Evidence boundary · Snapshot as of 2026-08-07 14:00 Europe/Vilnius. Evidence is 13 screenshots covering 12 unique slides from today’s all-hands. There is no audio, Q&A, underlying dashboard, accounting definition sheet, or raw dataset. “Mysterium reported” is not the same as “verified.” Exact capture is retained privately in the vault source note; the original PNGs are archived, hash-verified, beside this report.
Executive verdict
July looks materially better. It does not yet prove business health.
The deck shows a company moving from broad ambition toward one commercial priority: acquire more high-quality customers, convert one strong month into a repeatable system, and force weekly progress on every major bet. That strategic compression is good. The concrete operating signals are also real enough to take seriously: reported total revenue rose to $288k; recurring revenue reached $168k; new revenue reached $87k; SuperProxy beat its July sales target; VPN revenue recovered to May’s level; payment orchestration went live; Poland’s incentivised node count reportedly rose 20%; and the support team now has tagged historical chat data instead of manual Intercom reporting.
But the evidence layer is not mature enough for the confidence of the narrative. The deck contains revenue but no gross margin, burn, cash collection, runway, or entity/product perimeter. It calls customers “high quality” without defining quality. It calls July traction without showing cohort retention or a multi-month series. It calls SuperProxy’s month a win while 78% of the displayed result is paid tests that have not yet converted. It celebrates a 20% node increase without showing incentive cost, persistence, utilisation, traffic quality, or incremental revenue. It lists a dozen product bets without baselines, owners, decision rules, or kill dates.
The biggest issue is a same-month revenue-perimeter contradiction. The deck implies June total revenue of $264k; the Kairos corpus carried roughly $75.6k/month for that same June, recounted from the July 17 all-hands — a 3.5× gap on an identical period. (July’s $288k against the old baseline is 3.8×, but that pairing mixes months and invites a false rebuttal.) The evidence is also asymmetric: the deck figures sit on a photographed slide; the $75.6k is a meeting recollection, and the likeliest explanation is that the 07-17 capture voiced only the VPN and GoProxies lines while Kairos canon promoted their sum to “total revenue.” The old Phase-1 break-even model must therefore be marked do not use — rebuild on deck figures once the perimeter is named. This is not bad news; the $288k figure may be genuinely better and more complete. It is simply not comparable until the perimeter is named.
The most valuable Kairos move is not another strategy brainstorm. It is a one-week economic truth map + quality-customer scorecard, followed by one reversible intervention with clean measurement. The four highest-EV intervention lanes visible in the screenshots are:
- convert paid proxy tests into durable MRR;
- recover failed VPN payments through orchestration and Adyen fallback;
- reduce VPN churn with an honest cancellation/retention flow;
- turn Poland’s dynamic-incentive result into a controlled node-economics experiment.
Everything else should be forced to show how it produces retained contribution, not activity.
What the numbers actually say
Company-level revenue
| Metric | July | Prior period | Change | Checked reading |
|---|---|---|---|---|
| Total revenue | $288k |
$264k implied |
+$24k / +9.09% |
Slide’s +9% is arithmetically consistent. |
| Recurring revenue | $168k |
$157k |
+$11k / +7.01% |
Slide’s +7% is consistent. |
| New revenue | $87k |
$76k |
+$11k / +14.47% |
Slide’s +14.5% is consistent. |
| Conditional remainder | $33k |
$31k implied |
+$2k / +6.45% |
Only valid if recurring and new revenue are non-overlapping components of total revenue. The deck does not say they are. |
Useful ratios, not accounting claims: recurring revenue is 58.3% of the reported total and new revenue is 30.2%. If the categories are additive, 11.5% remains outside them. The repeated $11k increase in both recurring and new revenue may reflect two independent gains, or overlap in metric construction; definitions are required before summing.
At a flat run rate, $288k/month annualises to $3.456m/year. That is a scale illustration, not a forecast, and not a profit figure.
The prior-baseline contradiction
The 07-17 Kairos corpus carried:
- total revenue around
$75.6k/month; - VPN around
$67.6k/monthand declining 10.2% month over month; - GoProxies around
$8.07k/monthand growing.
The like-for-like comparison is June against June: the deck implies $264k for June ($288k − $24k), versus the $75.6k the corpus carried for the same month — 3.49×. July’s $288k is 3.81× the old baseline, but that pairing mixes months and should not be the headline.
The two sources are not equal-weight evidence. The deck figures are a photographed slide; the $75.6k is Lee’s meeting recollection (canon itself marks the VPN decline “n=1”). A document beats a recollection. Plausible explanations, likeliest first:
- the 07-17 capture voiced only the VPN and GoProxies lines, and Kairos canon promoted their two-line sum to “total revenue” — a partial perimeter, not a conflicting measurement;
$288k/$264kare group-wide, gross billings, recognised revenue, or include non-recurring/token/other lines the recollection never covered;- the old number was misheard or transcribed incorrectly;
- the perimeter changed through consolidation or reclassification;
- one of the slides uses a label more loosely than an accountant would.
Until resolved, do not use the old $75.6k baseline for any calculation — break-even, runway, valuation, customer economics, or team affordability. The deck figures may be used as working numbers, but only with perimeter labels attached (entity, product, gross/net, recognition, period). The screenshot improves the question; it does not answer it.
SuperProxy sales math
| Metric | Value | Checked reading |
|---|---|---|
| July result | $11,628 |
Exact sum of new MRR and paid tests below. |
| Target | $8,500 |
Actual exceeded target by $3,128, or 36.8%. |
| Attainment | 136% displayed |
Mathematically 136.8%; likely rounded/truncated. This is target attainment, not growth. |
| New MRR | $2,544 |
21.9% of the displayed July result. |
| Paid tests | $9,084 |
78.1% of the displayed July result. |
The sales team has found willingness to trial. It has not yet shown equivalent durable revenue. The conversion of paid tests is rightly listed as a biggest bet because almost four-fifths of the reported July win sits in that transient state. A clean next scorecard needs: tests started, test value, tests completed, conversion rate, days to conversion, contracted MRR/ARR, gross margin, churn after 30/90 days, and loss reasons.
VPN marketing math
The marketing slide reports web new revenue +5.1% and paid-ad revenue +15%, with the footnote “we are counting July vs last 31 days, not 30 ;)”. The most natural reading is that marketing already normalised the window — July’s 31 days against the preceding 31 days — which makes this the one slide in the deck showing explicit window hygiene. Treat the footnote as a hygiene signal, not a suspicion target.
The conditional still matters: if the comparison was in fact July’s 31 calendar days against June’s 30-day total, the daily-rate-normalised changes shrink to roughly:
- web new revenue:
+1.7%rather than+5.1%; - paid-ad revenue:
+11.3%rather than+15%.
One question resolves it: the exact start/end dates of both windows. More importantly, “good ROAS” is not enough: quality must survive refunds, chargebacks, taxes, processing fees, support cost, retention, and geographic price differences.
MystNodes supply math
The slide reports 33,000 nodes, the highest pool in three months, and a 20% node increase in Poland after dynamic incentives. That is a promising natural experiment, but the absolute Polish baseline is absent. A 20% lift could mean 20 extra nodes or 2,000; the business meaning changes completely. The screenshot also does not report the incentive cost or whether nodes persisted after activation.
The 33,000 figure is compatible in order of magnitude with prior 31,547–32,570 observations, but not directly reconcilable because “node,” “active node,” “IP,” “available node,” country coverage, observation window, and product surface may differ. It does not validate the 80M+ GoProxies inventory claim or prove those inventories share a source.
Claim-by-claim audit ledger
Legend: CALC = arithmetic checks out · SIGNAL = useful directional evidence · REPORTED = precise enough to retain but not independently verified · PLAN = intention, no result yet · GAP = missing definition/baseline/outcome · CONFLICT = materially conflicts with current Kairos canon · ADAPT = directionally right; adopt with the stated correction. Compound verdicts (e.g. PLAN/SIGNAL) mark atoms that straddle two categories.
Direction and operating cadence
| # | Slide atom | Audit verdict |
|---|---|---|
| 1 | Ambition is “Meaningful Impact.” | REPORTED. Useful north star; no operational measure. |
| 2 | Reach and scale matter. | GAP. No target, timeframe, or product boundary. |
| 3 | Product quality and performance matter. | GAP. No reliability, speed, failure, or quality score. |
| 4 | Work should align with vision. | GAP. Vision-to-decision rule is not shown. |
| 5 | Community strength and resilience matter. | GAP. No node/community health metric. |
| 6 | Team and culture matter. | GAP. Matrix launch is an activity, not culture outcome. |
| 7 | Q3 priority is acquisition of high-quality customers. | SIGNAL. Strong compression; “high quality” is undefined. |
| 8 | Growth-driving work should be prioritised and resourced fast. | SIGNAL. Directionally sound, but risks starving reliability, compliance, data, and retention if acquisition is read too narrowly. |
| 9 | Work not contributing to acquisition should wait. | ADAPT. Replace “acquisition” with “retained contribution or an explicit enabling dependency.” Otherwise the rule can optimise the front door while the floor leaks. |
| 10 | July proved direction and potential. | REPORTED. One month demonstrates possibility, not repeatability. Management itself partly acknowledges this. |
| 11 | Consistent months build success. | SIGNAL. Correct; needs a defined streak scorecard. |
| 12 | Think long-term and show progress weekly. | SIGNAL. Excellent cadence rule if progress means measured movement, not output lists. |
| 13 | July was strong despite summer slowdown. | REPORTED. Seasonality claim lacks historical comparison. |
| 14 | Next all-hands success means healthy growth, bets moving, no someday results. | GAP. All three are semantically soft and can be declared without a threshold. |
Company revenue
| # | Slide atom | Audit verdict |
|---|---|---|
| 15 | Total revenue is $288k, up $24k / 9%. |
CALC + CONFLICT. Arithmetic works; perimeter conflicts with $75.6k canon. |
| 16 | Recurring revenue is $168k, up from $157k / 7%. |
CALC. Definition and product/entity split missing. |
| 17 | New revenue is $87k, up from $76k / 14.5%. |
CALC. Recognition and overlap with recurring revenue missing. |
| 18 | July is 2026’s strongest total-revenue growth month. | REPORTED. Needs January–July series. |
| 19 | VPN recurring revenue recovered to May level. | SIGNAL. This weakens the “secular 10.2% monthly melt” narrative; it does not prove recovery is durable. |
| 20 | SuperProxy recurring revenue grew steadily with no red flags. | REPORTED. “No red flags” needs churn, margin, concentration, fraud, supply-quality, and collection evidence. |
| 21 | July is second-best new-revenue month after April. | REPORTED. Needs full monthly series and product split. |
| 22 | Focus next on low-hanging fruit and speed. | ADAPT. Rank by expected retained contribution × speed × reversibility, not ease alone. |
VPN acquisition and organic
| # | Slide atom | Audit verdict |
|---|---|---|
| 23 | Marketing began targeting tier-3 countries. | REPORTED. Countries, dates, spend, and pricing are absent. |
| 24 | Tier-3 acquisition currently shows good ROAS. | GAP. No number, attribution window, or quality adjustment. |
| 25 | Organic momentum is improving. | GAP. Search impressions, non-brand clicks, conversions, and cohort value absent. |
| 26 | Domain Rating reached 60. | REPORTED. SEO authority proxy, not a customer or revenue outcome. |
| 27 | Web new revenue increased 5.1%. | REPORTED. Footnote suggests an already-normalised 31-day window — a hygiene signal; confirm exact dates (if July vs calendar June, daily-rate growth is ~+1.7%). |
| 28 | Paid-ad web revenue increased 15%. | REPORTED. Spend, ROAS, contribution, cohort retention, and window definition absent. |
| 29 | Nostalgia campaign is a major bet. | PLAN. Needs audience, channel, message test, spend cap, and kill rule. |
| 29a | Campaign creative uses fear framing: “Your internet is about to become restricted,” buttons “Ignore” / “Fight.” | GAP. No brand-safety or compliance review visible; fear-based restriction claims need substantiation under ad-platform rules, and the message deserves a test before spend. |
| 30 | NFL content is a major pillar. | PLAN. Needs rights/safety check, seasonal thesis, target geography, organic/paid distinction, and conversion path. |
SuperProxy sales
| # | Slide atom | Audit verdict |
|---|---|---|
| 31 | Sales is abandoning many Excel tables. | SIGNAL. Simplification can improve focus; the replacement system and data retention are unspecified. |
| 32 | Sales will track outcomes instead of inputs. | SIGNAL. Good principle; needs a minimal leading-indicator layer so pipelines do not become invisible. |
| 33 | Action plans are clearer. | GAP. No owner/date/evidence shown. |
| 34 | Calls now have structure. | SIGNAL. Operational hygiene, not yet a business result. |
| 35 | July delivered $11,628 against $8,500. |
CALC. 136.8% attainment. Definition is likely bookings/test value, not proven recurring revenue. |
| 36 | New MRR was $2,544. |
REPORTED. Durable value requires margin, term, collection, and churn. |
| 37 | Paid tests were $9,084. |
REPORTED. 78.1% of the displayed win; conversion is the bottleneck. |
| 38 | Enterprise clients are a major bet. | PLAN. ICP, procurement cycle, minimum contract, delivery capacity, and concentration guard absent. |
| 39 | Real Estate API is a major bet. | PLAN. User/job, differentiation, data legality, margin, and customer evidence absent. |
| 40 | SERP API is a major bet. | PLAN. Crowded market; needs wedge, quality benchmark, cost curve, and pre-commitment evidence. |
| 41 | Converting paid tests is a major bet. | SIGNAL. Highest-confidence sales priority visible in the deck. |
| 42 | Sales struggles to keep all process pillars stable. | REPORTED. This may be the constraint underneath inconsistent conversion; name which pillars fail and why. |
Customer success and payments
| # | Slide atom | Audit verdict |
|---|---|---|
| 43 | Intercom reporting for GP and VPN is no longer manual. | SIGNAL. Automation is valuable if taxonomy, completeness, freshness, and owner are governed. |
| 44 | Historical chats are reviewable by tags, topics, and requests. | SIGNAL. A useful voice-of-customer substrate; not proof of a central operational data layer. |
| 45 | Reporting is exposing product/support gaps. | REPORTED. The gaps and prioritisation mechanism are not shown. |
| 46 | A clear customer profile was identified. | GAP. No profile, evidence base, economic value, or product distinction is visible. |
| 47 | Live-chat communication was reshaped. | PLAN/SIGNAL. Measure response time, resolution, CSAT, conversion, review rate, churn, and escalations. |
| 48 | Better chat should improve customer experience and reviews. | PLAN. Plausible causal chain; no baseline or experiment. |
| 49 | Growth’s biggest struggle is unspecified. | GAP. The visible template placeholder is a reporting-quality failure and should be repaired before the next all-hands. |
| 50 | VPN went live on Payments Orchestration with Stripe on 07-23. | REPORTED. High-value instrumentation milestone. |
| 51 | The system can track network-token, independent-3DS, and adaptive-3DS effects. | PLAN/SIGNAL. Instrumentation capability is not yet an effect. Metric definitions and causal design required. |
| 52 | First impact results will be visible after one month. | PLAN. Pre-register the baseline/window now to prevent post-hoc storytelling. |
| 53 | Adyen fallback may recover revenue. | PLAN. Strong torpedo candidate; net uplift must include fees, fraud, chargebacks, and cannibalisation. |
VPN product
| # | Slide atom | Audit verdict |
|---|---|---|
| 54 | VPN app was open-sourced on 08-04. | REPORTED. Potential trust/developer lever; governance, license, release parity, and security process need checking. |
| 55 | Store metadata/localised presence was overhauled. | REPORTED. Measure store impressions → page views → installs → trials → paid cohorts by locale. |
| 56 | WireGuard-router support shipped 07-29. | REPORTED. Measure activation, retained router users, support burden, and revenue. |
| 57 | OpenVPN for Android shipped 08-04. | REPORTED. Measure usage and whether it fixes an acquisition/retention barrier. |
| 58 | All active plans are growing steadily. | REPORTED. Needs absolute counts, MRR, mix, cohort age, refunds, and product boundaries. |
| 59 | News Center and Notifier are built for v2.4.9. | PLAN. Hidden implementation is not customer value until used; define notification quality and opt-out guard. |
| 60 | Cancellation flow should reduce churn and Support billing requests. | PLAN. High-EV bet if it is helpful rather than obstructive; measure saved users at 30/90 days and support contacts. |
| 61 | Favorite IPs answer customer requests. | PLAN. Measure repeat connection, session success, retention, and support reduction. |
| 62 | Linux CLI targets developers and power users. | PLAN. Needs demand proof, monetisation hypothesis, maintenance/security owner, and support-cost cap. |
| 63 | Adaptive-pricing tests may start by end of August. | PLAN/GAP. “Hopefully” signals ownership or readiness risk; define hypothesis, segments, floor/ceiling, and rollback. |
| 64 | Actual LTV is below target and the gap should shrink. | REPORTED/GAP. This is the most important unquantified VPN metric on the slide. Current LTV, target, formula, cohorts, CAC, and payback are absent. |
MystNodes
| # | Slide atom | Audit verdict |
|---|---|---|
| 65 | Dynamic incentives were properly activated. | REPORTED. “Properly” needs mechanism, dates, spend, and failure criteria. |
| 66 | Extension/Launcher synchronisation improved product uniformity. | REPORTED. Measure update coverage, failure rate, and support impact. |
| 67 | Poland node count increased 20% after incentives. | SIGNAL. Best quasi-experiment in the deck; absolute lift, cost, persistence, quality, and utilisation missing. |
| 68 | Results were almost immediate. | REPORTED. Exact lag and pre/post window absent. |
| 69 | Node pool reached 33,000, a three-month high. | REPORTED. Definition and economic usefulness absent. |
| 70 | Launcher optimisation, notifications, and bug fixes drove growth. | REPORTED. Bundled changes prevent clean attribution unless staggered/cohorted. |
| 71 | UX/UI optimisation should improve onboarding and node comprehension. | PLAN. Measure install → activation → first earning → D7/D30 persistence and support contacts. |
| 72 | Token-price action is a major struggle. | REPORTED. External volatility may affect supply economics and user trust; do not solve it with unpriced incentive leakage. |
| 73 | Support lacks knowledge because product scope is huge. | REPORTED. Strong product-complexity signal; solve through scope/taxonomy/tooling, not only training. |
People and culture
| # | Slide atom | Audit verdict |
|---|---|---|
| 74 | Mangirdas joined as Head of Success. | REPORTED. Charter should tie support evidence to retention, conversion, and product fixes. |
| 75 | Matrix launched for peer recognition and motivation. | PLAN/SIGNAL. Track adoption and fairness lightly; do not mistake nominations for operating health. |
| 76 | A marketing copywriter received an offer. | REPORTED. Hiring should be tied to the high-quality-customer scorecard, not content volume alone. |
| 77 | Meeting participant indicator ranged 30–36. | REPORTED. UI attendance only, not paid headcount or organisational scope. |
What changed versus the current Kairos thesis
1. The old break-even equation is now blocked by revenue definition, not only burn
The old model said: revenue around $75.6k, burn unknown, gap huge. Today’s slide says $288k. Burn is still absent, but even revenue is no longer a stable input. The first Phase-1 work product must be an economic-perimeter table:
| Required line | Minimum definition |
|---|---|
| Entity/group | Legal entities included and intercompany eliminations. |
| Product | VPN, SuperProxy/GoProxies, MystNodes/network, token/other. |
| Revenue type | Recurring, new, test, usage, one-off, token/other. |
| Recognition | Gross billings, recognised revenue, cash collected, net revenue. |
| Quality | Refunds, chargebacks, bad debt, processor fees, taxes, direct supply cost, support burden. |
| Time | Calendar month, trailing days, booked date, invoice date, collection date. |
Only after that can monthly burn, contribution margin, and runway be meaningfully compared.
2. “VPN is melting 10.2% monthly” is downgraded from trajectory to one earlier observation
The all-hands says VPN recurring revenue recovered to May level. That does not prove a turnaround, but it directly undermines extrapolating a constant 10.2% monthly decline. The required evidence is a 12-month cohort series split into new paid, retained, reactivated, voluntarily churned, involuntarily churned, refunded, and payment-failed.
3. Proxy demand is more tangible, but its durable economics remain unproven
There is now a concrete July sales figure and target. That is progress. Yet 78% is paid tests, not new MRR. The biggest opportunity is a conversion machine; the biggest analytical mistake would be counting test value as stable recurring revenue.
4. The product-name map is now a hard gate
The vault uses GoProxies; the deck uses SuperProxy and “GP.” Are these the same customer product, an internal line, a rebrand, a platform, or separate offers? Revenue and support data cannot be joined safely until the naming/ownership map is explicit.
5. The “no central data layer” inference remains open
Automated Intercom reporting proves one functional data improvement. It does not establish an org-wide source of truth. The deck itself still presents metrics without definitions, baselines, owners, or product reconciliation, which is consistent with fragmentation but not proof. The cheap falsifier remains: where does someone find last month’s numbers for a function they do not own, with definitions and row-level provenance?
Ranked gaps
P0 — must resolve before strategy claims
- Revenue perimeter and definitions. Reconcile
$75.6kversus$288k; name entities, products, gross/net/cash basis, overlap, and time window. - Burn, contribution margin, cash, and runway. Revenue growth can coexist with value destruction. Break-even is unknowable without direct costs and operating spend.
- Definition of a high-quality customer. Minimum viable definition: positive expected contribution after acquisition, payment, supply and support costs; payback inside the accepted window; retained through the chosen cohort horizon; low abuse/fraud/chargeback risk.
- Twelve-month product revenue/cohort series. One good July cannot distinguish recovery, seasonality, timing, or noise.
- SuperProxy/GoProxies taxonomy and sales-funnel states. Tests, MRR, recognised revenue, cash, churn, gross margin, supply source, and concentration.
P1 — needed to turn bets into decisions
- Experiment registry. Every big bet needs hypothesis, owner, baseline, cohort/holdout, launch date, primary metric, guardrails, decision date, and kill/scale rule.
- Payments causality. Approval rate, decline taxonomy, recovery, fraud, chargebacks, fees, involuntary churn, and geographic/issuer mix.
- VPN LTV truth. Actual versus target, formula, cohorts, CAC/payback, and which driver explains the gap.
- Node-incentive unit economics. Cost per incremental persistent quality node; utilisation and revenue per node; token exposure; fraud/Sybil controls.
- Paid-test conversion system. Conversion rate and time, contracted MRR, gross margin, reasons lost, capacity bottlenecks, named owner.
P2 — compounding infrastructure
- Voice-of-customer operating loop. Support tags must flow to a ranked product queue and back to customers; otherwise reporting becomes a prettier archive.
- Support knowledge architecture. The product is too broad for memory-based support. Build a governed taxonomy, source-linked answers, ownership, freshness, and feedback from unresolved cases.
- Product portfolio boundaries. VPN, proxy, node supply, token/network and mission work need separate scorecards and shared dependency maps.
- Weekly definition of progress. Output shipped, leading signal moved, business outcome moved, confidence updated, next decision. A bet does not “move” because a team worked on it.
- Hiring-to-outcome link. Head of Success and copywriter should have explicit revenue-quality/retention outcomes, not activity quotas.
Language debt — the strategy may not mean the same thing across the company
Lee’s alarm is stronger than the original “define high-quality customer” gap. This is a ubiquitous-language and execution-control problem.
The Q3 instruction is effectively: prioritise anything that acquires high-quality customers; defer everything else. If “high-quality customer” is undefined, the prioritisation rule itself is undefined. Marketing, Sales, Product, Payments and Support can all claim alignment while selecting different customers, metrics and work.
The deck already shows possible vocabulary drift:
- “high-quality customers”;
- “new qualitative users”;
- “customers” versus “users”;
- “healthy growth”;
- “real traction”;
- “momentum” and “consistency”;
- “progress”;
- “meaningful impact”;
- “what matters”;
- “build for years” / “build for the long term”;
- “no red flags.”
These are not decorative phrases. They allocate resources, determine whether a bet survives, and shape how performance is judged.
Lee’s test, via Napoleon: orders must not merely be easy to understand; they must be impossible to not understand.
The dangerous time problem inside “high-quality customer”
Customer quality is partly unknowable at acquisition. The operating language therefore needs at least two terms:
- Predicted high-quality acquisition — a newly acquired customer who, using observable acquisition-time signals, is likely to meet the quality criteria.
- Realised high-quality customer — a customer who actually met those criteria after the agreed observation period.
Without this distinction, Marketing is ordered to acquire something that can only be identified retrospectively. It also becomes impossible to learn whether the acquisition model predicted quality correctly.
One company definition should provide the common economic spine, with product-specific implementations beneath it:
- VPN: contribution after CAC, payment and network costs; D30/D90 retention; refunds; chargebacks; abuse risk; payment failure; support load.
- SuperProxy: paid-test conversion; contracted recurring margin; time to conversion; delivery/implementation burden; credit/default risk; bandwidth economics; retention and concentration.
- MystNodes: a supply participant is not a customer. Node quality requires separate language around persistence, uniqueness, residential/ASN characteristics, usable traffic, abuse and incentive economics.
A provisional company spine is:
A realised high-quality customer is a customer whose contribution after acquisition, payment, network/supply, refund, abuse and support costs exceeds the agreed hurdle; whose payback and retention meet the product-specific thresholds; and whose operational burden remains inside the accepted range.
The definition is not operational until the thresholds and observation windows are filled from MN’s economics.
A term needs an operating contract, not a glossary sentence
Each load-bearing term should contain:
| Field | Required answer |
|---|---|
| Definition | What does the term mean? |
| Formula or classification test | How is it calculated or decided? |
| Threshold | What qualifies and what does not? |
| Observation window | When does the judgment become valid? |
| Data source | Where does the answer come from? |
| Positive examples | Which cases clearly qualify? |
| Counterexamples | Which tempting cases do not qualify? |
| Decision consequence | What action changes when the term applies? |
| Owner and version | Who resolves ambiguity, and when did the meaning change? |
This should become a small, versioned Mysterium Operating Language: perhaps 10–20 genuinely load-bearing terms, not a bureaucratic encyclopedia. It must be embedded in all-hands slides, dashboards, OKRs, experiment briefs, roadmap templates, onboarding, performance conversations and weekly bet reviews. A new strategy term should not enter a company-wide deck without referencing an existing definition or creating one.
“Build for the long term” needs a decision procedure
The deck says:
- “Think long-term. Deliver progress now.”
- “Build for the long term — show progress every week.”
- “Build for years. Show progress every week.”
The principle is directionally good but does not resolve a conflict between infrastructure, brand/organic acquisition, enterprise sales, decentralisation, technical debt, open-source adoption, payments, retention or other defensible “long-term” work.
A usable definition is closer to:
A long-term initiative creates or strengthens a durable capability, asset, advantage or risk reduction that compounds beyond the current quarter. It names the future outcome, causal hypothesis, owner, leading indicator, next evidence-producing step and kill criterion.
“Weekly progress” also needs an evidence hierarchy; otherwise it rewards output theatre:
- Customer behaviour or economic outcome changed.
- A material risk or uncertainty was reduced.
- A causal hypothesis was validated or invalidated.
- A reusable capability became operational.
- Something was shipped.
- Work was performed.
Only the first four are strong evidence by default. Shipping may be progress, but not automatically; activity alone is not progress. “Payment orchestration went live” is a milestone. “Authorisation increased by X%, recovered revenue increased by Y, and false declines fell by Z” is progress.
Test alignment; do not ask whether people understand
Self-reported understanding is nearly useless. Test the language independently:
- Give Marketing, Sales, Product, Finance and Support the same ten customer cases.
- Ask each person to classify them and explain why.
- Repeat with ten initiative cases: which represent meaningful weekly progress on a long-term bet?
- Compare both the classifications and reasoning.
- Require at least 80% agreement before treating the term as operational; adjudicate every high-consequence disagreement.
The disagreements are the valuable output. They reveal where ostensibly aligned teams are operating different companies in their heads.
The strongest falsification question is not “What is your definition of a high-quality customer?” It is:
Show the written definition, thresholds and dashboard; then test whether Marketing, Sales, Product and Support independently classify the same ten customers the same way.
If they can, the language is real. If they cannot, this is one of the most consequential operating gaps exposed by the all-hands deck.
July’s 80/20 — growth attribution and the truth/celebration architecture
Lee’s second alarm is equally important: what small fraction of July’s effort produced most of July’s growth? The deck celebrates the aggregate result and lists many activities, but does not show a causal bridge from interventions to outcomes. “Many different things added to it” may be true; it may also be the default story produced when nobody has done the attribution work.
The stronger question is:
Which small number of interventions produced most of the incremental retained contribution, with what confidence, after accounting for timing, spend and lag?
This is better than asking only which 20% of work produced 80% of revenue. Revenue can be bought with inefficient spend, created by one-offs, shifted between periods, or generated by customers who churn quickly. The economically relevant numerator is incremental retained contribution; the denominator should include money, team effort and operational burden.
Build a July growth bridge before telling a causal story
Reconcile the result as:
June baseline → acquisition volume → conversion → price/mix → retention → reactivation → payment recovery → proxy tests/contracts → one-offs → calendar/FX → July result
Split the bridge by:
- product;
- channel and campaign;
- country;
- plan;
- customer type;
- new, renewed and reactivated revenue;
- paid test versus contracted recurring revenue;
- gross revenue versus retained contribution.
Then rank interventions in a compact table:
| Intervention | Launch/exposure date | Incremental outcome | Spend | Team effort | Confidence | Lag |
|---|---|---|---|---|---|---|
| — | — | — | — | — | — | — |
The resulting efficiency measure is approximately:
incremental retained contribution ÷ (money + team effort + operational burden)
Fake precision is unnecessary. A truthful first pass can classify the July increase as strongly evidenced, probable, weakly evidenced and unexplained.
The screenshots already eliminate several explanations
Temporal order is a powerful falsifier. Several visible initiatives cannot plausibly explain most of July:
- Payment Orchestration went live on 23 July, and the deck itself says its first impact should be visible after a month.
- Router support launched on 29 July, leaving three July days including launch day.
- Android OpenVPN and the public repository are dated 4 August, after the measured month.
- News Center was still hidden.
- Adyen fallback, cancellation flow, favourite IPs and Linux CLI were future bets.
These may become valuable; they are not credible explanations of July’s aggregate result.
The visible plausible candidates are VPN recurring revenue returning to May’s level, paid-ad web revenue growing 15%, SuperProxy’s $9,084 of paid tests plus $2,544 of new MRR, and tier-3 acquisition. But the deck does not permit attribution:
- paid tests are reported as a total, not an incremental change;
- paid-ad growth has no absolute base, spend, margin or retained cohort quality;
- VPN recovery has no dollar bridge or identified mechanism;
- tier-3 “good ROAS” has no cohort retention, chargeback, support-cost or contribution evidence.
The honest answer may therefore be that part of July’s growth is still unexplained. That is not failure. Unexplained growth is a management fact and a direct instruction to improve instrumentation.
“July is usually slow” also needs an evidence contract
The seasonal claim makes the celebration feel stronger, but the screenshots do not substantiate it. Test it with:
- 31-versus-30-day normalisation;
- July 2024, 2025 and 2026 by product and channel;
- a pre-stated seasonal baseline or forecast;
- adjustments for product mix, campaign timing and one-off revenue.
Until then, “despite the summer slowdown” is a plausible narrative, not a proven causal fact.
Celebration and radical truth are different meeting functions
There is a false choice between turning the all-hands into a hostile interrogation and preserving morale by leaving the causal story unexamined. The better operating principle is:
Celebrate the result; interrogate the explanation.
Radical truth should be a property of the operating system, not an unmodulated emotional register at every moment. A strong cadence separates three functions while guaranteeing that none disappears:
- Celebration: recognise the result, effort and people.
- Truth layer in the all-hands: state what changed, the likely causes, confidence, unknowns, biggest miss or surprise, and the next evidence action.
- Operational review within 24–72 hours: examine the growth bridge, effort-to-impact ranking, attribution gaps and experiments; decide what to scale, hold or kill.
The danger is not celebration. The danger is celebration without a guaranteed analytical sequel. That conditions the organisation to accept good news at a lower evidentiary standard than bad news.
Practical ways to lower the “festivity tax” on truth:
- invite questions before and during the meeting;
- include a standing “What could make this result misleading?” slide;
- assign a rotating truth-seeker or red-team role;
- have the leader name uncertainty first, making scrutiny socially safe;
- label claims as known, inferred or unknown;
- keep a question parking lot with a data owner and answer date;
- schedule the operational follow-up before the celebration ends.
Lee’s position in the room
Staying quiet as an unintroduced fly-on-the-wall listener was reasonable. The organisation had not yet granted Lee a clear social or analytical role, and an unframed challenge during celebration could be misread as status behaviour rather than useful inquiry.
The clean future question is:
The July result looks genuinely encouraging. Has anyone built a growth bridge showing which interventions explain the increase, what remains unattributed, and which actions produced the highest retained contribution per unit of effort?
The sharper follow-up is:
If we could preserve only two July interventions, which two would the evidence tell us to keep?
One-page diagnostic to request
A July Growth Attribution Map should contain four buckets:
- strongly evidenced drivers;
- plausible drivers;
- temporally impossible drivers;
- unexplained growth.
For each item: owner, start date, affected segment, incremental outcome, cost, retained contribution, confidence and next validation step. Building this single month’s map is an excellent early Kairos diagnostic. Automating it company-wide would be a separate scope and authority decision.
Kairos operating intervention — from ambiguity to a measured torpedo
The ubiquitous-language problem and the July-attribution problem are not two independent observations. They are consecutive failures in one operating chain:
shared meaning → comparable evidence → causal explanation → ranked decision → live intervention → measured learning
If “high-quality customer” is undefined, teams cannot measure acquisition quality consistently. If July’s drivers are unattributed, leadership cannot know which work to repeat. If neither layer is reliable, a torpedo is chosen by enthusiasm or status rather than expected value. Kairos’s role is to repair the chain just far enough to make one consequential decision and test it—not to spend the month producing a beautiful diagnosis.
Kairos intervention stack
| Layer | Kairos output | Decision enabled | Proof that the layer works |
|---|---|---|---|
| 1. Meaning | Mysterium Operating Language v0.1: operational definitions for high-quality customer, recurring revenue, new revenue, retained contribution, progress, long-term bet and paid test. | Teams classify the same customer and initiative consistently. | Cross-functional case test reaches ≥80% agreement; disagreements are adjudicated. |
| 2. Economic truth | Definition-bound revenue perimeter and product/channel contribution bridge. | Leadership knows what $288k, $168k, $87k and the older $75.6k do—and do not—represent. | Every headline number has entity, product, period, currency, gross/net and recognition labels. |
| 3. Causality | July Growth Attribution Map plus an effort portfolio. | Leadership knows which interventions to repeat, investigate, stop or leave unexplained. | Most material dollar movement is assigned a confidence level; no effect is attributed before exposure. |
| 4. Choice | One-page decision board ranking levers by expected retained contribution, evidence readiness, reversibility, time-to-signal and implementation dependency. | One torpedo is chosen for information value and economic proximity, not narrative appeal. | Sponsor records why this lever beat the alternatives and what evidence would reverse the choice. |
| 5. Torpedo | Pre-registered intervention brief: hypothesis, counterfactual, cohort, owner, insider path, metric, guardrails, cost, decision date and kill/scale rule. | The team can act without redefining success after seeing the outcome. | The intervention fires, produces interpretable data and ends in scale, iterate or stop—even if the result is null. |
| 6. Learning loop | A compact Monday Update and reusable all-hands truth layer. | Evidence changes the portfolio and compounds into the next decision. | At least one resource allocation, workflow or belief changes because of measured evidence. |
The first Kairos packet
The minimum viable packet is five connected artifacts, not a company-wide BI rebuild:
- Operating Language v0.1 — one-page term contracts and ten-case alignment test.
- July Growth Bridge — dollars reconciled from June baseline to July result.
- July Attribution + Effort Map — drivers ranked by confidence and retained contribution per unit of resource.
- Decision Board — one recommended torpedo, alternatives, assumptions and reversal evidence.
- Torpedo Contract — named owner and implementer, pre-registered measurement, decision date and kill/scale rule.
The first four aim the torpedo; the fifth prevents Kairos from becoming the diagnosis-only team Gitanas feared.
Roles and authority
- Lee / Kairos research lane: extract definitions, reconcile claims, expose contradictions, build the causal model and specify what is known, inferred and unknown.
- Šaras / Kairos torpedo lane: pressure-test the hypothesis, simplify the live test, force a decision and drive execution to measured data.
- Mysterium sponsor: grant data access, settle definition disputes, choose the decision owner and protect the truth-seeking mandate.
- Finance/data owner: certify the economic perimeter and calculations.
- Named insider implementer: execute any change touching an existing product, billing flow, customer surface or production system.
Kairos owns the diagnosis-to-experiment chain within the agreed scope. It does not silently acquire product authority, financial sign-off, production access or the mandate to police every meeting. Those remain explicit gates.
Proof standard for Kairos itself
Kairos should be judged by whether it improves decisions and produces measured movement, not by the volume of analysis. A credible first-month proof would show:
- one strategically important phrase converted from rhetoric into a tested operating definition;
- July’s material movement reconciled into evidenced, probable, impossible and unexplained drivers;
- one low-evidence or low-return activity explicitly deprioritised;
- one reversible torpedo fired with a pre-registered measurement contract;
- one interpretable result—positive, negative or null—that changes the next allocation;
- the all-hands cadence retaining celebration while gaining a mandatory truth layer and analytical sequel.
This is the Kairos promise in miniature: make the organisation harder to fool, then turn the sharper picture into action.
Highest-value opportunities
Opportunity 1 — the Quality Customer Scoreboard
Turn the Q3 slogan into one shared weekly table by product and acquisition channel:
customers acquired → activation → paid conversion → retained D30/D90 → revenue → direct costs → contribution → CAC → payback → refunds/chargebacks → support cost → abuse flags
This becomes the filter for tier-3 ads, nostalgia/NFL content, store localisation, APIs, paid tests, cancellation flow, and Linux CLI. It also prevents “acquisition” from overruling retention and economics.
Opportunity 2 — Paid-Test Conversion Strike
The screenshot gives enough evidence to act: $9,084 of $11,628 sits in paid tests. Build a single test-to-contract board with next action, technical blocker, economic buyer, success criterion, end date, conversion likelihood, expected MRR, margin, and owner. Review twice weekly until the cohort resolves. The result is not “more follow-up”; it is a measurable conversion rate and a map of why tests fail.
Opportunity 3 — Payment-Recovery Torpedo
Payments Orchestration is already instrumented and Adyen fallback is planned. This is unusually close to revenue. Pre-register a clean test: eligible failure classes, Stripe baseline approval, routed cohort, Adyen recovery, incremental captured revenue, fees, fraud/chargeback guardrails, issuer/geo segmentation, and 30-day retained value. This can become the first defendable Kairos torpedo if ownership and data access are ready.
Opportunity 4 — VPN Retention Stack
Combine cancellation reasons, payment failures, support billing requests, cohort retention and the new cancellation flow. Separate voluntary churn from involuntary churn. Offer helpful save paths—pause, plan change, troubleshooting, payment retry—without obstruction. Judge success at 30/90 days, not at the click where cancellation was delayed.
Opportunity 5 — Poland Incentive Economics
Treat Poland as an experiment, not a victory slide. Reconstruct baseline nodes, incentive start, absolute lift, cost, D7/D30 persistence, unique IP/ASN/residential quality, traffic served, earnings, support contacts, abuse, and revenue. Compare with matched non-incentivised countries or stagger the next activation. Scale only if incremental quality supply is economically used.
Opportunity 6 — Support Data → Product Decision Loop
The Intercom automation is a seed of the org intelligence layer. Define the top recurring customer problems by product, cohort, revenue risk and support cost; name product owners; publish fix status; then measure whether volume falls. This is ordinary paid-work scope as a diagnostic. Any material company-wide intelligence build remains Mammoth-class: no material pursuit without a signed Opportunity Schedule.
Opportunity 7 — Weekly Bet Registry
The leadership cadence is right but the success language is soft. Give every big bet one row:
bet · problem · owner · product · baseline · this week’s shipped change · leading signal · outcome signal · confidence · blocker · next decision/date · scale/hold/kill
No status theatre. “No movement” is allowed; it triggers a decision.
Reversible torpedoes
| Torpedo | Product touch | Primary metric | Guardrails | Decision |
|---|---|---|---|---|
| Adyen fallback on eligible Stripe failures | Yes — payments | Net recovered retained revenue | fraud, chargebacks, fees, latency, issuer/geo bias | Scale by failure class or stop. |
| Convert July paid-test cohort | Sales + product as needed | Test-to-MRR conversion and days | margin, concentration, delivery capacity | Standardise winning path; kill weak segments. |
| Tier-3 geo acquisition cohort | Marketing/pricing | D30/D90 contribution per acquired customer | refunds, abuse, support cost, payment failure | Scale only countries beating threshold. |
| Cancellation-flow cohort | Yes — VPN | D30/D90 retained contribution | support contacts, complaints, refund/chargeback, dark-pattern review | Keep helpful saves; remove friction-only elements. |
| Next dynamic-incentive country with holdout/stagger | Yes — nodes | Cost per persistent utilised quality node | Sybil/abuse, token leakage, support burden | Scale only if usage economics clear. |
| Favorite IPs cohort | Yes — VPN | repeat successful connections and retention | reliability, privacy, support | Keep if it changes behaviour, not because requested. |
| Linux CLI demand smoke test before heavy build | Limited | qualified waitlist/design partners willing to pay | maintenance/security estimate | Build only with a credible segment and owner. |
For every product-touching torpedo, pre-agree the named insider implementer before launch. Otherwise Kairos will reproduce Gitanas’s feared pattern: diagnose correctly, then stall at the intervention boundary.
Questions for the next room
Economic truth
- What exactly is inside the
$288ktotal—entities, products, revenue types, and dates? - Is
$288kgross billings, recognised revenue, cash collected, or net revenue? - Are
$168krecurring and$87knew revenue mutually exclusive and additive, or do they overlap? - What is the remaining revenue category if they are additive?
- The 07-17 recollection carried roughly
$75.6kwhile the deck implies$264kfor the same June. Did the 07-17 all-hands voice only the VPN and GoProxies lines — and what was June’s actual total then? - What are gross margin and contribution margin by VPN, proxy, paid test and node/network line?
- What is monthly operating burn, cash runway, and cuttable versus protected spend?
- Which legal entity owns each revenue line, cost line, customer contract and payment account?
- What counts as “substantial results” at Kairos’s month-one continuation gate, and who decides?
High-quality customers
- What is the company’s quantitative definition of a high-quality customer?
- Which retention horizon matters: D30, D90, annual renewal, or contract term?
- What payback window and contribution threshold are acceptable by product?
- How are refunds, chargebacks, payment fees, supply costs, support costs and abuse risk included?
- Which July channels produced the best retained contribution, not merely revenue?
VPN
- Show 12 months of VPN MRR, active paid users, ARPU, new adds, reactivations, voluntary churn, involuntary churn, refunds and payment failures.
- What caused recovery to May level—new acquisition, reactivation, fewer failures, price/mix, annual plans, or timing?
- What are current and target LTV, with the exact formula and cohort split?
- Which tier-3 countries were targeted, at what spend and price, and what are their D30/D90 economics?
- Were the
+5.1%and+15%comparisons 31 equal days or July’s 31 versus June’s 30? - What is paid-ad ROAS after refunds, chargebacks, processor fees, tax, support and retention?
- What should cancellation flow change, and what would count as harmful friction?
- What usage/adoption did router support and Android OpenVPN unlock?
- What evidence supports Linux CLI as a commercial segment rather than an enthusiast feature?
- What is the adaptive-pricing hypothesis, owner, readiness blocker, price floor/ceiling and rollback?
SuperProxy / GoProxies
- Are SuperProxy, GP and GoProxies the same product/economic line? If not, map them.
- What exactly is the
$11,628: booked sales, invoiced tests, collected cash, recognised revenue, or contract value? - How many paid tests produced
$9,084, and what are their sizes and end dates? - What percentage of paid tests convert to MRR, how long does it take, and what happened to prior cohorts?
- What is proxy MRR, gross margin, logo concentration, churn and net retention?
- Which constraint is dominant: lead quality, sales process, product capability, supply quality, pricing, legal/compliance, or implementation?
- What customer evidence supports enterprise, Real Estate API and SERP API as the top bets?
- Which proxy SKUs use MN nodes versus upstream supply, at what transfer/direct cost and consent/risk profile?
Payments
- What was Stripe’s baseline authorisation and failure mix before 07-23?
- Which payment failures are technically recoverable through Adyen and which are not?
- How will network tokens, independent 3DS and adaptive 3DS be isolated from seasonality, traffic mix and one another?
- What are the primary metric, holdout/comparison, measurement window and fraud/chargeback guardrails?
- What net incremental retained revenue would justify the orchestration and second-processor cost?
MystNodes
- What does “33,000 nodes” mean—registered, online, active, unique IP, daily average, or available at capture?
- What was Poland’s absolute baseline and lift, incentive amount, start date, and observation window?
- How many incremental nodes persisted at D7/D30 and served paid traffic?
- What is cost per persistent utilised quality node and revenue/contribution per node?
- How are Sybil, duplicate-IP, datacenter/residential, ASN, geo, quality and abuse controlled?
- Did Launcher optimisation, notifications or bug fixes cause the broader pool increase, or were they bundled?
- How does token-price movement affect node acquisition, retention, payout promises and company cost?
Data, support, and execution
- Where does a team member find last month’s numbers for a function they do not own, with definitions and source rows?
- What percentage of Intercom conversations is correctly tagged, who owns taxonomy, and how fresh is the report?
- What clear customer profile was identified, from how many users, and does it differ by VPN versus proxy?
- Which product/support gaps are now visible, ranked by revenue risk and contact volume?
- Why was Growth’s “biggest struggle” placeholder left empty, and who owns completing the next all-hands source?
- Which named implementer will execute product-touching torpedoes, and what turnaround time is committed?
- For every “biggest bet,” what are the owner, baseline, weekly signal, decision date and kill rule?
What not to conclude
- Do not conclude Mysterium is profitable from
$288krevenue; burn and contribution are absent. - Do not conclude VPN decline is solved because July recovered to May; one rebound is not a trend.
- Do not conclude proxy is stable because the sales target was beaten; most displayed value is paid tests.
- Do not conclude node growth creates value; incentive economics and utilisation are absent.
- Do not conclude Domain Rating 60 equals acquisition quality.
- Do not conclude the central-data-layer gap is solved by automated Intercom reporting.
- Do not conclude 30–36 meeting participants equals paid headcount.
- Do not conclude product activity equals customer impact; most product slides lack adoption and retained-value measures.
Recommended Kairos week-one use
- Draft Operating Language v0.1 and run the ten-case cross-functional alignment test.
- Build the July growth bridge and attribution map, preserving unexplained movement instead of forcing a story.
- Reconcile the economic perimeter and publish one definition-bound revenue/cost map.
- Rank the effort portfolio by retained contribution, evidence readiness and operational burden.
- Select one torpedo—payment recovery or paid-test conversion remain closest to cash on current evidence.
- Name the insider implementer for any product touch and pre-register the measurement contract.
- Report the first measured signal weekly, including failure or no movement, and record what decision changes.
This is the shortest route from “strong July” to evidence that deserves continuation after month one.
Independent review — completed
Tris adversarial review ran 2026-08-08; verdict upheld in substance (filed in the vault at 90-system/agent-reviews/). Verified without change: all arithmetic (re-derived independently), the transcription layer (two slides read directly from the original pixels; all 13 manifest hashes match), atom coverage, temporal falsifiers, opportunity ranking, and authority boundaries.
Changes applied 2026-08-09 from the review’s challenges, on Lee’s instruction:
- The headline contradiction re-paired to the same month — deck-implied June
$264kvs the$75.6kJune canon (3.5×) — replacing the month-mixing 3.8× framing. - Evidence asymmetry named: the old baseline is a meeting recollection, likeliest a partial capture; only the old figure is now blocked from use, and deck figures are usable with perimeter labels.
- The 31-day marketing footnote re-read as window hygiene, with the deflated alternates retained as a conditional.
- Ledger legend completed (ADAPT, compound verdicts); the Nostalgia fear-framed creative added as atom 29a.
- Evidence originals archived into the vault beside this report and hash-verified against the manifest.
Unresolved disagreements: none material. Adjudication receipt remains with Talos.