously in security marketing. We are constantly telling security leaders and practitioners they are doing something wrong. When we do it in an accusatory way, we put people in a defensive position. And a defensive person is not open to hearing what you are saying, let alone buying what you are selling. Koi accomplished something most security marketers never manage: they made their audience feel the weight of the problem without ever making them feel attacked.
There is a concept in psychology called benign violation theory, one of the most widely accepted explanations for why things are funny. Something is funny when it is simultaneously a violation of how things should be and somehow non-threatening. The Koi mascot sitting in the priest’s chair is exactly that. It is absurd. It violates every expectation the setting has built. And that absurdity releases all the tension the thriller music and dark confessional just created. The humor lands so hard because the fear was real a moment earlier. That is not an accident. That is extraordinary creative judgment.
And then there is the sequencing. Koi waited. They built tension, built the story, built the emotional context, and only then, at the 38-second mark, revealed the product. By the time Koidex appears on that laptop screen, you already understand exactly why you need it. The product intro is not an interruption. It is a resolution. The campaign tagline lands, the product name is introduced, a clean one-liner explains what it actually does, and the CTA drives you directly to Product Hunt with “Now live on Product Hunt.” Not “learn more.” Not “click here.” A specific, action-oriented directive that speaks the exact language of the audience they are trying to reach.
Security marketing is known for leaning too hard on fear. Fear without relief is just exhausting. Koi neutralized that fear with humor, and the result is a video that makes you feel something and then gives you somewhere to go with it.
The Product Hunt Page Was Compounding Execution at Its Best
Getting someone to click through to your Product Hunt page is only half the job. What they find when they get there is the other half, and this is where teams typically fall short. Not Koi.
What I like to think of as “Compounding Execution” is the discipline of doing a large number of small tactical details really well. No single detail makes or breaks the launch. But they accumulate into something that feels credible, complete, and worth upvoting.
Koi’s Product Hunt page had all of it: crystal-clear messaging that answered “what does this actually do,” well-designed carousel images that spoke directly to Koidex’s value props, correct tags, and the full team listed. That team listing matters. It signals to the Product Hunt community that this launch had real organizational weight behind it. It was not delegated down.
The founder comment from Amit Assaraf is another detail worth mentioning. He wrote that Koi’s research team published a harmless lookalike VS Code theme and saw installs from large-company networks within 30 minutes. That is not a statistic. That is a proof of concept with a story inside it. And the line he ended with: “one-click install needs one-click due diligence.” That is genuinely great copywriting. It is the kind of line that makes you stop scrolling.
The Koidex Page Is a Complete Conversion Journey
The Koidex page is an incredibly well-architected product page.
First, the search bar in the hero section. The moment you land on this page, you are not reading about what Koidex does. You are doing what Koidex does. That is the difference between telling someone your product is fast and handing them the keys.
Koi skipped the pitch entirely and went straight to the proof. And look at what the search bar surfaces before you even type anything: real extensions with real names, real install counts, real publisher info. The product is demonstrating its own depth and breadth on first contact. You only build a page like that if you genuinely believe what you built is good enough to sell itself.
Below the search bar sits “Catch of the Day,” a live feed of malware caught in the wild. Real extension names. Real install counts. Things that real people have installed millions of times, all flagged as critical malware. There is a concept in behavioral psychology called the availability heuristic, where people assess the likelihood of a risk based on how easily a concrete example comes to mind. Koi is manufacturing that availability on demand, right on their product page. Every entry in Catch of the Day is simultaneously a proof point that Koidex works and a reason to come back to the page.
The research section that follows is credibility infrastructure. Original threat research with named campaigns, specific findings, and real numbers tells the developer audience, who are deeply skeptical of vendor marketing, that Koi is not just a product company. They are a research org that built a product around what they discovered. That is a fundamentally different and more trusted positioning.
One more detail worth calling out: Koidex has its own branded placement in the main website nav. It is not buried under a products dropdown. It is front and center, with its own distinct visual treatment. It is not uncommon for security marketers to launch something big and then make it easier to find Bigfoot than to find it on the website. Koi made sure that was never the case.
The Employee Advocacy Strategy That Left Me in Awe
I want to spend real time on this because it solves a problem that so many marketing teams wrestle with.
Most employee advocacy programs fail in one of two ways.
Either employees repost stale company content and the whole thing feels like an obligation rather than a genuine voice.
Or a handful of employees become “thought leaders” for the company, build a following on the back of the company’s story and resources, and then leave. That looks bad on the company and eventually undermines the credibility of the person too. I have watched people jump two or three times, parrot each founder’s story in turn, and lose the audience they spent years building in the process.
What Koi did was something entirely different. They gave every employee the same creative framework and then completely got out of the way.
The structure was identical across every post: a personal confession, a pivot to what that confession means from a security perspective, the Koidex intro, and the Product Hunt CTA. But the stories were entirely their own.

Tom, a cybersecurity specialist, confessed that the marketing team forces him to wear the fish costume and walk around the city in the heat. Tuval, a security researcher, confessed he picked dev tools the same way he used to pick dates: a nice profile picture, a few good reviews, and “seems legit.” Lotan confessed she installs software the way she picks restaurants: stars, vibes, and “looks fine.” Ben confessed he had been hoarding AI browser extensions the same way he used to collect Pokémon. And Gal, shared a story about almost going to jail in the Israeli army for making an omelette in a pan intended for meat.
These are not company talking points. These are human beings. And that is precisely the point.
What Koi pulled off here is what I would call structured authenticity. They gave employees a creative container: the confession format, the campaign photography, the confessional booth imagery. Inside that container, everyone told a genuinely personal story. The result is that the campaign scaled across a dozen people without ever feeling like a campaign. Each post felt like something that person actually wanted to write. Because they probably did.
What I Might Have Explored Differently
I want to be honest about something before I get into this section. Finding two things to improve in this campaign felt a little like being handed a Michelin-starred meal and being asked what I would season differently. But here we are.
Collect the Reviews While the Momentum Is Hot
Koidex launched as the #1 Product of the Day on Product Hunt. And the Product Hunt page still has no reviews. For a product that is free and requires no setup, collecting reviews is the lowest-friction ask you can make of a new user. A handful of authentic reviews on that page would have extended the social proof flywheel well beyond launch day and turned the Product Hunt page into a long-term acquisition asset. The momentum was there. Capturing it in review form is the natural next move.
Turn the Confession Framework Into a Community Ritual
The idea I keep coming back to is this: the Confess Your Sins framework is so strong and so extensible that it should not have ended with the launch. The confession format, the visual language, the emotional resonance, all of it was already built and already proven.
Imagine a rolling series where real users and practitioners share their own software install confessions, user-generated content that feeds directly back into the campaign and into Koidex adoption. The infrastructure existed. The creative container existed. The audience was primed. Koi had everything they needed to turn a brilliant campaign into a living community ritual. That is the one move I would have made.
Bring the Confession to Life with a Koi Plushy
The confession framework Koi built is so strong and so recognizable that it had the potential to live beyond screens entirely.
Imagine a limited-edition Koi the Fish plushy, shipped to practitioners, customers, and influencers with one simple ask: confess your worst software install sin to Koi, post it, tag us. The physical product becomes the prop. The campaign becomes the ritual. And every post is a piece of user-generated content that extends the reach of "Confess Your Sins" without Koi spending another dollar on production.
There is something uniquely powerful about bringing a physical object into a digital campaign, it creates a moment that people actually want to share. A plushy sitting on a developer's desk is also a brand impression every single day, which no banner ad or sponsored post can replicate. This one was right there for the taking.
The Bottom Line
I have been writing these posts for a while now and I do not reach for perfect scores lightly. But Koi’s Confess Your Sins campaign earned it. The creative was exceptional. The strategy was coherent from the campaign video all the way through to the product page. The employee advocacy execution solved a problem most marketing teams never crack. The PLG motion was thoughtfully constructed. And the whole thing was executed with a level of craft and attention to detail that is so rare.
Three small gaps do not change the grade. They represent the most exciting part of what comes next. The foundation is as strong as anything I have seen in cybersecurity marketing.
Every week, I write about a marketing campaign in the cybersecurity software space that stands out strategically and/or has creative execution worth studying. And every quarter, I select three “Campaigns of the Quarter” where the marketers who led the campaigns receive a free, personalized Funko Pop. Yes, I’m serious. Here’s mine as proof:
If you’ve led a campaign you’re proud of or know someone who has, message me on Substack or LinkedIn to submit it. I want to see what you’re building.
Originally published on Campaign Telemetry.
Read on Substack



