250 conversations before a line of code

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya6 min read

Key takeaways

  • Twine's 250 pre-build conversations revealed that identity, not vulnerability, was the bigger pain, and the company pivoted before writing code.
  • Ask the purchase-intent question early: is this pain big enough for you to buy tomorrow? Woody's one regret was not asking it.
  • Itzik Alvas's referral test is a fast honesty check: if a buyer will name someone else with the problem, the pain is real.
  • Design partnerships are easier to start than founders assume, including with dream logos, when value is two-way and no sales hook hides in the research.
  • Validation is not a delay to building; it produces your first design partners, your first honest messaging, and a de-risked raise.

Justin Woody planned 100 conversations with buyers before building anything at Twine. "We thought we were going to do one hundred," he told us on the Cult Products podcast. He ended up having 250. Nearly all of them told him the same uncomfortable thing: the bigger pain was not vulnerability management, the problem he had set out to solve. It was identity. "We heard this in 99.9% of our conversations, which made us say, alright, I guess identity is a problem." So Twine pivoted, before a single line of code existed to defend.

Sit with the counterfactual for a moment. Without those conversations, an experienced team out of Claroty and Mandiant builds a competent product for the wrong pain, discovers the mismatch a year later through the sales pipeline, and pivots anyway, with a burned year and a built codebase pulling against the turn. The 250 conversations did not delay the company. They were the fastest work Twine ever did.

Most founders know, in the abstract, that they should talk to customers first. Fewer treat those conversations as what they actually are: the process that shapes the proposition itself. Here is what that looks like in practice, from founders who did it in public and from our own research with the buyers on the other side of the table.

The spiral, not the checklist#

Woody describes the process with an image worth keeping. "A spiral, right, that keeps getting smaller and smaller until you hit the middle," he said on the episode. "And each conversation gets your spiral to be tighter and tighter." The first ten conversations are wide and disorienting; everyone's pain sounds slightly different, and you cannot tell signal from anecdote. By conversation eighty, patterns repeat. By two hundred, you can finish the buyer's sentence, and when a new conversation surprises you, the surprise itself is information. Validation is not a checklist you complete. It is a curve you converge along, and you know you are done when the spiral stops tightening.

He is also candid about the one thing he would change, and it is a question. Across 250 conversations, he never directly asked: is this pain big enough for you to purchase against tomorrow? People will confirm that a problem exists all day. Confirming that it outranks the other forty problems competing for the same budget is a different admission, and it is the one that predicts revenue. Ask it early and ask it plainly. A wince is data.

Pain that is real but not purchasable is a research finding, not a business.

The referral test#

Itzik Alvas ran the same play at Entro Security: more than 200 conversations with practitioners before a line of code. Out of them came a filter any founder can apply in the last two minutes of a call. "Do you know anybody else with that problem? Do you know anybody else that would like to have that conversation too?" he asked on his episode. If the answer comes with a name and an introduction, the pain is real.

The mechanics of the question are what make it honest. Telling a founder their idea is interesting costs a practitioner nothing; the cybersecurity community is small and people are generous to founders. A referral is different. It spends real currency, a colleague's time and the referrer's credibility. A yes means the pain is real enough to vouch for. A polite deflection means you have learned something too, and learned it in two minutes instead of two quarters.

This is the core insight of The Mom Test, the book we recommend to every founder at this stage: people will lie to you to be kind, so design questions that politeness cannot answer. Ask about behavior, past spending, and referrals. Never ask "would you buy this?" and believe the answer.

From conversations to a testable proposition#

Conversations tell you the pain is real. They do not yet tell you that your framing of the fix will land. The method we walk through in our webinar bridges that gap.

See it in action.

Write the value proposition down as a sentence a stranger could evaluate. Then put it in front of honest outsiders, and test three things: do they understand it, unprompted, in their own words; how much do they want it, scored out of ten rather than gestured at; and what do they expect it to cost, which surfaces price sensitivity before a procurement team does. Iterate through the conversations until the scores move. Then, and only then, put the proposition on a live page and let real traffic vote.

The sequencing matters. Founders love to skip to the live page, because a page feels like progress and a survey feels like homework. But traffic on an unvalidated proposition just measures how convincingly you phrased the wrong thing. The conversations come first because they are where the proposition gets its content: the words buyers use for the pain, which are almost never the words in your architecture diagram. That language is an asset. It becomes the homepage, and it is the difference we describe in the five-second homepage between a line that lands in seconds and a poetic sentence that could describe three unrelated products.

Design partners are closer than you think#

The step after validation is design partnership, and here founders consistently overestimate the barrier. In our CISO research, a finding that surprises almost every founder we share it with: design partnerships are easier to start than you assume, including with the dream logos. Senior security buyers take these conversations willingly, on conditions that are entirely within your control. The value has to be genuinely two-way. Pricing and intent have to be transparent from the first email. And there must be no sales hook hidden inside a research conversation, because the buyer who discovers one will remember it, and the community they talk to is small.

What does the buyer get? Earlier than you think, quite a lot: influence over a roadmap they will eventually depend on, early sight of a capability their incumbent vendors lack, and a founder who actually listens. One CISO we interviewed put the value of a good design partner in terms every founder should internalize: they tell you which missing capability will block the sale in eighteen months. That is knowledge no amount of internal planning produces, and it arrives while the fix is still cheap.

The trust that opens these doors is personal before it is corporate. Buyers of early-stage products get comfortable with the people as a proxy for the immature product, which is why the same credibility you build in research conversations has to be visible on your website too. We cover that in your team page is a security control.

What validation buys you beyond the product#

Frame the 250 conversations as product research and you undercount the return. Three other assets come out of the same work.

A de-risked raise. An investor hearing "we held 250 buyer conversations and pivoted on what we learned" is hearing evidence of process, not just conviction. The pivot is not a blemish on the story. It is the story: proof the company steers by market signal.

Your first design partners. The best conversations do not end. The practitioner who lit up in minute forty is your first design partner candidate, already warm, already invested in the shape of the fix.

Your first honest messaging. By the end, you have heard the pain described a hundred ways and watched which framings made buyers lean in. Your positioning is no longer a guess to be tested in the market. It has already survived contact.

The founders who skip this stage usually skip it because building feels like progress and talking feels like delay. Twine's story is the rebuttal. The most consequential product decision the company ever made happened before the product existed, in conversation number one through two hundred fifty. The code came after, and it was written at the right target.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.