Cold outreach to security consultancies #99
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#99
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
docs/launch-readiness.mdnames this as the largest untested assumption in thewhole project:
docs/commercial-model.mdputs break-even at roughly ten paying accountsagainst ~€36/month of fixed infrastructure. Ten. That is a conversations problem,
not a funnel problem, and no amount of posting substitutes for it.
Why security consultancies specifically
This is the one segment where "the server cannot read your notes" is a
contractual requirement rather than a preference. Engagement notes contain
client vulnerabilities, credentials and scope, under NDAs that routinely forbid
third-party storage the vendor can read. Relay disqualifies itself for these
buyers in its own public documentation.
They are also the only buyers who can use the second pillar. "The code that
encrypts your notes is on your disk — read it" is worth nothing to someone who
cannot read it, and close to decisive for someone who can.
What to do
Build the list — a method, not a list of invented names:
authors and their employers. There is a substantial corpus
(
b-3llum/pentest-notes,Obsidian4OSCP,Twigonometry/OSCP-Notes-Template,blue-pho3nix/pentesting_templates_obsidian).management. TrustedSec has one titled "Obsidian, Taming a Collective
Consciousness" — unread, it 403s to automated fetches; read it by hand
before treating it as evidence of anything.
and the Obsidian forum.
One qualified lead already exists in public. Relay's own Obsidian forum
thread contains someone objecting "I would have to upload my vault to your
server with no privacy guarantees". That person stated our exact wedge, in
public, unprompted. Find them, and anyone who agreed.
The email: short, names their specific constraint, links
/securityratherthan
/pricing, offers a call, does not pitch. Target ten replies, not athousand sends.
Constraints
conversations, not announcements — a rough edge costs nothing and what comes
back shapes the product.
designed to be audited, and here is how you audit it yourself — unminified
client, published SHA-256 per release,
scripts/verify-build.mjsreproducingit from source, key fingerprints comparable off-server.
no metadata". Never "more secure than Obsidian Sync" — Sync is E2EE too; the
true claim is collaborative and private, which Sync is not and Relay is not.
sync, an API, web account management, two years of hardening. "They are
broader, we are private." That honesty is what makes the rest credible.
Moved to the Vikunja board as NEC-75: https://projectron.nerchure.com/tasks/75