Go-to-market programme #110

Closed
opened 2026-09-23 10:46:56 +01:00 by cruelacid · 1 comment
Owner

Tracking issue for the go-to-market programme. The strategy lives in
docs/go-to-market.md (#95) — this issue carries the checklist and the links.
Two copies of a strategy is one copy that goes stale.

The market

Security consultancies, red teams and independent pentesters. The one segment
where "the server cannot read your notes" is a contractual requirement rather
than a preference, and the only one that can actually verify the unminified
client. Small software teams are spillover, not the headline.

Why this is not a social media programme

Neither direct competitor does social media. Relay — 209,229 downloads — has a
Discord, a forum thread and a release-notes page; Peerdraft has a Discord. And
the arithmetic is against a funnel: 36 downloads, zero paying customers, and
break-even at roughly ten paying accounts.
Ten is a conversations problem.

docs/launch-readiness.md already names the gap: "no phase, stage or task
anywhere involves a person outside this project… it remains the largest untested
assumption behind the whole plan."

Blocks everything public

  • #94 Re-check launch gates A–C and reconcile README against Gate A

Nobody currently knows how far the hosted service is from launch. Gates A–C are
unticked but flagged stale; README.md:29 says the hosted service is live while
Gate A says the sync server runs on no host. Also unresolved: no live payment has
ever completed, and terms.md and privacy.md are still DRAFT.

Now — safe before the gates close (gate:pre-ga)

  • #95 docs/go-to-market.md — the strategy, private
  • #96 /roadmap and /changelog on nectenda.com
  • #97 Publish a what-we-do-not-protect-against page
  • #98 Write the security explainer
  • #99 Cold outreach to security consultancies
  • #100 Begin sustained participation in r/netsec
  • #90 Sustained participation in r/ObsidianMD
  • #101 Reserve the social handles and publish profiles
  • #102 Extend brand-raster.mjs with a brand/social target

Outreach and community participation start now deliberately. Cold emails are
one-to-one conversations, not announcements — a rough edge costs nothing and what
comes back shapes the product. And r/netsec gives accounts with no prior history
the most moderator attention, so participation has to begin months before the
post that matters.

Held until the gates close (gate:at-ga)

  • #89 An announcement thread on the Obsidian forum
  • #103 Show HN — the security model, not the product
  • #104 Submit to the Obsidian Roundup newsletter
  • #88 A comparison piece covering Relay, Peerdraft, Live Share and Nectenda
  • #91 Earned coverage
  • #105 YouTube creator outreach

One first impression per channel. Spend them in the same week so they compound,
and not before a security audience can follow a link without finding DRAFT
legals.

Deferred — the feedback board

  • #106 Self-hosted Fider at feedback.nectenda.com
  • #107 OAuth2 shim for board sign-in

Designed and costed, not being built now. Both issues carry the full design so it
is not re-derived — including why Featul was rejected, why the shim exists rather
than an OAuth provider inside packages/identity, and the two findings that
would otherwise be discovered the hard way: packages/identity/static/auth.js
never redirects the browser out, and a constant deviceId is what stops a board
sign-in revoking someone's vault session.

Until a board exists, feature requests go to hello@nectenda.com.

Surfaced by this work, worth fixing on their own

  • #108 snapshot.sh backs up one hardcoded database and still reports ok
  • #109 inventory.mjs reports ok for pins whose tag it cannot parse

Not marketing, and not labelled as such.

Message discipline

Everything in docs/positioning.md binds. Never "open source", never "audited"
(designed to be audited), never "zero knowledge", never "we store no metadata",
never "more secure than Obsidian Sync". No feature claimed that is not in the
shipped plugin. iOS is untested on a device. No users, customers or revenue
claimed — there are none.

Voice: sentence case throughout, no exclamation marks, success stated as fact.

Measuring

Ten paying organisations is the only number that matters, and at this scale
none of the others predict it well.

Tracking issue for the go-to-market programme. The strategy lives in `docs/go-to-market.md` (#95) — this issue carries the checklist and the links. Two copies of a strategy is one copy that goes stale. ## The market **Security consultancies, red teams and independent pentesters.** The one segment where "the server cannot read your notes" is a contractual requirement rather than a preference, and the only one that can actually verify the unminified client. Small software teams are spillover, not the headline. ## Why this is not a social media programme Neither direct competitor does social media. Relay — 209,229 downloads — has a Discord, a forum thread and a release-notes page; Peerdraft has a Discord. And the arithmetic is against a funnel: **36 downloads, zero paying customers, and break-even at roughly ten paying accounts.** Ten is a conversations problem. `docs/launch-readiness.md` already names the gap: *"no phase, stage or task anywhere involves a person outside this project… it remains the largest untested assumption behind the whole plan."* ## Blocks everything public - [ ] #94 Re-check launch gates A–C and reconcile README against Gate A Nobody currently knows how far the hosted service is from launch. Gates A–C are unticked but flagged stale; `README.md:29` says the hosted service is live while Gate A says the sync server runs on no host. Also unresolved: no live payment has ever completed, and `terms.md` and `privacy.md` are still DRAFT. ## Now — safe before the gates close (`gate:pre-ga`) - [ ] #95 `docs/go-to-market.md` — the strategy, private - [ ] #96 `/roadmap` and `/changelog` on nectenda.com - [ ] #97 Publish a what-we-do-not-protect-against page - [ ] #98 Write the security explainer - [ ] #99 Cold outreach to security consultancies - [ ] #100 Begin sustained participation in r/netsec - [ ] #90 Sustained participation in r/ObsidianMD - [ ] #101 Reserve the social handles and publish profiles - [ ] #102 Extend `brand-raster.mjs` with a `brand/social` target Outreach and community participation start now deliberately. Cold emails are one-to-one conversations, not announcements — a rough edge costs nothing and what comes back shapes the product. And r/netsec gives accounts with no prior history the most moderator attention, so participation has to begin months before the post that matters. ## Held until the gates close (`gate:at-ga`) - [ ] #89 An announcement thread on the Obsidian forum - [ ] #103 Show HN — the security model, not the product - [ ] #104 Submit to the Obsidian Roundup newsletter - [ ] #88 A comparison piece covering Relay, Peerdraft, Live Share and Nectenda - [ ] #91 Earned coverage - [ ] #105 YouTube creator outreach One first impression per channel. Spend them in the same week so they compound, and not before a security audience can follow a link without finding DRAFT legals. ## Deferred — the feedback board - [ ] #106 Self-hosted Fider at `feedback.nectenda.com` - [ ] #107 OAuth2 shim for board sign-in Designed and costed, not being built now. Both issues carry the full design so it is not re-derived — including why Featul was rejected, why the shim exists rather than an OAuth provider inside `packages/identity`, and the two findings that would otherwise be discovered the hard way: `packages/identity/static/auth.js` never redirects the browser out, and a constant `deviceId` is what stops a board sign-in revoking someone's vault session. Until a board exists, feature requests go to `hello@nectenda.com`. ## Surfaced by this work, worth fixing on their own - [ ] #108 `snapshot.sh` backs up one hardcoded database and still reports ok - [ ] #109 `inventory.mjs` reports ok for pins whose tag it cannot parse Not marketing, and not labelled as such. ## Message discipline Everything in `docs/positioning.md` binds. Never "open source", never "audited" (*designed to be audited*), never "zero knowledge", never "we store no metadata", never "more secure than Obsidian Sync". No feature claimed that is not in the shipped plugin. iOS is untested on a device. No users, customers or revenue claimed — there are none. Voice: sentence case throughout, no exclamation marks, success stated as fact. ## Measuring **Ten paying organisations is the only number that matters**, and at this scale none of the others predict it well.
cruelacid added this to the Marketing project 2026-09-23 10:48:13 +01:00
Author
Owner

Moved to the Vikunja board as NEC-86: https://projectron.nerchure.com/tasks/86

Moved to the Vikunja board as **NEC-86**: https://projectron.nerchure.com/tasks/86
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#110
No description provided.