Cold outreach to security consultancies #99

Closed
opened 2026-09-23 10:46:10 +01:00 by cruelacid · 1 comment
Owner

Why

docs/launch-readiness.md names this as the largest untested assumption in the
whole project:

"no phase, stage or task anywhere involves a person outside this project… the
first ten conversations will teach more than that document does… it remains
the largest untested assumption behind the whole plan."

docs/commercial-model.md puts break-even at roughly ten paying accounts
against ~€36/month of fixed infrastructure. Ten. That is a conversations problem,
not a funnel problem, and no amount of posting substitutes for it.

Why security consultancies specifically

This is the one segment where "the server cannot read your notes" is a
contractual requirement rather than a preference. Engagement notes contain
client vulnerabilities, credentials and scope, under NDAs that routinely forbid
third-party storage the vendor can read. Relay disqualifies itself for these
buyers in its own public documentation.

They are also the only buyers who can use the second pillar. "The code that
encrypts your notes is on your disk — read it" is worth nothing to someone who
cannot read it, and close to decisive for someone who can.

What to do

Build the list — a method, not a list of invented names:

  • Search GitHub for public Obsidian pentest/OSCP vault templates and note the
    authors and their employers. There is a substantial corpus
    (b-3llum/pentest-notes, Obsidian4OSCP, Twigonometry/OSCP-Notes-Template,
    blue-pho3nix/pentesting_templates_obsidian).
  • Search consultancy engineering blogs for posts on note-taking or knowledge
    management. TrustedSec has one titled "Obsidian, Taming a Collective
    Consciousness"
    — unread, it 403s to automated fetches; read it by hand
    before treating it as evidence of anything.
  • Look at who is asking about collaborative Obsidian in r/netsec, r/Pentesting
    and the Obsidian forum.

One qualified lead already exists in public. Relay's own Obsidian forum
thread contains someone objecting "I would have to upload my vault to your
server with no privacy guarantees"
. That person stated our exact wedge, in
public, unprompted. Find them, and anyone who agreed.

The email: short, names their specific constraint, links /security rather
than /pricing, offers a call, does not pitch. Target ten replies, not a
thousand sends.

Constraints

  • This can start now, before the launch gates close. These are one-to-one
    conversations, not announcements — a rough edge costs nothing and what comes
    back shapes the product.
  • The audit question arrives within two emails. The answer is: not audited,
    designed to be audited, and here is how you audit it yourself — unminified
    client, published SHA-256 per release, scripts/verify-build.mjs reproducing
    it from source, key fingerprints comparable off-server.
  • Never "open source", never "audited", never "zero knowledge", never "we store
    no metadata". Never "more secure than Obsidian Sync" — Sync is E2EE too; the
    true claim is collaborative and private, which Sync is not and Relay is not.
  • Say what Relay does better when asked: Canvas multiplayer, SSO, RBAC, Git
    sync, an API, web account management, two years of hardening. "They are
    broader, we are private." That honesty is what makes the rest credible.
  • No claim of existing customers. There are none.
## Why `docs/launch-readiness.md` names this as the largest untested assumption in the whole project: > "no phase, stage or task anywhere involves a person outside this project… the > first ten conversations will teach more than that document does… it remains > the largest untested assumption behind the whole plan." `docs/commercial-model.md` puts break-even at roughly **ten paying accounts** against ~€36/month of fixed infrastructure. Ten. That is a conversations problem, not a funnel problem, and no amount of posting substitutes for it. ## Why security consultancies specifically This is the one segment where "the server cannot read your notes" is a **contractual requirement rather than a preference**. Engagement notes contain client vulnerabilities, credentials and scope, under NDAs that routinely forbid third-party storage the vendor can read. Relay disqualifies itself for these buyers in its own public documentation. They are also the only buyers who can use the second pillar. "The code that encrypts your notes is on your disk — read it" is worth nothing to someone who cannot read it, and close to decisive for someone who can. ## What to do **Build the list** — a method, not a list of invented names: - Search GitHub for public Obsidian pentest/OSCP vault templates and note the authors and their employers. There is a substantial corpus (`b-3llum/pentest-notes`, `Obsidian4OSCP`, `Twigonometry/OSCP-Notes-Template`, `blue-pho3nix/pentesting_templates_obsidian`). - Search consultancy engineering blogs for posts on note-taking or knowledge management. TrustedSec has one titled *"Obsidian, Taming a Collective Consciousness"* — **unread, it 403s to automated fetches; read it by hand before treating it as evidence of anything.** - Look at who is asking about collaborative Obsidian in r/netsec, r/Pentesting and the Obsidian forum. **One qualified lead already exists in public.** Relay's own Obsidian forum thread contains someone objecting *"I would have to upload my vault to your server with no privacy guarantees"*. That person stated our exact wedge, in public, unprompted. Find them, and anyone who agreed. **The email**: short, names their specific constraint, links `/security` rather than `/pricing`, offers a call, does not pitch. Target ten replies, not a thousand sends. ## Constraints - This can start **now**, before the launch gates close. These are one-to-one conversations, not announcements — a rough edge costs nothing and what comes back shapes the product. - **The audit question arrives within two emails.** The answer is: not audited, *designed* to be audited, and here is how you audit it yourself — unminified client, published SHA-256 per release, `scripts/verify-build.mjs` reproducing it from source, key fingerprints comparable off-server. - Never "open source", never "audited", never "zero knowledge", never "we store no metadata". Never "more secure than Obsidian Sync" — Sync is E2EE too; the true claim is *collaborative and private, which Sync is not and Relay is not*. - **Say what Relay does better when asked**: Canvas multiplayer, SSO, RBAC, Git sync, an API, web account management, two years of hardening. "They are broader, we are private." That honesty is what makes the rest credible. - No claim of existing customers. There are none.
cruelacid added this to the Marketing project 2026-09-23 10:48:13 +01:00
Author
Owner

Moved to the Vikunja board as NEC-75: https://projectron.nerchure.com/tasks/75

Moved to the Vikunja board as **NEC-75**: https://projectron.nerchure.com/tasks/75
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#99
No description provided.