VPN business-health benchmarks — 2026-08-11
Verdict
Solid comparison data exists, but not as one clean current database of premium VPN companies. The defensible benchmark is a three-layer stack:
- VPN and consumer-cybersecurity company disclosures for retention, subscriber growth, recurring-revenue mix, cash conversion and profit;
- large subscription-app datasets for plan-specific cohort retention, refunds and billing-related cancellations;
- payment-platform data for first-attempt failures, recovery and peer benchmarks.
The stack is useful only if MN freezes the metric definitions first. A 75% Stripe failure rate could mean unique recurring invoices failing on their first attempt, failed charge attempts including repeated retries, declined new checkouts, or the share of cancellations attributed to billing. Those are different quantities. Comparing them creates fake reassurance or fake panic.
Blunt answer: if 75% means unique recurring subscription payments that failed on their first attempt, it is not an inevitable industry norm. Stripe's published subscription baseline is 9%, so 75% is about 8.3× that reference and leaves only a 25% first-attempt acceptance rate. Treat that as a critical defect or a badly defined metric until the data proves otherwise. If 75% counts every retry attempt, it may be heavily inflated by the retry policy and cannot be benchmarked as a customer or invoice failure rate.
Snapshot: 2026-08-11. Kape figures are historical public-company disclosures; current private VPN leaders generally do not publish churn, failure rate or LTV.
What the external evidence actually gives us
| Layer | Source and period | Exact disclosed metric | What it can benchmark | Comparability limit |
|---|---|---|---|---|
| Pure-play VPN / privacy | Kape 2021 Annual Report | 81% retention, explicitly calculated on a six-month basis; 92% pro-forma recurring-revenue share; 20% organic customer growth; 33.8% pro-forma adjusted EBITDA margin |
Mature premium-VPN portfolio health. Kape included ExpressVPN, CyberGhost and Private Internet Access. | Kape does not disclose enough of the retention formula to convert 81% safely into monthly churn. It is not necessarily new-cohort survival. |
| Pure-play VPN / privacy | Kape FY2022 final results | 7.4m paying subscribers, +12%; 86.8% recurring revenue; $176m / $623.5m = 28.2% pro-forma adjusted EBITDA margin; 94% adjusted cash conversion |
Scale, recurring mix, profitability and cash-quality anchors for a healthy premium-VPN portfolio | Group-level; post-acquisition; no payment-failure or plan-specific retention disclosure. |
| Consumer cybersecurity / privacy adjacent | Gen Digital FY2025 10-K | 78% annual direct-customer retention, 40.4m direct customers, $7.26 monthly ARPU |
Mature consumer cyber-safety retention and ARPU anchor; Gen sells Norton/Avast/AVG VPN and suites | Multi-product, annual-plan-heavy, not a pure VPN cohort. This was Gen's last granular retention disclosure found; FY2026 changed reporting. |
| Consumer cybersecurity / privacy adjacent | Gen Digital FY2026 10-K | Cyber Safety Platform revenue $3.339b, up 5.1% reported from $3.176b; segment operating income $2.041b; 79m total paid customers across the enlarged group |
Current scale and profitable-growth context | Includes security suites and consolidated allocation; the segment margin is not directly comparable to MN's entity P&L. |
| Subscription apps | RevenueCat State of Subscription Apps 2026 | Dataset: 115,000+ apps and $16b+ revenue. Monthly-plan six-month cohort retention: 14–26% median, 30–50% top quartile. Year-one annual-plan retention: 20–40% median, 32–59% top quartile. First monthly renewal: 53–61% median across categories. Refunds: most categories 3–4% median. |
A current harsh consumer-app floor, segmented by plan duration and cohort age | Category bucket is broad; app-store cohorts are not direct-web VPN renewals. Cohort survival must not be mixed with Kape's rolling retention metric. |
| App-store billing | RevenueCat 2026 | Billing errors are 15.2% of App Store cancellations and 32.2% of Google Play cancellations |
Involuntary-churn composition by store | This is the share of cancellations, not payment failure rate and not the share of all subscribers. |
| Subscription payments | Stripe payment-method guide | 9% of subscription invoices fail on the first charge attempt due to involuntary-churn causes |
Public first-attempt recurring-payment baseline | Older Stripe publication; broad subscription mix, not VPN-specific. Use as a reference, then prefer MN's live Stripe peer benchmark. |
| Subscription payments | Stripe Revenue Recovery analytics | Failure rate = recurring subscription payment volume failing on the first attempt; recovery rate = initially failed volume later recovered. First post-trial invoice is excluded. | The definition MN should reproduce exactly | MN's orchestration may span processors and may need a separate all-processor definition. |
| Subscription payments | Stripe Billing features | Smart Retries recover 57% of recurring payments that originally failed on average; Stripe says nearly a quarter of churn is involuntary |
Recovery-rate reference and size of the preventable problem | Stripe-wide product result, not a promise for MN's geography, risk or payment mix. |
| Matched peer benchmark | Stripe Billing benchmarking | Top/median/bottom trends from at least 100 similar businesses selected by MCC, inferred industry, ARR and ARPU; metrics include churn, retention, MRR growth, LTV, ARPU and trial conversion. Stripe's current features page also lists subscription payment failure rate. |
Best available live peer set if MN's account is eligible | Account-only; the public docs and features page differ on whether payment failure is included, so confirm what the MN dashboard exposes. |
A useful Kape acquisition-efficiency anchor
Kape's 2021 annual report also discloses cumulative cash collected from new premium subscriptions relative to direct acquisition marketing spend for historical cohorts: about 0.9× in under one year, 1.4× in under two, 2.0× in under three and 3.1× in under four. It calls this TROI, not LTV:CAC. The clean lesson is that a scaled premium-VPN portfolio expected direct marketing cash payback around the first year and substantial continued cash yield afterward.
Do not turn that into an MN LTV:CAC ratio without matching Kape's definition. It excludes the contribution-margin question and uses cumulative cash collected, not profit.
The measurement dictionary MN needs
Payments
| Metric | Locked definition | Never divide by |
|---|---|---|
| Initial recurring failure rate | Unique recurring invoices failing on their first payment attempt / unique recurring invoices attempted. Report count and value. Keep first post-trial invoices separate. | All charge attempts; retries; all customers; cancellations. |
| Initial checkout failure rate | Unique new-customer payment intents that reached an authorization attempt and failed / unique new-customer intents that reached authorization. | Page visits or abandoned forms. |
| Attempt-weighted decline rate | Failed charge attempts / all charge attempts. Diagnostic only. | Do not present as invoice or customer failure. Repeated retries poison the denominator. |
| Mature recovery rate | Initially failed unique invoices paid within the completed dunning window / initially failed unique invoices. | Current-month failures still in recovery. |
| Net involuntary loss rate | Initially failed unique invoices still unpaid after the dunning window / unique recurring invoices due. Report count, revenue and MRR lost. | Total churn without separating voluntary cancellations. |
| Processor uplift | Incremental unique invoices recovered by fallback processor versus a pre-registered control or counterfactual / eligible failed invoices | All Adyen approvals; many would have succeeded later on Stripe. |
Every payment metric must split new checkout vs renewal, plan duration, first post-trial vs mature renewal, processor, country, currency, card country, payment method, card network, issuer/BIN where privacy permits, 3DS state, network-token state, decline code and retry number. Count unique invoices and attempts separately.
Retention and value
| Metric | Locked definition |
|---|---|
| Voluntary subscriber churn | Paying subscribers who deliberately cancel and become inactive / comparable active-subscriber denominator. Keep Stripe's exact denominator if using Stripe peer benchmarks. |
| Involuntary subscriber churn | Paying subscribers lost after payment recovery is exhausted / same denominator. |
| Gross MRR churn | Churned MRR + contraction MRR / opening MRR. No expansion offset. |
| Net MRR churn | Churned MRR + contraction MRR − expansion/reactivation MRR / opening MRR. |
| Cohort subscriber retention | Share of a start-month cohort still paid at M1, M2, M3, M6, M12. Split by original plan and channel. |
| Cohort revenue retention | Original cohort MRR remaining at the same ages, with gross and net views. |
| Stripe-comparable LTV | ARPU / monthly subscriber churn, using Stripe's configured definitions. This is a top-line estimate, useful only for Stripe peer comparison. |
| Economic LTV | Realised or modelled lifetime contribution, after refunds, payment fees, taxes borne, node/supply cost, variable infrastructure and variable support. Show cohort-realised value beside the model. |
| LTV:CAC and payback | Economic LTV / fully loaded CAC; payback months = CAC / monthly contribution per acquired payer. Split paid, affiliate, organic and store channels. |
An “LTV gap” without the formula, gross margin, cohort date, plan mix and acquisition channel is not a usable KPI.
Provisional operating gates
These are Kairos triage gates, not universal laws. Replace them with MN's Stripe matched-peer percentiles once the dashboard/export is available.
| Metric | Green | Amber | Red / critical | Basis |
|---|---|---|---|---|
| First-attempt recurring failure | ≤10% |
10–15% |
>15%; >25% critical |
Stripe's published 9% reference, widened for mix/geography |
| Mature recovery of initial failures | ≥57% |
35–57% |
<35% |
Current Stripe Smart Retries average |
| Net unrecovered recurring invoices | ≤5% |
5–10% |
>10% |
Roughly consistent with 9% initial failure and 57% recovery (3.9% illustrative net loss); not an independent external benchmark |
| Refund rate | ≤4% |
4–8% |
>8% |
RevenueCat median cluster and outlier range |
| Paid-acquisition cash payback | ≤12 months |
12–18 |
>18 |
Kape TROI evidence; contribution payback is stricter and preferred |
There is not enough public VPN evidence to set honest universal red/amber/green gates for monthly churn or LTV. Use Kape and Gen as reference points, RevenueCat as the consumer-app floor, and Stripe's matched peers as the actual comparator. Any fixed churn target before plan-mix and metric-definition reconciliation is theatre.
The first MN pull
Pull at least the last 13 complete months, plus daily data from the Payments Orchestration launch on 2026-07-23. Aggregate only; customer-level PII is unnecessary for the benchmark pass.
- Unique invoices due, initially paid, initially failed, eventually recovered, unrecovered after the mature dunning window, and all attempts by retry number.
- The same cut by the payment dimensions above, including Stripe-only before orchestration and Stripe/fallback afterward.
- Active paid subscribers, new paid, voluntary churn, involuntary churn, reactivations and plan migrations by month.
- Subscriber and revenue retention cohorts at M1/M2/M3/M6/M12 by plan, price, channel, country and platform.
- ARPU, gross and net MRR churn, refund rate, chargeback rate, gross margin and contribution margin.
- CAC and payback by paid ads, affiliate/content, app stores and organic; economic LTV by the same acquisition cohorts.
- Current Stripe Billing benchmark screenshots/export showing MN's peer median, top and bottom ranges, the peer-matching inputs, and which metrics the account exposes.
The first decision table should be small:
| Question | Evidence that answers it |
|---|---|
Is 75% real? |
Recompute first-attempt failure on unique recurring invoices; show attempt-weighted rate beside it. |
| Is the damage concentrated? | Country × processor × payment method × 3DS/token × decline-code contribution to failed value. |
| Is fallback incremental? | Eligible-failure control or pre-registered routing comparison, net of fees, fraud and chargebacks. |
| Is VPN decline payment-led? | Voluntary vs involuntary churn, recovered/unrecovered MRR, and retention cohorts before/after orchestration. |
| Is LTV weak because of churn, price or margin? | ARPU × cohort survival × contribution margin, split by channel and plan. |
Evidence gaps
- No current public VPN-company panel was found with matched payment failure, churn, CAC and LTV definitions.
- Kape's strongest direct-VPN retention disclosure is historical and its formula is not granular enough for monthly conversion.
- Gen is current and audited but multi-product; its latest filing no longer discloses the granular retention/ARPU table used in FY2025.
- Payment-provider averages are influenced by their customer mix and market their recovery products. They are useful anchors, not neutral ground truth.
- Stripe's public benchmark documentation lists slightly different available metrics across pages. The live MN account decides what is actually available.
Working conclusion for Kairos
The benchmark question does not justify accepting 75% as normal. It justifies forcing one clean payment-funnel reconstruction. If the recomputed unique-invoice first-attempt recurring failure rate is anywhere near 75%, payments is not a side issue; it is an emergency revenue torpedo. If it collapses toward 9–15% after removing retries and unrelated checkout events, the original number was a measurement failure—and repairing the metric is itself the first win.