Short answer: in cybersecurity sales, a warm introduction is only useful if nobody gets exposed along the way. The buyer may not want anyone to know they are evaluating. The champion may be under NDA. The board member may be willing to help twice a year and no more. The way to protect all of them is structural: every ask is proposed, then approved by the rep and by whoever owns the relationship, then accepted or declined by the connector, who sends it from their own account. Boomerang is software built on that sequence. Rudy, its AI agent, maps the paths and drafts the asks. It never sends an introduction on anyone's behalf.
This post covers why confidentiality matters more in security, where warm intro programs usually leak, which controls actually matter, and how to set the program up. For the broader case for warm introductions in security, see why security companies are a great fit for Boomerang.
Why confidentiality matters more in security sales
Most B2B buyers do not mind if a vendor knows they are shopping. Security buyers often do. An evaluation of a detection or asset visibility product can hint at a gap in the buyer's defenses, a recent incident, or a coming reorganization. None of that is something a CISO wants passed around.
The people who can help you reach that buyer carry their own sensitivities:
- Board members and investors spend personal credibility every time they vouch for a portfolio company. Ask too often, or for the wrong deal, and they stop answering.
- Customer champions may be bound by an NDA or a policy that stops them from naming vendors in public. A private word to a peer is fine. Being named in a campaign is not.
- Regulated buyers in financial services, healthcare and government often have strict rules about who can contact them and how. A careless ask can close a door for years.
- Confidential deals sometimes cannot be discussed outside a small group inside the vendor, let alone with outside connectors.
The security market is also small and well connected. CISOs talk to each other. A clumsy ask travels just as fast as a good recommendation.
Where warm intro programs leak
Most confidentiality failures in warm intro programs are not breaches. They are process failures. Four come up again and again.
Over-asking board members and investors
Without a system, every rep who spots a board member in a buyer's network makes their own ask. The board member gets five requests in a month, none of them coordinated, some for deals too small to justify the favor. Goodwill that took years to build is spent in a quarter.
Exposing a champion
A champion who ran your product at a previous company is the warmest path into their new one. But if a rep reaches out publicly, references their old deployment by name, or asks them to vouch in writing to a group, the champion may be put in breach of an agreement or simply embarrassed.
Leaking a confidential evaluation
An ask that says "Acme is looking at replacing its current tool, can you put in a word" tells the connector something Acme may not want known. If that connector sits on another vendor's board, the information has now left the building.
Reps cold-messaging someone else's relationship
The most common failure is also the simplest. A rep finds that an investor knows the buyer and messages the investor directly, without the CEO who owns that relationship ever knowing. The investor wonders why a stranger is asking for a favor, and the CEO hears about it secondhand.
The controls that actually matter
A confidential warm intro program needs a small number of controls, applied to every ask without exception.
- Consent at each step. Nothing moves without a person deciding it should: the rep, the relationship owner and the connector.
- Owner approval. The person who holds the relationship decides whether and how to ask. Reps do not go around them.
- Connector preferences. Each connector's limits on deal size, channel, cadence and exceptions are written down and applied automatically, not remembered.
- The connector sends from their own account. The introduction comes from a person the buyer knows, in their own words, not from a tool.
- No connector install. Board members, investors and champions should not have to install software or share their contacts to be part of the program.
- Auditability and identity. A record of who asked what, and standard controls over who can sign in: SSO, SCIM, and a SOC 2 Type II report.
How Boomerang handles each control
Mapping without asking connectors for anything
Rudy maps who four types of connector know: your executives and employees; your investors, advisors and board members; your customer champions; and your partners. It uses more than 80 relationship signals, drawn from signals the company already has and from public sources. Connectors never upload, install or agree to anything to be mapped. LinkedIn and mailbox connections are optional enhancers, never prerequisites.
Proposals, not sends
Rudy watches your deals and, when one needs a warm path, proposes who should ask whom and drafts the ask. Nothing moves until the rep approves. That keeps the rep in control of what is said about the deal, which is where confidential details are most likely to slip.
Routing through the relationship owner
Once the rep approves, the ask routes to whoever owns the relationship. Board and investor asks go through the CEO or chief of staff. Customer asks go through the CSM or the executive with the most meetings on that account. Internal executives are asked directly. Each owner approves before anything goes out. This is the fix for reps messaging someone else's relationship: there is no path to the connector that skips the owner.
The connector decides and sends
The connector accepts or declines. On accept, a draft is generated in the sender's voice, and the connector sends it from their own inbox. They can edit it, soften it or leave out details they are not comfortable sharing. Rudy never sends an introduction on anyone's behalf. It delivers the request, nudges when things go quiet, and tracks the outcome.
Preferences enforced on every ask
Each connector sets deal size thresholds, channel, cadence and exceptions. Rudy enforces them on every ask. A board member who only wants enterprise deals above a certain size, no more than one request a quarter, and never anything involving a named competitor, gets exactly that.
Security and administration
Boomerang is SOC 2 Type II compliant, with documentation on its trust center. The Company plan includes Okta SSO. Enterprise adds SCIM and custom IdP, audit logs and custom CRM objects, along with an implementation plan and a named CSM with an SLA.
A checklist for security vendors setting up the program
- Pick your connectors deliberately. Start with the board, investors, advisors and your strongest customer champions. Add partners and employees once the approval flow is working.
- Name an owner for every sensitive relationship. Confirm who approves board and investor asks, usually the CEO or chief of staff, and who approves customer asks, usually the CSM or the executive closest to the account.
- Record connector preferences before the first ask. Deal size threshold, preferred channel, how often they are willing to be asked, and any exceptions such as competitors or regulated accounts.
- Write a rule for confidential deals. Decide what a draft may and may not say about an evaluation, and have reps edit drafts accordingly before approving.
- Treat champions with care. Use champion job changes as a trigger, but let the person who knew them best decide whether and how to reach out.
- Lock down access. Connect your identity provider, and on Enterprise use SCIM and audit logs so the program meets the same standards you sell.
- Review outcomes, not just volume. Look at accepts, declines and booked meetings by connector, and adjust preferences when someone is being asked too often.
Setup takes about 30 minutes of admin work, and warm paths appear the same day. Boomerang works with Salesforce, HubSpot, Attio, Slack and Slack Connect, Gmail, Outlook, Google and Microsoft calendars, Gong, Outreach, Clay and Common Room, plus a REST API, MCP and webhooks.
Armis in practice
Armis, a $300M ARR cybersecurity company, runs Boomerang across its enterprise motion. Its published results:
- 26,000 warm intro paths created.
- 10x ROI on revenue in year one.
- More than 1,400 hours of manual research eliminated.
- Path to Power running across more than 200 enterprise accounts.
Path to Power is where confidentiality matters most: reaching senior executives through the strongest warm path across reps, the CEO, the board and advisors. Every one of those asks follows the same sequence of rep approval, owner approval and a connector who chooses to send. The Armis case study has the detail.
Getting started
Starter is $80 a month billed annually, Team $600 and Company $2,000, and Enterprise is custom. Every plan includes users, and Starter comes with a 7-day free trial. See the pricing page for plan detail, or start free.
Frequently asked questions
Does Rudy message board members or investors directly?
No. Rudy proposes the path and drafts the ask, and the rep approves it. Board and investor asks then route through the CEO or chief of staff, who approves before anything goes out. The board member or investor accepts or declines, and on accept sends the introduction from their own inbox. Rudy never sends an introduction on anyone's behalf; it delivers the request, nudges when things go quiet and tracks the outcome.
Does Boomerang provide operators or a managed service?
No. Boomerang is software. There are no Boomerang operators who run your program or make asks for you. Your own people approve and send every introduction. Enterprise customers get an implementation plan and a named CSM with an SLA, which is help deploying and running the software, not people contacting your connectors.
What security certifications does Boomerang have?
Boomerang is SOC 2 Type II compliant, and documentation is available on its trust center. The Company plan includes Okta SSO. Enterprise adds SCIM and custom IdP, audit logs and custom CRM objects, plus an implementation plan and a named CSM with an SLA.
Do connectors need to install anything?
No. Board members, investors, champions and partners never upload contacts, install software or agree to anything to be mapped. Rudy builds the map from signals your company already has and from public sources. LinkedIn and mailbox connections are optional enhancers. When a connector accepts an ask, they send it from their own account.
Can a connector decline an ask or set limits?
Yes. Every connector accepts or declines each ask, and nothing is sent unless they choose to send it. Connectors also set preferences: deal size thresholds, preferred channel, how often they are willing to be asked, and exceptions. Rudy enforces those preferences on every ask, so a board member is not asked more often, or for smaller deals, than they agreed to.
How are customer champions under NDA protected?
Customer asks route through the CSM or the executive with the most meetings on that account, who approves first. The champion then decides whether to help and sends any introduction privately from their own inbox, in their own words. They can edit the draft or leave out anything they are not comfortable sharing, so nothing names them publicly without their choice.



.png)

