Controls and assurance are different
It is reasonable for a public site to describe how a product is intended to make decisions: external shares expire, policy can deny an action, a hold can block deletion, audit events remain queryable. Those are control behaviours that can be demonstrated.
A certification, penetration-test result or cryptographic assurance statement is different. It has scope, dates, evidence and often contractual context.
Precision leaves room for due diligence
Keeping the homepage conservative does not mean avoiding security detail. It means putting the detail in the right place. A technical evaluator can ask for architecture, algorithms, independent assessments, availability commitments and operational procedures under the current evaluation process.
The public page should not freeze an outdated answer into a permanent slogan.
Avoid language that cannot be falsified
Terms such as “military-grade”, “unhackable” or universal compliance claims sound confident precisely because they are hard to test. Better language describes the boundary, the expected behaviour and the evidence available.
That makes both buyers and engineers better able to challenge the product in useful ways.
Keep claims supportable
Describe controls that can be demonstrated. Publish certifications and customer references only when they are current, scoped and approved for public use.