first-attempt failure across 2,979 July Stripe renewal invoices (50.72% ex-Radar). Denominator reproduced twice; SQL and result hashed. The attempt-weighted 83.36% is retry inflation—it retires the ~75% family, it does not describe invoices.
Evidence-first ranking · derived blind, then adjudicated
Ranked by evidence.
No torpedo yet.
Every claim carries its grade. Every ranking publishes the condition that would flip it. And the board now has three rings—including one for what the data cannot see.
A torpedo, in this fleet's vocabulary: a decisive, launch-ready revenue strike—every gate cleared, ready to fire. Nothing on this board has earned the name yet. The title says so on purpose.
Evidence is not upside
Five ranked candidates, placed by documentary signal and potential asymmetry. Marker state shows how each one knows what it claims to know. Position never indicates launch readiness.
How to read it: further right = stronger real-world evidence; higher = bigger possible prize. Top-right—strong evidence and big upside—is where decisions get made; nothing has reached it yet. Corner labels name each region's failure or proof mode: "story risk" is a big prize on thin evidence, "operational proof" is solid evidence on a modest prize.
Troops before ghosts
The method is deliberately boring: thresholds before data, grades per claim, and a published condition under which each ranking flips. This is the condensed version a non-analyst can hold.
Model reasoning, public sources, analogies. Not zero, never sufficient alone.
Decks and dashboards—what MN says about itself. Unaudited.
Reproduced in the warehouse at known grain; queries logged and hashed.
Matches an external ground truth: processor export, finance statement, bank.
The human who owns the system confirms the semantics mean what we think.
"Troops" are L2–L4. "Ghosts" are L0–L1 standing alone. Within a level, an A–D grade scores quality—assigned per load-bearing claim, never averaged per candidate, because averaging is how fake confidence gets manufactured.
Before touching an area: "we proceed if [measurable condition]; drop if [condition]; park only on a named external blocker." Written before the evidence is read, logged if rewritten.
A detail earns investigation only if some plausible value of it can flip the proceed/drop verdict. Everything else gets one line in the log.
Proceeding requires measured numbers (≥L2) plus owner-confirmed semantics (L4). A drop can happen at any tier the moment a kill condition is met—cheap kills are wins.
Every ranking on this page states the evidence that would change it. A board that can't say what would move it isn't a ranking; it's a mood.
Leaks and levers in the measured business
Candidates derived from MN's own operating data. This is where the troops are—and where the honest ceilings get stated next to every rate.
Payment Recovery rescuing failed subscription payments
Half of July's Stripe renewal invoices failed on first attempt. The failure is measured, persistent and concentrated—what remains unmeasured is exactly how much of it is recoverable.
Subscriptions renew by charging the customer's card automatically. In July, half of those charges failed on the first try. Some failures are customers who chose to leave—nothing to rescue there. Many are cards that just didn't work that day: no balance, expired, a prepaid card that ran dry. Recovery means winning back that second group—for example, a card that declines for insufficient funds on the 1st usually has balance again mid-month, so a retry timed to payday keeps the customer without them lifting a finger. What nobody has measured yet: how much of MN's failed pool is rescuable rather than customers who meant to quit. Measuring exactly that is this lane's next step.
July's still-unpaid renewal invoices—Stripe-only, before voluntary correction. This sizes the problem, not the prize. And Stripe is only 38% of July gross ($87.9k of $230.3k); the other gateways are blindspot row 1.
canonical recurring failure, H2-2025 into 2026; mature recovery runs 15.0–19.5% on settled cohorts. insufficient_funds is the largest addressable pool; prepaid and debit cards carry most first failures.
Load-bearing claims, graded10 claims · grades L2-A to absent
- L2-A
July 2026: 2,979 Stripe renewal invoices, 1,528 first-attempt failures = 51.29% (50.72% ex-Radar). Denominator independently reproduced twice; SQL + result hashed.
- L2-B
Persistent, not a spike: canonical recurring failure 38.5–43.8% (H2-2025) → 46–56.7% (2026). Single pipeline, method visible.
- L2-B
Mature recovery is weak: 15.0–19.5% for Jan–Jun 2026 cohorts by cutoff.
- L2-A
July still-unpaid renewal face value $19,187—one amount per invoice, derived twice independently.
- L0-B
External reference: Stripe's published subscription first-attempt failure baseline ≈9%; MN runs more than 5× that. Older publication, broad mix.
- L0-C
The open gate: the recoverable (involuntary) share of the unpaid pool. The voluntary-cancellation test is pre-registered but unrun—blocked on warehouse auth. Invisible-invoice caveat noted at the grain level.
- L2-B
Failure concentration: insufficient_funds is the largest addressable pool (23.6% recovery); prepaid 31.3% and debit 48.9% of first failures.
- L2-B
Payments Orchestration shows no detectable first-attempt improvement yet (52.35% pre vs 53.18% post, right-censored). Descriptive split, non-causal.
- L2-A
Stripe is $87.9k of $230.3k July gross (38%)—apple, google, coingate and paypal carry the rest, unexamined.
- L4 · absent
Decline-code semantics, dunning rules and orchestration scope—owner answers outstanding, including whether previously_declined_do_not_retry is intentional.
If the failed pool turns out to be dominated by customers who meant to cancel, plus charges that never resolve either way—pushing conservative rescuable value below ~$2k/mo—payments drops off the lead. That is the number that would change this page.
Retention Economics (pricing × churn)
Revenue doubled in 24 months on price, not volume—and first-renewal retention on recent monthly cohorts now sits materially below the external corridor. The level is measured. The cause is deliberately not yet claimed.
MN doubled revenue by charging more, not by winning more customers. The open question is what that did to loyalty: of the people who start a monthly plan now, only about one in three pays a second month—against an industry norm above one in two, and below MN's own 2024 customers. Two suspects, deliberately kept apart: the higher prices, or a shift in who's buying (more customers from countries and app stores where everyone quits sooner). One warehouse query can tell the suspects apart—and the answer changes the move. If price did it, the finding is "stop raising." If the customer mix did it, the price rises were free money and the leak is elsewhere.
Average ticket $10.52 → $18.19 across the tier repack; purchase count nearly flat. The doubling was a pricing event—which proves the lever can move revenue at 2× scale.
on recent monthly cohorts, against a 53–61% external median (RevenueCat, 115k apps) and down ~7 points from 2024 cohorts across the repricing window. No loyalty plateau: long-tenure survivors still decay ~8%/mo.
Price is one hypothesis. Geo/channel mix shift is the named rival: survivors skew web-card tier-1/2 ≈2.5× Google-Play tier-3. Claiming either now would outrun the evidence.
Load-bearing claims, graded5 claims · the cause is the L0
- L2-B
Revenue doubled in 24 months price-led: new-purchase count +19%, average ticket +73% ($10.52 → $18.19); the tier repack did it. Survives the duplication correction.
- L2-B
First renewal on recent monthly cohorts ≈32% vs 38–40% for 2024 cohorts—a ~7pt deterioration across the repricing window; cross-validated in two independent tables.
- L2-B
2026 new-purchase volume drifts down since January (7,160 → 6,346).
- L0-C
The cause of the deterioration. Price (elasticity) is untested hypothesis H1; seasonality, marketing and store-mix shift have equal standing—survivor skew makes mix shift a serious rival.
- L1-C
MN itself intends adaptive-pricing tests "hopefully end of August" (all-hands; ownership risk flagged)—a live attachment point for pre-registered measurement.
Per-tier, per-geo cohorts showing the deterioration is a mix-shift artifact re-park the pricing half. And if elasticity shows the 2026 volume drift is price-caused, the upside flips sign—the finding becomes "stop raising prices," still decision-grade.
Paid-Test Conversion turning paid proxy trials into contracts
Still the strongest asymmetry story on the board—a first-party paid cohort with contract upside—told entirely at L1. The data that would grade it sits on MN's side, and the cohort decays while it waits.
MN's second product line, GoProxies / SuperProxy, sells businesses access to the internet through real residential addresses—companies use it for price monitoring, ad verification, and collecting public web data at scale. In July, businesses paid $9,084 just to try it. This candidate asks: do those paid trials become long-term contracts, and can Kairos help them convert? The catch: the answer lives in MN's sales records, not in the analytics warehouse Kairos can query—so the candidate is parked until that ledger arrives, and it loses value daily as the trials wrap up.
July proxy result in paid tests (78.1%), new MRR $2,544—deck figures, unreconciled. Paid intent, not recurring revenue.
Proxy revenue appears in none of the 24 warehouse datasets—verified, not assumed. Attribution at any grain is currently impossible with granted access.
Oct-2024 added €2.2k MRR against a 15/17/21 OKR, upsell headroom was called exhausted, deal sizes fell. The burden of proof rises; the story must answer its own history.
Load-bearing claims, graded4 claims · why this parks
- L1-B
July: $11,628 vs $8.5k target; 78.1% is paid tests ($9,084); new MRR $2,544. One deck, no reconciliation.
- L2-A
Proxy revenue is not in the warehouse at all—verified across all 24 datasets.
- L1-C
Adverse history: Oct-2024 proxy push added €2.2k MRR vs a 15/17/21 OKR, with upsell headroom called exhausted and deal sizes falling.
- Absent
Prior-cohort test→MRR conversion rate—nowhere in Kairos evidence.
One clean cohort ledger showing strong test→MRR conversion at stable deal size promotes this sharply. It keeps its candidate page and its moat story—as an L1-graded story.
The July cohort decays as tests conclude. If the ledger has not arrived by the read-ahead cycle after next, this cannot make the September board—and will say so honestly.
Poland incentive economics
MN pays people to run nodes; the deck reports +20% Polish nodes on dynamic incentives—L1-C, with no baseline, cost, persistence or utilisation, and ~35% same-day node-registration churn in the 2024 corpus. No incentive table among the enumerated warehouse datasets. One Šaras question locates the data or drops the area.
Retention-stack interventions
No measured below-corridor defect stood alone until the retention-economics lane entered—so save-flow work folds into lane 02. The 2024 cancellation-button history argues repair framing, not friction.
What the data cannot rank
An evidence-first ranking is a streetlight: it can only rank what already has data, and MN's data only describes what already exists. This ring exists so the ladder cannot become a box.
Plan-migration offer monthly → annual
Why MN: tier appetite is proven at 2× scale (+73% ticket), and an annual plan has 1 renewal event where monthly has 12—migration structurally deletes involuntary-churn exposure while pulling cash forward. The failed-renewal moment is a natural offer point: "card failed—switch to annual instead."
Cheapest test: design rides the payments experiment. The rare move that is simultaneously generative and welded to the board's best-measured lane.
Known counter-evidence: none found for VPN plan migration; unexamined.
VPN ↔ proxy cross-sell
Why MN: GoProxies is in-house—two paying audiences, one company, zero cross-sell ever examined. Nobody else owns both lists, and proxy needs ~25× demand growth.
Cheapest test: one in-product or email offer cohort in each direction.
Known counter-evidence: Oct-2024: small self-service proxy purchases don't convert upward—a caution for proxy-side upsell, silent on VPN→proxy.
Node-runner community as launch audience
Why MN: ~33k crypto-native operators are MN's own distribution channel; no incumbent has one attached.
Cheapest test: folds into the crypto-wedge smoke test as its first outreach pool—community post and opt-in before any cold outreach.
Known counter-evidence: node-count basis conflicts; community activity level unknown.
Winback as an engineered offer
Why MN: Winback is already a warehouse revenue type—$12.6k in July. Reactivation exists; nobody has examined whether it is systematic or accidental. First-party lapsed-customer list, years deep.
Cheapest test: one warehouse query (organic or campaign-driven?), then one offer test.
Known counter-evidence: none; genuinely unexamined.
B2B / team VPN packaging
Why MN: selling the same network to companies as a team product—higher ARPU and stickier than consumer, on existing infrastructure.
Cheapest test: desk scan plus one landing test, market-side.
Known counter-evidence: crowded category (Tailscale and peers). Held.
External candidates
The September brief's bar: a nameable external candidate with first-hand signal—or an evidenced empty statement. First-hand demand signal is currently absent across the lane, and this page says so before it is asked.
Residential Vantage measurement from real home connections
Hypothesis: a consented subset of Mysterium nodes becomes a last-mile measurement and geo-compliance network—selling observations instead of anonymous egress. The lane inverts MN's structural fragility: operator identity becomes an asset.
MN's network is thousands of volunteer computers in real homes. Today they relay traffic. This candidate would sell something different: observations. From a real home connection you can see what a datacenter cannot—whether a streaming app actually loads in Warsaw, how fast a bank's site feels to a normal household, whether a government block is really in effect. Companies already pay for such measurements; RIPE Atlas, Catchpoint and ThousandEyes sell versions of it. Example buyer: a streaming service paying to know "does our app work right now on real home connections in Poland, as residents actually experience it?" The two open questions, in test order: does MN's supply really cover what the pitch claims—and would any buyer pick MN over the incumbents.
Synthetic monitoring from datacenters structurally cannot see what a residential vantage sees. RIPE Atlas, Catchpoint, ThousandEyes and Kentik prove the category pays—and that it is already competitive.
32,570 across 182 countries vs 31,547 across 135 vs the deck's 33,000—with 60,092 reported in 2022 and ~35% same-day registration churn. "Node" is not yet a defined unit. Supply measurement comes before any buyer conversation.
A node-registry coverage cut (via Šaras) is cheaper than any demand test and can kill the candidate alone. Only if supply holds: two credible buyer conversations before proposing anything wider.
Load-bearing claims, graded5 claims · coverage is the D
- L0-B
The category exists and pays: real comparables sell residential-vantage measurement; datacenter probes structurally cannot replicate it.
- L0-B
The lane inverts MN's structural fragility—measurement, verification and compliance make operator identity an asset; the raid-risk profile disappears.
- L0-D
MN's usable supply supports the claim—node counts conflict; "node" undefined; ~35% same-day registration churn.
- Absent
Any first-hand buyer signal.
- L1-C
Supply reliability is first-order: persistence before buyers.
Supply measurement contradicting the coverage claim kills this candidate regardless of demand. Kill conditions carried verbatim: no two credible design partners naming a costly unsolved problem; no stable consented nodes by country/ASN; or required integrity demanding a new network rather than a thin layer.
Expand incumbents and limits
Crypto-Native Access Wedge internet access AI agents can pay for in crypto
The one slice the July screen didn't kill: protocol-level, no-KYC, crypto-paid egress for crypto-native and agent-infra builders who don't want a vendor relationship. Second by evidence, first by test order—because the catalyst has a date.
AI agents—software that browses and fetches data on its own—increasingly need internet access their code can buy without a human: no sales call, no contract, no identity check. Established providers won't sell it that way. MN's network already takes crypto and doesn't need to know who you are—which for this buyer suddenly reads as a feature, not a bug. Example buyer: a small team whose research agents fetch public web pages from many countries, paying per gigabyte from a crypto wallet. The test is cheap and dated: a landing page plus a direct ask to ~20 named teams building such agents—before Cloudflare's Sept-15 bot-rule change forces everyone to confront the question.
Incumbents structurally won't go permissionless; Grass is the only comparable. The generic agent-access market is a knife-fight the July screen already killed—this wedge deliberately excludes it.
Cloudflare bot-policy defaults land then—which raises the information value of testing now and decays it after. Deferral is equivalent to dropping.
Landing page and opt-in plus outreach to ~20 named crypto-agent teams—starting inside MN's own node-runner community (G3). Market-side, fully inside Kairos's settled self-run authority, with a pre-registered response floor.
Real conversions above the pre-registered floor put this above Vantage. A ~zero response drops it to the rejection log with evidence—an equally useful result.
Provenance / proof-of-origin selling verifiable proof of where traffic really came from
In plain words: certifying that a connection or measurement genuinely originated from a real household in a stated place—proof a buyer could audit. Same risk-inversion cluster as Vantage (L0-B structurally) but a less-formed buyer set and no catalyst date. It rides Vantage's discovery conversations as a secondary probe—and promotes only if buyers keep reaching for exactly that proof.
Grant-funded censorship resistance foundation money for keeping the open internet reachable
Mission-aligned, near-zero revenue in the possibility map (L0-B). No named program with an inside-horizon deadline exists anywhere in evidence. One bounded search pass (≤2h) for a program with a ≤6-month award; otherwise it takes an honest line in the rejection log—which strengthens the portfolio.
Rejected and held
A rejection log is evidence that selection happened. This one inherits the July screening kills verbatim, with reasons—because a candidate that re-enters through the side door wastes a month.
Generic agent-access outbound
Selling internet access to AI-agent builders in general: vendor-dense and freshly VC-funded (Browserbase, Anchor, Firecrawl), and the big proxy incumbents already ship ready-made agent products. The wedge above deliberately excludes this market.
Head-on B2B proxy
Against Bright Data and Oxylabs—Oxylabs alone runs 397 people, in the same city.
Token-first revival
Rebuilding the business around the MYST crypto token. Base rates say no; every precedent that pulled it off needed a bigger trough and a war chest.
"Ethical supply" as legal moat
Bright Data's federal court wins removed the moat.
Consumer dVPN growth race
Doubling down on growing the consumer VPN against free and giant incumbents. No MN-specific right to win emerged from the July screen.
FWA / consented-mobile supply
Growing the network's supply side through mobile and fixed-wireless connections. Screened out in the July right-to-win pass: a supply thesis without a matched buyer.
Provenance as September lead
Folded into Vantage's probes; promotes only on buyer pull.
Org-wide intelligence layer
A means, not a September opportunity. Material pursuit remains gated separately.
Retention stack as standalone
Folded into the #2 retention-economics lane; repair framing, not friction.
Measured evidence at working tier: warehouse-reproduced July figures with logged, hashed queries. Semantics validation (L4) is still open everywhere—no internal candidate is past its proceed bar yet.
Screening and discovery depth only. First-hand demand signal is absent across the lane, and the thin-result posture is pre-declared under the September brief's own empty-result clause.
Context fact: GoProxies is MN's own in-house brand—MN captures 100% of proxy revenue, and per the infrastructure assessment capacity is not the constraint; demand is.
The blindspot map
What Kairos has not touched, in the order it should be touched, and why. Criteria per row: revenue proximity × data accessibility × time-to-signal—judgment visible, no fake composite score.
Non-Stripe payment funnels
apple, google, coingate and paypal carry ~62% of July gross with zero failure or recovery analysis. The proven Stripe method extends directly—and public store data (billing errors run 15–32% of store cancellations) says the involuntary class plausibly exists there too, at a bigger base.
Proxy / SuperProxy line
Second business line, the deck's own #1 bet, zero warehouse presence (verified)—and the gap that parks the Paid-Test candidate. Rider: a near-zero-cost trust-surface sprint—GoProxies' own ToS names no legal entity, a confirmed diligence gap that is MN's own to fix.
Marketing economics
Spend, CAC, ROAS, channel and geo contribution. The datasets exist in-warehouse, never opened—and for 82% of revenue MN cannot currently say which marketing channel brought the customer. Deck claims stay unverified and the quality-customer question is undecidable without it.
Pricing / packaging elasticity
Per-tier, per-geo response—the climb path for the #2 lane, with the queries already specified and MN's own adaptive-pricing intent as the live attachment point.
Finance perimeter
Burn, runway, headcount, entity map—the denominator of every materiality judgment on this board. Two self-serve paths: the all-hands deck corpus sweep, and public registry filings—MN Intelligence UAB, 2025 revenue €1,132,969, net loss €268,369, 13 employees (one entity of several; BlockDev AG Zug separate). Transaction fees are already fillable in-warehouse (July ≈ $17.2k).
Metric lineage & owner semantics
What each measured field actually means to the human who owns it—the L4 gate for every area above. Until it clears, every "proceed" on this board stays conditional.
Support economics
What customers contact support about, what each contact costs—and what share of conversations are about billing, which cross-checks the payments lane. The Intercom datasets sit in-warehouse and MN just automated tagging: a cheap voice-of-customer layer, unopened.
Fraud / abuse
July's failed first attempts are already shown not to be card-testing (1.27 attempts per customer)—which partially clears the payment-failure denominator. Chargebacks remain unquantified.
Node / incentive economics
Poland cost, persistence, utilisation, payout flows. The node-count conflict is now three-way (32,570/182 countries vs 31,547/135 vs the deck's 33,000)—this row gates both the Poland reserve and the Vantage supply claim.
Partnerships / affiliates / resellers
No MN data of any kind in Kairos evidence—existence unknown, and that is the finding. One question sizes whether the channel exists at all.
Token / MYST exposure
Named a major struggle in the deck. Real risk, weak Kairos leverage—watch, don't work.
The offer/packaging space itself meta
No divergence pass had ever been run on MN's existing base—every prior candidate was a diagnosis, not an offer. The generative ring above is the first pass, and the pass repeats each release.
What this ranking rests on
Warehouse measurement at working tier, company reports, public primary sources, explicit inference—and named unknowns.
July figures, paid-test share, orchestration state and candidate context—company-reported tier.
Current constraints, corrected claims, hypothesis board and authority gates.
The measured claims: reproduced denominators, logged SQL, hashed results, known grain. The working tier every L2 label on this page points to.
Global probe network, customised measurements and current probe scale.
Current commercial agent inventory and last-mile positioning.
Endpoint agents and measurements from user environments.
Global synthetic agents and private deployments.
Same board. Structured.
A compact reading layer for collaborator agents; no hidden evidence and no added authority. The full structured payload travels in this page's embedded machine brief.
- Verdict
- Payment Recovery leads the inner lane on measured evidence (L2-A core) with its flip-down condition published. Retention economics enters at #2. Paid-Test parks with a ≈21 Aug drop-by. No candidate is yet a proven opportunity.
- Inner ring
- 01 Payment Recovery (measured validation lead) · 02 Retention economics, pricing × churn (measured entry) · 03 Paid-Test Conversion (parked, MN-side ledger) · 04 Poland incentives (reserve, drop-lean).
- Generative ring
- G1 plan-migration · G2 VPN↔proxy cross-sell · G3 node-community launch audience · G4 winback engineering · G5 B2B packaging (held). All L0 by definition; ranked on asset-fit, never dressed as validated.
- Outer ring
- 01 Residential Vantage (discovery; supply falsifier first) · 02 crypto-native access wedge (smoke test before Sept 15) · 03 provenance (hold, folded) · 04 grant-CR (one bounded pass).
- Method
- Thresholds before data; L0–L4 evidence ladder with A–D grades per claim; proceed needs ≥L2 numbers plus L4 semantics; flip conditions published; blind re-derivation adjudicated before release.
- Blindspots
- Twelve prioritised untouched areas, led by non-Stripe payment funnels (~62% of July gross) and the proxy line (zero warehouse presence). The denominator of "strongest opportunity" is itself partially unmeasured—which is why rows 1–2 outrank polish on any current lead.
- Authority
- No material pursuit, build, outreach programme, transfer or spend is authorized by this page. Product-touching generative tests are joint decisions with an MN owner; market-side tests run in Kairos authority.