1The market problem
Every company running LLM inference at scale has a cost line growing faster than revenue. Some of that growth is legitimate. Some of it is someone else monetizing their tokens.
| Layer | What it is | Examples |
|---|---|---|
| Relay market | Open-source OpenAI-compatible gateways repurposed as commercial transfer stations | one-api, new-api |
| Credit marketplaces | Sites brokering unused startup credits | AI Credits, AICreditMart |
| Bulk-discount routers | Claim "bulk pricing," likely acquiring supply elsewhere | CheapCredits, Tokvana, Neokens |
| Direct brokers | Individuals offering $100k/day in spend via email and Telegram | unnamed |
| Message boards | Reddit and Telegram channels moving credits | r/saasforsale, r/indiehackers |
The market is real and documented, but it's invisible to most buyers. That's a category-creation problem — and category creation is won with research, not cold calls.
2Who we sell to
The pain scales with inference spend. We segment by monthly LLM spend, not company size or vertical.
Inference is the core cost of goods. Reseller traffic directly inflates COGS — margin is existential.
| Tier | Profile | LLM spend | Entry point |
|---|---|---|---|
| 1 | AI-native companies — inference is the core cost of goods | $50k–500k+/mo | Founder or Head of Engineering |
| 2 | Established SaaS adding AI features — cost center not yet owned | $10k–100k/mo | VP Engineering or CFO |
| 3 | Model providers and API platforms — resellers steal their revenue | n/a — they are the supply | Trust & Safety, Fraud, Platform |
| 4 | Marketplaces and aggregators — reseller traffic shows up as buyer behavior | — | Risk / Trust & Safety |
Under $5k/mo LLM spend (no pain) · pure consultancies (no inference) · anyone who can't see their own token-level data.
3Positioning
LLM abuse and fraud detection. Not "API security." Not "bot management." Those categories have incumbents and buyers who think they're already covered. This one is new and unclaimed.
Positioning statement:
For companies running LLM inference at scale, Vectoral is the abuse detection layer that catches resellers, stolen keys, and free-tier farming before they hit your invoice — fusing browser signals and account signals into one verdict. Unlike bot-management tools that only see the client, Vectoral sees the account and the client together.
Three proof pillars
Objection handling
| Objection | Response |
|---|---|
| "We have Cloudflare / bot management" | Those see the client. Resellers use real browsers. You need the account signal too. |
| "We'd know if someone was stealing our tokens" | The research shows 3.6M monthly visits across ten relays. You wouldn't. |
| "We can't send traffic to a third party" | Self-hosted Docker in your VPC. Your traffic never leaves. |
| "Our spend is fine" | Show them the free-tier farming pattern. Most companies have it and don't know. |
| "Too early, we'll revisit" | Every month of delay is a month of leakage. Quantify it in their numbers. |
4Channel strategy
It's the only channel that creates the category and generates demand at the same time. Cold outbound can't do that.
The research already works — Simon Willison and CSA picked it up unprompted. The job is systematizing it.
- Publish one threat-research piece per month: relay market economics, token broker anatomy, free-tier farming, sybil ring structure
- Each piece ends with a "check your exposure" CTA → demo request
- Distribute via Hacker News, r/netsec, r/LocalLLaMA, LinkedIn, X, AI newsletters
- Target: 2–3 pieces that hit HN front page per quarter
Channel 2 — Signal-based outbound
Not list-based spray. Signal-based, small, high-relevance.
| Signal | Why it matters | Where to find it |
|---|---|---|
| Hiring AI/ML engineers | Scaling inference = scaling exposure | Job boards, LinkedIn |
| Public LLM cost complaints | Pain is conscious | HN, X, Reddit |
| Recent funding round | Budget plus scaling pressure | Crunchbase, TechCrunch |
| Launching a free tier | Free-tier farming risk | Product pages, PH launches |
Using one-api / new-api | Already in the relay ecosystem | GitHub stars, dependency graphs |
40–60 highly-qualified accounts per month — not 2,000.
Channel 3 — Partner and ecosystem
Channel 4 — Community presence
Hacker News comment threads on AI cost and abuse · r/LocalLLaMA, r/netsec, r/cybersecurity · AI engineering Discords and Slacks · conference talks at RSA, Black Hat, AI Engineer Summit.
5Outbound motion
Don't pitch the product. Pitch the audit. Nobody believes they have a token-reselling problem — so don't ask them to. Ask for 15 minutes to show them what we found.
Sequence — 6 touches over 14 days
- Day 1 — EmailReference their specific signal, the research, and offer an exposure read.
- Day 2 — CallOne call, one voicemail. Reference the email and the research by name, restate the 15-minute exposure read, and follow up by email either way.
- Day 3 — LinkedInConnect with a one-line note referencing the same signal.
- Day 5 — EmailSend the relevant research piece. No ask.
- Day 8 — EmailOne specific pattern from their stack — free tier, gateway, volume.
- Day 14 — EmailBreakup: "closing the loop, here's the research, reach out anytime."
- Every email references something specific about them. No templates that could go to anyone.
- Lead with the research, not the product. Research earns the meeting.
- Never say "I'd love to pick your brain." Ask for a specific 15 minutes.
- One CTA per touch. Always the same CTA: a 15-minute exposure read — on the call and in every email.
Run their public endpoints through Vectoral's detection and show them what reseller traffic looks like against their own traffic.
Costs nothing, proves the product, creates urgency. This is the single highest-converting motion available — it turns an abstract threat into their own data.
6Sales process
| Stage | Definition | Exit criteria |
|---|---|---|
| 1. Identified | Signal detected, account qualified | ICP fit confirmed, entry point identified |
| 2. Engaged | Reply received, conversation open | Exposure read scheduled |
| 3. Exposure read | Delivered findings from their traffic | Problem confirmed in their data |
| 4. Discovery | Technical and business requirements | Champion identified, budget confirmed |
| 5. Evaluation | Trial or pilot running | Success criteria defined and met |
| 6. Proposal | Pricing and terms presented | Procurement engaged |
| 7. Closed | Contract signed | Onboarding scheduled |
45–75 days from engaged to closed.
Qualification — MEDDPICC adapted
| Letter | Question |
|---|---|
| Metrics | What's the leakage in dollars? |
| Economic buyer | Who owns the inference budget? |
| Decision criteria | Security review, procurement, legal? |
| Decision process | Who signs, what's the timeline? |
| Paper process | MSA, DPA, security questionnaire? |
| Identified pain | Confirmed in their own data |
| Champion | Someone who wants this to happen |
| Competition | Cloudflare, bot management, build-it-themselves |
7Metrics
Activity metrics are what the motion is actually steered by. Revenue targets get set once we have their real ARR, ACV, and inbound volume — see open questions.
| Leading indicator | Weekly target |
|---|---|
| Qualified accounts touched | 40–60 |
| Reply rate | 8–12% |
| Positive reply rate | 3–5% |
| Exposure reads delivered | 8–12 |
| Research pieces published | 1 per month |
Quota math is only meaningful against their current ARR, ACV, and deal cycle. Inventing a target before those are known would make this playbook look precise and be wrong — so the revenue line stays open until discovery fills it in.
8First 90 days
Days 1–30 — Foundation
- Audit the current pipeline, CRM, and any existing inbound
- Build the ICP list: 300 target accounts across the four tiers
- Stand up the outbound stack: enrichment, sending, CRM pipeline
- Write the messaging: three value props tested against 20 accounts
- Ship the exposure-read offer and deliver the first five
- Publish research piece #1
Days 31–60 — Motion
- Run the full outbound sequence at 60 accounts per month
- Deliver 10 exposure reads and measure conversion
- Publish research piece #2
- Open the partner channel: five cloud marketplace listings, ten AI infra intros
- First closed deal
Days 61–90 — Scale
- Double outbound volume if reply rate holds above 8%
- Build the objection-handling doc from real calls
- Publish research piece #3
- Hire and onboard the second AE — run the search and the onboarding
- Write the sales playbook so the next hire ramps in three weeks, not three months
A documented, repeatable sales motion — not just a number.
9What this needs to work
| Need | Why |
|---|---|
| Access to product telemetry | Exposure reads require running real traffic through detection |
| Founder time for research | The research engine is channel one; it needs Matt's voice and expertise |
| A working demo environment | Exposure reads must be deliverable within 48 hours of a request |
| Pricing clarity | ACV range and packaging must be settled before outbound scales |
| Security documentation | Self-hosted deployment requires a security questionnaire response ready to go |
| CRM ownership | Pipeline hygiene and reporting need one owner from day one |
10Open questions
- Current ARR and customer count — sets what a realistic Year-1 revenue target actually looks like
- ACV today — is it $20k or $100k? That changes the deal math entirely
- Inbound volume — how much demand does the research generate today?
- Self-hosted vs hosted mix — which do customers actually choose?
- Existing pipeline — is there anything in flight to build on?
- Competitive landscape — who else is showing up in deals?
Appendix — the stack
The stack scales with the motion, not ahead of it. Nothing in tier 3 gets bought until tier 2 is producing.
Tier 1 — stand up in month 1 · ~$400/mo
| Layer | Tool | Cost |
|---|---|---|
| Orchestration | Clay | $185/mo |
| Sending | Smartlead | $94/mo |
| Email infrastructure | Zapmail | $39/mo |
| CRM | Attio | $35/seat/mo |
| Scheduling | Calendly | $12/mo |
| Automation | n8n (self-hosted) | $0 |
Tier 2 — add at month 3 · ~$330/mo
| Layer | Tool | Cost |
|---|---|---|
| Website signals | RB2B | $79/mo |
| Social signals | Trigify | $149/mo |
| LinkedIn outreach | HeyReach | ~$100/mo |
Tier 3 — at scale, only when proven
| Layer | Tool | Cost |
|---|---|---|
| Multi-source signals | Common Room | $2,500/mo |
| Search and research | Exa | ~$50/mo |
| Unified data API | Deepline | custom |
| AI orchestration | Claude Code | usage-based |
Tier 1 only: ~$400/mo · Tier 1 + 2: ~$730/mo · Tier 1 + 2 + 3: ~$3,300/mo
The stack scales with the motion. Tier 1 is enough to run the first 90 days.