first-attempt failure across 2,979 July Stripe renewal invoices (50.72% ex-Radar). Denominator reproduced twice; SQL and result hashed. The attempt-weighted 83.36% is retry inflation—it retires the ~75% family, it does not describe invoices.
Evidence-first ranking · all context through 27 August
Ranked by evidence.
No torpedo yet.
No formal rank swap. Retention gains the strongest new signal, Crypto-native becomes the most vulnerable hold, and two challengers enter the pressure map without being smuggled into the top five.
A torpedo, in this fleet's vocabulary: a decisive, launch-ready revenue strike—every gate cleared, ready to fire. Nothing on this board has earned the name yet. The title says so on purpose.
Evidence is not upside
Five ranked candidates, placed by documentary signal and potential asymmetry. Marker state shows how each one knows what it claims to know. Position never indicates launch readiness.
How to read it: further right = stronger real-world evidence; higher = bigger possible prize. Top-right—strong evidence and big upside—is where decisions get made; nothing has reached it yet. Corner labels name each region's failure or proof mode: "story risk" is a big prize on thin evidence, "operational proof" is solid evidence on a modest prize.
Troops before ghosts
The method is deliberately boring: thresholds before data, grades per claim, and a published condition under which each ranking flips. This is the condensed version a non-analyst can hold.
Model reasoning, public sources, analogies. Not zero, never sufficient alone.
Decks and dashboards—what MN says about itself. Unaudited.
Reproduced in the warehouse at known grain; queries logged and hashed.
Matches an external ground truth: processor export, finance statement, bank.
The human who owns the system confirms the semantics mean what we think.
"Troops" are L2–L4. "Ghosts" are L0–L1 standing alone. Within a level, an A–D grade scores quality—assigned per load-bearing claim, never averaged per candidate, because averaging is how fake confidence gets manufactured.
Every claim, placed
How to read it: the board at the top places five candidates. This places every claim those candidates stand on—one dot per claim, drawn straight from the graded lists further down this page. Same grammar as the map: further right = evidence from further inside the real world; higher = better established inside that level. Top-right is decision-grade.
What it shows: the two right-hand columns are empty. No claim on this board has been reconciled against an external ground truth, and none has been confirmed by the person who owns the system—which is the whole argument of the title. The board lives in one column.
Why two axes and not one: quality without level is a well-argued guess; level without quality is sloppy measurement. A grade never promotes a claim across the ghost line—an L0-A is still a ghost, and the most dangerous kind, because it argues well. Read vertically and a candidate is a cloud, not a point: the same lane holds measured cores and open gates at once. That is why grades are assigned per claim and never averaged into one.
Before touching an area: "we proceed if [measurable condition]; drop if [condition]; park only on a named external blocker." Written before the evidence is read, logged if rewritten.
A detail earns investigation only if some plausible value of it can flip the proceed/drop verdict. Everything else gets one line in the log.
Proceeding requires measured numbers (≥L2) plus owner-confirmed semantics (L4). A drop can happen at any tier the moment a kill condition is met—cheap kills are wins.
Every ranking on this page states the evidence that would change it. A board that can't say what would move it isn't a ranking; it's a mood.
Leaks and levers in the measured business
Candidates derived from MN's own operating data. This is where the troops are—and where the honest ceilings get stated next to every rate.
Payment Recovery rescuing failed subscription payments
Half of July's Stripe renewal invoices failed on first attempt. The failure is measured, persistent and concentrated—and now measured as overwhelmingly involuntary—about 97% of the unpaid face is cards that failed, not customers who left. What remains unmeasured is how much of it a better retry can win, because today's retries already try about six times and win 17%.
Subscriptions renew by charging the customer's card automatically. In July, half of those charges failed on the first try. Some failures are customers who chose to leave—nothing to rescue there. Many are cards that just didn't work that day: no balance, expired, a prepaid card that ran dry. Recovery means winning back that second group—for example, a card that declines for insufficient funds on the 1st usually has balance again mid-month, so a retry timed to payday keeps the customer without them lifting a finger. That question is now answered: matched against MN's own churn dates, only about 3% of the unpaid July renewals belong to customers who had already cancelled; the rest are cards that failed. The new fact is that those cards are already being retried about six times each and only 17% come back—so the lever is smarter retries (which decline class, what timing, which route), not more of them. Confirming what MN's decline codes and dunning rules actually mean, with the person who owns them, is this lane's next step.
July's still-unpaid renewal invoices, Stripe-only, after voluntary correction: $19,150 face, of which $540 (2.8%) belongs to customers who had already cancelled and $644 (3.4%) is unresolved same-day. This bounds the problem, not the prize—it is what today's dunning already failed to win. Stripe is only 38% of July gross ($87.9k of $230.3k); the other gateways were blindspot row 1, killed 16 Aug—the stores bill and retry out of sight, PayPal and Coingate have no charge table—so this ceiling does not rise from the warehouse.
canonical recurring failure, H2-2025 into 2026; mature recovery runs 15.0–19.5% on settled cohorts. insufficient_funds is the largest addressable pool; prepaid and debit cards carry most first failures.
Load-bearing claims, graded12 claims · grades L2-A to absent
- L2-A
July 2026: 2,979 Stripe renewal invoices, 1,528 first-attempt failures = 51.29% (50.72% ex-Radar). Denominator independently reproduced twice; SQL + result hashed.
- L2-B
Persistent, not a spike: canonical recurring failure 38.5–43.8% (H2-2025) → 46–56.7% (2026). Single pipeline, method visible.
- L2-B
Mature recovery is weak: 15.0–19.5% for Jan–Jun 2026 cohorts by cutoff.
- L2-A
July still-unpaid renewal face value $19,187—one amount per invoice, derived twice independently.
- L0-B
External reference: Stripe's published subscription first-attempt failure baseline ≈9%; MN runs more than 5× that. Older publication, broad mix.
- L2-A
The gate, measured: of July's 1,251 first-failed-never-recovered renewal invoices ($19,150.50), 38 ($540, 2.8%) show churn dated before the attempt—voluntary; 897 ($13.9k) churn on average 3.6 days after it, 276 ($4.1k) have no churn row. About 97% involuntary. Stop rules cleared (unresolved same-day 3.4% vs 15% ceiling; unlinked 0.08% vs 10% floor). Cohort reproduces the 08-11 count to 0.1%; SQL and result hashed. Invisible-invoice caveat still applies.
- L2-B
Retry saturation: July's 1,556 first-failed renewal invoices absorbed about 9,200 charge attempts (≈6 each) and 269 (17.3%) recovered; 341 were never retried. Invoice grain from the charges table, reproducing the 08-12 rates. "Retry more" is not the lever.
- L2-B
Fees do not kill it: Stripe 4–5% of gross, Adyen ≈3.7%, Google 15%, Apple ≈24% (recorded only from Dec 2025), PayPal 6–7%, Coingate 1%; blended 11.6% in Q1-2026. Fee table frozen 2026-04-28, so nothing after April. A recovered Stripe renewal nets ≈95%.
- L2-B
Failure concentration: insufficient_funds is the largest addressable pool (23.6% recovery); prepaid 31.3% and debit 48.9% of first failures.
- L2-B
Payments Orchestration shows no detectable first-attempt improvement yet (52.35% pre vs 53.18% post, right-censored). Descriptive split, non-causal.
- L2-A
Stripe is $87.9k of $230.3k July gross (38%)—apple, google, coingate and paypal carry the rest, unexamined.
- L4 · absent
Decline-code semantics, dunning rules and orchestration scope—owner answers outstanding, including whether previously_declined_do_not_retry is intentional.
If the failed pool turns out to be dominated by customers who meant to cancel, plus charges that never resolve either way—pushing conservative rescuable value below ~$2k/mo—payments drops off the lead. That is the number that would change this page. Tested 16 Aug 2026: voluntary $540 plus unresolved $644 of $19,150 face—not triggered.
Retention Economics pricing, churn and verified reliability
Revenue doubled in 24 months on price, not volume—and first-renewal retention on recent monthly cohorts now sits materially below the external corridor. Delight adds one concrete product-intervention hypothesis: detect failure, contain unsafe fallback, recover, and verify the outcome. The lane strengthens; causation remains open.
MN doubled revenue by charging more, not by winning more customers. The open question is what that did to loyalty: of the people who start a monthly plan now, only about one in three pays a second month—against an industry norm above one in two, and below MN's own 2024 customers. Two suspects, deliberately kept apart: the higher prices, or a shift in who's buying (more customers from countries and app stores where everyone quits sooner). One warehouse query can tell the suspects apart—and the answer changes the move. If price did it, the finding is "stop raising." If the customer mix did it, the price rises were free money and the leak is elsewhere.
Average ticket $10.52 → $18.19 across the tier repack; purchase count nearly flat. The doubling was a pricing event—which proves the lever can move revenue at 2× scale.
on recent monthly cohorts, against a 53–61% external median (RevenueCat, 115k apps) and down ~7 points from 2024 cohorts across the repricing window. No loyalty plateau: long-tenure survivors still decay ~8%/mo.
Price is one hypothesis. Geo/channel mix shift is the named rival: survivors skew web-card tier-1/2 ≈2.5× Google-Play tier-3. Claiming either now would outrun the evidence.
Load-bearing claims, graded8 claims · level measured, causes open
- L2-B
Revenue doubled in 24 months price-led: new-purchase count +19%, average ticket +73% ($10.52 → $18.19); the tier repack did it. Survives the duplication correction.
- L2-B
First renewal on recent monthly cohorts ≈32% vs 38–40% for 2024 cohorts—a ~7pt deterioration across the repricing window; cross-validated in two independent tables.
- L2-B
2026 new-purchase volume drifts down since January (7,160 → 6,346).
- L2-B
Churn by country tier is measured on a month-start cohort: tier 3 turns over ≈1.5× tier 1 every month Feb–Jul 2026 (July gross 38% vs 25%; net of 30-day recoveries 28% vs 19%). List price is uniform across tiers on Stripe, Coingate, PayPal and Apple, so the tier gap is not price elasticity; tier-3 cancellers name product failure more and price less on every platform (survey sample). Row W6 carries it.
- L0-C
The cause of the deterioration. Price (elasticity) is untested hypothesis H1; seasonality, marketing and store-mix shift have equal standing—survivor skew makes mix shift a serious rival.
- L1-C
MN itself intends adaptive-pricing tests "hopefully end of August" (all-hands; ownership risk flagged)—a live attachment point for pre-registered measurement.
- L2-B
Support prevalence at working tier: 889 of 9,060 unique Intercom conversations in the latest 90-day window matched the locked human-tag connection-failure taxonomy—9.81% of all conversations and 21.67% of tagged conversations.
- L2-B
The crude error-exposed/churn association was 8.52×; controlling for observed user days reduced it to 2.00×, and also controlling for recorded event-volume opportunity reduced it to 1.18×. Recorded errors may precede cancellation, but these fields do not establish causal retained value.
Per-tier, per-geo cohorts showing the deterioration is a mix-shift artifact re-park the pricing half. And if elasticity shows the 2026 volume drift is price-caused, the upside flips sign—the finding becomes "stop raising prices," still decision-grade.
GoProxies Conversion System from account and checkout to recurring contract
The paid-test thesis survives as a parked hypothesis, but its published evidence gate is overdue. Kairos can inspect acquisition, account activation, plan selection, checkout progression, product use and support demand through the warehouse. It still cannot connect July's paid tests to revenue, margin, buyer, technical success or recurring outcome; the direct GoProxies source connection also remains blocked.
The old page said the proxy line had zero warehouse presence. That was too broad. The completed audit found roughly 11.4k accounts, about 2.15k enabled and unblocked, and 7,936 with no plan. The 2026 web funnel is also visible: 468,056 sessions → 13,696 pricing views → 9,483 plan-checkout events → 3,652 product-checkout events → 1,826 payment events → 277 thank-you events. Support adds about 3,964 contacts and 1,307 conversations. These are diagnostic surfaces, not revenue economics. The paid-test cohort still needs MN-side amounts, labels and outcomes.
July proxy result in paid tests (78.1%), new MRR $2,544—deck figures, unreconciled. Paid intent, not recurring revenue.
Accounts, plans, products, web funnel and support are queryable. Revenue amounts and a paid-test cohort label are not. Kairos can diagnose where users stop; it cannot yet value the stop.
Oct-2024 added €2.2k MRR against a 15/17/21 OKR, upsell headroom was called exhausted, deal sizes fell. The burden of proof rises; the story must answer its own history.
Load-bearing claims, graded4 claims · why this parks
- L1-B
July: $11,628 vs $8.5k target; 78.1% is paid tests ($9,084); new MRR $2,544. One deck, no reconciliation.
- L2-A
The warehouse coverage boundary is measured: GoProxies account, plan, product, funnel and support surfaces exist; revenue amounts and a paid-test cohort label do not.
- L1-C
Adverse history: Oct-2024 proxy push added €2.2k MRR vs a 15/17/21 OKR, with upsell headroom called exhausted and deal sizes falling.
- Absent
Prior-cohort test→MRR conversion rate—nowhere in Kairos evidence.
One clean cohort ledger showing strong test→MRR conversion at stable deal size promotes this sharply. Funnel friction alone does not.
If the cohort ledger does not arrive, the paid-test thesis drops. The broader GoProxies conversion work remains diagnostic until prices, margins and owner semantics exist.
Poland incentive economics
MN pays people to run nodes; the deck reports +20% Polish nodes on dynamic incentives—L1-C, with no baseline, cost, persistence or utilisation, and ~35% same-day node-registration churn in the 2024 corpus. No incentive table among the enumerated warehouse datasets. One Šaras question locates the data or drops the area.
Retention-stack interventions
No measured below-corridor defect stood alone until the retention-economics lane entered—so save-flow work folds into lane 02. The 2024 cancellation-button history argues repair framing, not friction.
What the data cannot rank
An evidence-first ranking is a streetlight: it can only rank what already has data, and MN's data only describes what already exists. This ring exists so the ladder cannot become a box.
Plan-migration offer monthly → annual
Why MN: tier appetite is proven at 2× scale (+73% ticket), and an annual plan has 1 renewal event where monthly has 12—migration structurally deletes involuntary-churn exposure while pulling cash forward. The failed-renewal moment is a natural offer point: "card failed—switch to annual instead."
Cheapest test: design rides the payments experiment. The rare move that is simultaneously generative and welded to the board's best-measured lane.
Known counter-evidence: none found for VPN plan migration; unexamined.
VPN ↔ proxy cross-sell
Why MN: GoProxies is in-house—two paying audiences, one company, zero cross-sell ever examined. Nobody else owns both lists, and proxy needs ~25× demand growth.
Cheapest test: one in-product or email offer cohort in each direction.
Known counter-evidence: Oct-2024: small self-service proxy purchases don't convert upward—a caution for proxy-side upsell, silent on VPN→proxy.
Node-runner community as launch audience
Why MN: ~33k crypto-native operators are MN's own distribution channel; no incumbent has one attached.
Cheapest test: folds into the crypto-wedge smoke test as its first outreach pool—community post and opt-in before any cold outreach.
Known counter-evidence: node-count basis conflicts; community activity level unknown.
Winback as an engineered offer
Why MN: Winback is already a warehouse revenue type—$12.6k in July. Reactivation exists; nobody has examined whether it is systematic or accidental. First-party lapsed-customer list, years deep.
Cheapest test: one warehouse query (organic or campaign-driven?), then one offer test.
Known counter-evidence: none; genuinely unexamined.
B2B / team VPN packaging
Why MN: selling the same network to companies as a team product—higher ARPU and stickier than consumer, on existing infrastructure.
Cheapest test: desk scan plus one landing test, market-side.
Known counter-evidence: crowded category (Tailscale and peers). Held.
Kairos opportunities—not MN candidates
Scope line: these emerged from the autonomous-agent relay portfolio, Standard of Performance work and the Key Maker intake. They do not enter the MN top five, do not inherit another candidate's evidence, and do not authorize product build, outreach, transfer or spend.
Cross-boundary opportunity and exception room
What is new: the relay turns conflicting evidence, permissions, owners and deadlines into one decision surface with receipts. In the current portfolio it ranks alongside payment exceptions as the strongest internal Kairos application.
Cheapest proof: run it on one real exception-heavy workstream and score decisions closed, contradictions surfaced and time-to-resolution.
Boundary: 17/20 is a comparative strategy score, not measured economics. The current relay runtime is not production-load ready.
Standard-of-Performance ratchet
What is new: every completed investigation can improve the next one—questions, evidence gates, owner semantics, rejection logic and release receipts compound instead of disappearing in chat.
Cheapest proof: compare repeated work before and after the ratchet on coverage, correction rate and decision latency.
Boundary: this is an internal delivery system until a buyer, price and external operating contract exist.
Managed relay applications
Where it may travel: billing-exception rooms, cyber-incident coordination, healthcare revenue-cycle exceptions, and M&A or joint-venture work where evidence and authority cross organisations.
Cheapest proof: one buyer-specific exception map before any product claim.
Boundary: these belong to a separate Kairos opportunity slate. None is launch-ready; none belongs on MN's board without a direct Mysterium fit.
Key Maker governed access without human credential toil
Two propositions, kept separate: inside MN, Key Maker could reduce access-cycle time, status confusion, human touches and unsafe custody while unlocking work across the ranked opportunities. Outside MN, the same operating system may become a reusable offer.
Evidence now: first-party MN problem signal; adjacent category existence L0-A; adjacent commercial activity L0-B. Capture timing, touches, retries, false-green states and useful work unlocked as a side effect of ordinary onboarding. The external path separately needs buyer, budget, price and delivery-economics evidence.
Boundary: not rank #6. Key Maker-specific demand, buying form, price and repeatability remain L0-C or unmeasured. Evidence-only, its adjacent-category and commercial signal is stronger than #5; a normalized portfolio pass still decides whether that becomes a rank move. See the direct #5 comparison ↓ · Open Key Maker →
The first named challenger to #5
A contender is a candidate that could displace a ranked opportunity under the same evidence protocol. It is not rank #6, a launch approval, or a promise that the swap will happen.
The access problem is happening inside MN now. Key Maker could reduce elapsed onboarding time, human touches, retries, false‑green status and unsafe secret handling while making the rest of this board easier to test.
Its 889 matched conversations strengthen Retention Economics. It becomes an independent contender only if evidence shows a separate economic lane, rather than one intervention inside retention.
No Key Maker‑specific buyer, buying form, budget, price, repeatability or delivery‑economics result exists yet. Its direct demand remains L0‑C, just like #5.
| Decision dimension | Key Maker · contender | #05 · Crypto‑native Access Wedge |
|---|---|---|
| Problem proximity | Stronger. First‑party MN operating friction is present now. | Hypothesis tied to a dated external catalyst; no buyer problem signal yet. |
| Category / commercial signal | Stronger. Category existence L0‑A; adjacent commercial activity L0‑B. | Category/catalyst L0‑B; direct demand L0‑C. |
| Direct demand | Absent for the specific offer. Buyer, budget and buying form unresolved. | Absent. No conversion or buyer signal; smoke test unrun. |
| Cheapest live evidence | Passive telemetry from ordinary MN onboarding: time, touches, retries, false‑green states and useful work unlocked. | A pre‑registered landing and outreach smoke test before the 15 September catalyst decays. |
| Current decision | Named contender. Compare after passive baseline and delivery‑economics work. | Holds #5. Its bounded, dated market test is more decision‑ready today. |
Promote only if a normalized comparison shows a better prize, value capture, controllability, time‑to‑evidence and delivery‑economics profile than #5. Direct buyer/problem/budget evidence would be the strongest additional signal, but is not an admission prerequisite.
Park the product thesis if ordinary onboarding shows no material time or access-quality gain, if the make/buy boundary is not differentiated, or if bespoke delivery and governance costs erase repeatable value.
External candidates
The September brief's bar: a nameable external candidate with first-hand signal—or an evidenced empty statement. First-hand demand signal is currently absent across the lane, and this page says so before it is asked.
Residential Vantage measurement from real home connections
Hypothesis: a consented subset of Mysterium nodes becomes a last-mile measurement and geo-compliance network—selling observations instead of anonymous egress. The lane inverts MN's structural fragility: operator identity becomes an asset.
MN's network is thousands of volunteer computers in real homes. Today they relay traffic. This candidate would sell something different: observations. From a real home connection you can see what a datacenter cannot—whether a streaming app actually loads in Warsaw, how fast a bank's site feels to a normal household, whether a government block is really in effect. Companies already pay for such measurements; RIPE Atlas, Catchpoint and ThousandEyes sell versions of it. Example buyer: a streaming service paying to know "does our app work right now on real home connections in Poland, as residents actually experience it?" The two open questions, in test order: does MN's supply really cover what the pitch claims—and would any buyer pick MN over the incumbents.
Synthetic monitoring from datacenters structurally cannot see what a residential vantage sees. RIPE Atlas, Catchpoint, ThousandEyes and Kentik prove the category pays—and that it is already competitive.
32,570 across 182 countries vs 31,547 across 135 vs the deck's 33,000—with 60,092 reported in 2022 and ~35% same-day registration churn. "Node" is not yet a defined unit. The new finding that residential carries roughly 78–79% of VPN traffic is a usage denominator for self-healing—not proof of stable, consented Vantage supply.
A node-registry coverage cut (via Šaras) is cheaper than any demand test and can kill the candidate alone. Only if supply holds: two credible buyer conversations before proposing anything wider.
Load-bearing claims, graded5 claims · coverage is the D
- L0-B
The category exists and pays: real comparables sell residential-vantage measurement; datacenter probes structurally cannot replicate it.
- L0-B
The lane inverts MN's structural fragility—measurement, verification and compliance make operator identity an asset; the raid-risk profile disappears.
- L0-D
MN's usable supply supports the claim—node counts conflict; "node" undefined; ~35% same-day registration churn.
- Absent
Any first-hand buyer signal.
- L1-C
Supply reliability is first-order: persistence before buyers.
Supply measurement contradicting the coverage claim kills this candidate regardless of demand. Kill conditions carried verbatim: no two credible design partners naming a costly unsolved problem; no stable consented nodes by country/ASN; or required integrity demanding a new network rather than a thin layer.
Expand incumbents and limits
Crypto-Native Access Wedge internet access AI agents can pay for in crypto
The one slice the July screen didn't kill: protocol-level, no-KYC, crypto-paid egress for crypto-native and agent-infra builders who don't want a vendor relationship. Second by evidence, first by test order—because the catalyst has a date.
AI agents—software that browses and fetches data on its own—increasingly need internet access their code can buy without a human: no sales call, no contract, no identity check. Established providers won't sell it that way. MN's network already takes crypto and doesn't need to know who you are—which for this buyer suddenly reads as a feature, not a bug. Example buyer: a small team whose research agents fetch public web pages from many countries, paying per gigabyte from a crypto wallet. The test is cheap and dated: a landing page plus a direct ask to ~20 named teams building such agents—before Cloudflare's Sept-15 bot-rule change forces everyone to confront the question.
Incumbents structurally won't go permissionless; Grass is the only comparable. The generic agent-access market is a knife-fight the July screen already killed—this wedge deliberately excludes it.
Cloudflare will block Agent and Training bots on ad-bearing pages by default for newly onboarded domains. That raises the information value of testing; it does not create universal demand for paid egress.
Landing page and opt-in plus outreach to ~20 named crypto-agent teams—starting inside MN's own node-runner community (G3). Market-side, fully inside Kairos's settled self-run authority, with a pre-registered response floor.
Real conversions above the pre-registered floor put this above Vantage. A ~zero response drops it to the rejection log with evidence—an equally useful result.
Provenance / proof-of-origin selling verifiable proof of where traffic really came from
Certifying that a connection or measurement genuinely originated from a real household in a stated place—proof a buyer could audit. Same risk-inversion cluster as Vantage (L0-B structurally) but a less-formed buyer set and no catalyst date. It rides Vantage's discovery conversations as a secondary probe—and promotes only if buyers keep reaching for exactly that proof.
Grant-funded censorship resistance foundation money for keeping the open internet reachable
Mission-aligned, near-zero revenue in the possibility map (L0-B). No named program with an inside-horizon deadline exists anywhere in evidence. One bounded search pass (≤2h) for a program with a ≤6-month award; otherwise it takes an honest line in the rejection log—which strengthens the portfolio.
Rejected and held
A rejection log is evidence that selection happened. This one inherits the July screening kills verbatim, with reasons—because a candidate that re-enters through the side door wastes a month.
Generic agent-access outbound
Selling internet access to AI-agent builders in general: vendor-dense and freshly VC-funded (Browserbase, Anchor, Firecrawl), and the big proxy incumbents already ship ready-made agent products. The wedge above deliberately excludes this market.
Head-on B2B proxy
Against Bright Data and Oxylabs—Oxylabs alone runs 397 people, in the same city.
Token-first revival
Rebuilding the business around the MYST crypto token. Base rates say no; every precedent that pulled it off needed a bigger trough and a war chest.
"Ethical supply" as legal moat
Bright Data's federal court wins removed the moat.
Consumer dVPN growth race
Doubling down on growing the consumer VPN against free and giant incumbents. No MN-specific right to win emerged from the July screen.
FWA / consented-mobile supply
Growing the network's supply side through mobile and fixed-wireless connections. Screened out in the July right-to-win pass: a supply thesis without a matched buyer.
Provenance as September lead
Folded into Vantage's probes; promotes only on buyer pull.
Org-wide intelligence layer
A means, not a September opportunity. Material pursuit remains gated separately.
Retention stack as standalone
Folded into the #2 retention-economics lane; repair framing, not friction.
Measured evidence at working tier: warehouse-reproduced July figures with logged, hashed queries. Semantics validation (L4) is still open everywhere—no internal candidate is past its proceed bar yet.
Screening and discovery depth only. First-hand demand signal is absent across the lane, and the thin-result posture is pre-declared under the September brief's own empty-result clause.
Context fact: GoProxies is MN's own in-house brand—MN captures 100% of proxy revenue, and per the infrastructure assessment capacity is not the constraint; demand is.
The blindspot map
What Kairos has not touched, in the order it should be touched, and why—now a working map, not a list: every row is a quest with a lane, a decision rule written before the data, an owner column, and a status that is derived from the map's own event record. Judgment stays visible; there is still no composite score.
How to read it: three working lanes, each spending a different resource, each in pull order — top row of a lane is the next quest in that lane. Chips: Prize how much money the territory touches · Prior our L0 judgment that a lead-class finding hides there · Data where the evidence lives · Signal predicted days from claim to first measured number, and the gate · Owner the person who holds this territory's meaning · Status where the quest is. A quest ends only as climbed (a candidate), killed (the drop rule fired), or parked (a named blocker with a revisit date). Every rule was written before the data and changes only in a release.
Warehouse lane Self-serve. Kairos can query these today; the only gate is BigQuery access. Pull in this order. Spends: Kairos hours.
Non-Stripe payment funnels the other four gateways, same failure question
apple, google, coingate and paypal carry ~62% of July gross with zero failure or recovery analysis. The proven Stripe method extends directly—and public store data (billing errors run 15–32% of store cancellations) says the involuntary class plausibly exists there too, at a bigger base.
Unlocks → Raises Payment Recovery's ceiling from Stripe-only (38% of July gross) to the whole base.
Decision rule — written before the data, changed only in a release
- Proceed if
- first-attempt failure on any non-Stripe gateway is measurable at charge grain and ≥ 20% of that gateway's renewal invoices.
- Drop if
- every gateway is < 10%, or the class is structurally invisible (store-billed, no retry visibility).
- Park
- only if the charge-grain tables carry no outcome field — a named data blocker, not a shrug.
Marketing economics what MN spends to win a customer, and through which door
Spend, CAC, ROAS, channel and geo contribution. The datasets exist in-warehouse, never opened—and for 82% of revenue MN cannot currently say which marketing channel brought the customer. Deck claims stay unverified and the quality-customer question is undecidable without it.
Unlocks → Decides the quality-customer question and the retention cause (price vs mix); gives every offer test its CAC denominator.
Decision rule — written before the data, changed only in a release
- Proceed if
- spend + attribution tables let us compute CAC for ≥ 50% of July revenue at channel grain.
- Drop if
- spend data is absent from all 24 datasets — then this becomes an MN-side ask and changes lane.
- Park
- on the ask, with the date it was made.
Pricing / packaging elasticity does the price move the churn — per tier, per country
Per-tier, per-geo response—the climb path for the #2 lane. What is now measured: the direct gateways charge one list price across tiers ($13.49 a month for the plus plan on Stripe, Coingate, PayPal and Apple, in every tier; Google Play tier 3 lands ≈7% lower), and tier-3 users churn ≈1.5× faster than tier 1 while naming price less when they cancel. Because the tiers do not differ in price, the tier churn gap is not elasticity evidence — the lever it points at is product (row W6). Elasticity itself remains untested.
Unlocks → The climb path for Retention economics (#2): turns L0-C on cause into a measured answer.
Decision rule — written before the data, changed only in a release
- Proceed if
- per-tier, per-geo cohorts show a renewal difference of ≥ 5 points between price tiers with ≥ 200 renewals per cell.
- Drop if
- cells are too thin to read (< 200 renewals) across the board — then elasticity is untestable at this scale and the row says so.
- Park
- never — the data is in-warehouse.
Support economics what customers write in about, and what each contact costs
What customers contact support about, what each contact costs—and what share of conversations are about billing, which cross-checks the payments lane. The Intercom datasets sit in-warehouse and MN just automated tagging: a cheap voice-of-customer layer, unopened.
Unlocks → Cross-checks Payment Recovery from the customer's side; a voice-of-customer layer for any offer test.
Decision rule — written before the data, changed only in a release
- Proceed if
- the billing-related share of conversations is classifiable and ≥ 15%.
- Drop if
- tags cannot separate billing from the rest — then the layer is unreadable and the row closes.
- Park
- on tagging coverage, if the automated tags start after the period we need.
Fraud / abuse is the failure denominator clean — chargebacks and card-testing
July's failed first attempts are already shown not to be card-testing (1.27 attempts per customer)—which partially clears the payment-failure denominator. Chargebacks remain unquantified.
Unlocks → Clears or dirties the payment-failure denominator that Payment Recovery stands on.
Decision rule — written before the data, changed only in a release
- Proceed if
- chargebacks are quantifiable and > 1% of gross.
- Drop if
- chargebacks < 0.5% of gross — the denominator is clean and the row closes as a win.
- Park
- if chargeback data is absent from the warehouse — then it is a processor-export ask.
Android product experience in the largest paying geography tier-3 users leave faster and, when asked, name product failure over price
Nigeria is the #1 country by 2026 new purchases (8,208, mostly Google Play at $12.90 a month). Users in tier-3 countries churn about 1.5× faster than tier 1 on a month-start cohort (July: 38% gross / 28% net of 30-day recoveries, against 25% / 19%). When they cancel in the app they name price less than tier-1 users on every platform (Android 23% vs 30%, iOS 19% vs 29%, Windows 16% vs 25%) and disconnects, blocked sites, missing features and error 7040 more. That is a survey-sample direction, not a churn cause: the sample is self-selected, app-only, ~7.5k submissions against ~44k churn rows.
Unlocks → Gives Retention Economics (#02) its tier cut and moves the lever from price to product; a survival curve by plan duration is the climb step.
Decision rule — written before the data, changed only in a release
- Proceed if
- the tier-3 cohort churn excess stays ≥ 5 points above tier 1 for three consecutive months AND a survival curve by plan duration keeps the gap after yearly plans are held out.
- Drop if
- the excess closes below 5 points, or disappears once plan duration is held constant — then it was plan mix, not the product.
- Park
- never — the data is in-warehouse.
Failed payments as a churn label — and the remainder billing never recovers how much churn carries a billing-retry label, and how much of it comes back
In 2026 about 48% of churned subscriptions carry a billing-retry label; the rest are voluntary, including explicit cancellation requests. One churn row is one subscription. Separately, about a quarter of churn rows in the status ledger reverse within 30 days. 93% of recurring-type reactivations arrive within 30 days of the churn row (10,328 of 11,064). That recurring-type reactivation equals billing recovery rather than a returning customer is a hypothesis — the reason join matched 10.1% and cannot carry it (ask 14). Name the query: reactivation rows in 2026 by ≤30 d × type, to give P(Recurring | ≤30 d) directly. What the warehouse cannot say is which labelled churns were involuntary in outcome, or how large the never-recovered remainder is: the key that pairs a churn with its billing attempts is MN's.
Unlocks → Sizes the un-recovered remainder that Payment Recovery (#01) can act on and Retention Economics (#02) must net out.
Decision rule — written before the data, changed only in a release
- Proceed if
- the pairing lands and never-recovered billing-labelled churn is ≥ 10% of monthly churned subscriptions.
- Drop if
- MN answers that no pairing key exists AND no proxy join reaches ≥ 90% match — then the remainder is an MN-side number, not a Kairos one, and the row says so.
- Park
- if the key is unanswered by the drop-by date — parked on the ask, revisited when it lands.
The Primer switch and the payment label it hides under a new web payment gateway that the revenue spine still labels Stripe
Primer replaced Stripe as the web gateway in the week of 22 July 2026. The web funnel shows it (Stripe transactions fall to near zero, Primer takes them); the revenue spine does not — it keeps every Primer payment under the stripe label. Week by week on identical New-type populations, web dollars ran at 101 · 102 · 101 · 100 · 100 · 110% of the spine's across the 22 July switch — flat through the cut-over, with the final week 10% over. Nothing visible is missing at weekly grain; row-level completeness is unprovable (the web table carries no transaction id, ask 16), and any Stripe-keyed analysis — Payment Recovery's failure rates included — silently absorbs Primer traffic.
Unlocks → Keeps Payment Recovery (#01) honest about its denominator; a lineage fix upstream is the cheapest win on the board.
Decision rule — written before the data, changed only in a release
- Proceed if
- Primer's first-attempt failure rate at charge grain differs from Stripe's by ≥ 5 points on ≥ 500 charges a week — then the recovery candidate needs a Primer arm.
- Drop if
- the rates match and the label is corrected upstream — then this row's only product was the lineage fix, and it closes.
- Park
- never — the data is in-warehouse.
Human lane These live in MN people's heads or MN-side records. Start now and run in parallel — never let this lane become the critical path. Spends: MN people's time.
Metric lineage & owner semantics who owns each number, and what it means to them
What each measured field actually means to the human who owns it—the L4 gate for every area above. Until it clears, every "proceed" on this board stays conditional.
Unlocks → Lifts the two measured candidates from L2 to L4 — the only move on this board that can. Fills the owner column of every other row.
Decision rule — written before the data, changed only in a release
- Proceed if
- the owner of each load-bearing field on the two measured candidates confirms its semantics in a sit-down — recorded, dated.
- Drop if
- not applicable — a gate does not drop.
- Park
- on owner availability, with the date asked.
GoProxies economics and owner semantics the funnel is visible; the money and paid-test labels are not
The warehouse now exposes GoProxies accounts, plans, products, checkout stages and support. It still lacks revenue amounts, paid-test cohort labels, prices, margins and recurring outcomes. That corrected boundary broadens candidate 03 without promoting it. Rider: GoProxies' own ToS names no legal entity, a confirmed diligence gap that is MN's own to fix.
Unlocks → Grades the GoProxies conversion system; un-parks its paid-test core; opens the VPN↔proxy cross-sell candidate.
Decision rule — written before the data, changed only in a release
- Proceed if
- MN supplies a paid-test cohort ledger with amount, end date and recurring outcome at account grain.
- Drop if
- the ledger does not exist — then the paid-test thesis drops, even though broader funnel diagnostics remain.
- Park
- the economic claim on the ask; continue only bounded warehouse diagnostics that can change a conversion decision.
Node / incentive economics what the node network costs, and how much of it is real
Poland cost, persistence, utilisation, payout flows. The node-count conflict is now three-way (32,570/182 countries vs 31,547/135 vs the deck's 33,000)—this row gates both the Poland reserve and the Vantage supply claim.
Unlocks → Gates the Poland incentive reserve and the Residential Vantage supply claim.
Decision rule — written before the data, changed only in a release
- Proceed if
- MN supplies incentive outlay and node persistence at node grain.
- Drop if
- measured outlay < $5k/mo with no retention effect — the Poland flip condition.
- Park
- on the ask.
Partnerships / affiliates / resellers does a partner channel exist at all
No MN data of any kind in Kairos evidence—existence unknown, and that is the finding. One question sizes whether the channel exists at all.
Unlocks → Sizes a channel or closes it; either is progress.
Decision rule — written before the data, changed only in a release
- Proceed if
- the channel exists and carries > 5% of revenue.
- Drop if
- it does not exist, or carries < 1% — closed as a finding.
- Park
- on the ask.
Corpus lane Self-serve but slow: the all-hands deck corpus and public filings. Runs in the background. Spends: Kairos hours, unattended.
Finance perimeter burn, runway, headcount — the denominator of everything
Burn, runway, headcount, entity map—the denominator of every materiality judgment on this board. Two self-serve paths: the all-hands deck corpus sweep, and public registry filings—MN Intelligence UAB, 2025 revenue €1,132,969, net loss €268,369, 13 employees (one entity of several; BlockDev AG Zug separate). Transaction fees are already fillable in-warehouse (July ≈ $17.2k).
Unlocks → Sets the materiality of every candidate and every row above.
Decision rule — written before the data, changed only in a release
- Proceed if
- burn and runway established from corpus + registry within ±20%.
- Drop if
- not applicable — a frame does not drop.
- Park
- if neither the deck corpus nor the registry yields it — then it is an MN finance ask.
Watched, not worked Real for MN, outside Kairos's leverage. Named so it is not forgotten; not a quest. Spends: nothing.
Token / MYST exposure the token risk MN carries, outside Kairos's reach
Named a major struggle in the deck. Real risk, weak Kairos leverage—watch, don't work.
Note not a quest — promoted to a row only if MYST exposure shows up material inside the finance perimeter.
Standing pass Repeats every release rather than ending. Reports its yield or its emptiness. Spends: one pass per release.
The offer/packaging space itself meta the search for offers that don't exist yet
No divergence pass had ever been run on MN's existing base—every prior candidate was a diagnosis, not an offer. The generative ring above is the first pass, and the pass repeats each release.
Note not a quest — the pass repeats each release and reports its yield or its emptiness.
What this ranking rests on
Warehouse measurement at working tier, company reports, public primary sources, explicit inference—and named unknowns.
July figures, paid-test share, orchestration state and candidate context—company-reported tier.
Current constraints, corrected claims, hypothesis board and authority gates.
The measured claims: reproduced denominators, logged SQL, hashed results, known grain. The 20 Aug audit also fixes the GoProxies coverage boundary: operational surfaces present, revenue amounts and paid-test labels absent.
Global probe network, customised measurements and current probe scale.
Current commercial agent inventory and last-mile positioning.
Endpoint agents and measurements from user environments.
Global synthetic agents and private deployments.
The internal evidence ratchet behind K2. Capability claim only; not an MN revenue opportunity.
The canonical rank judgment, Delight placement, Key Maker claim grades and explicit no-torpedo boundary.
Eleven source connections: 2 ready for a bounded question, 3 partially mapped, 6 blocked. Access changes time-to-evidence; it does not change a candidate's economics by itself.
The bounded detect → contain → recover → verify loop, inside #2 Retention Economics and not independently promoted.
The future-state operating concept. Its proposal surfaces do not assert current MN access truth; the opportunity grade on this page remains separate.
Same board. Structured.
A compact reading layer for collaborator agents; no hidden evidence and no added authority. The full structured payload travels in this page's embedded machine brief.
- Verdict
- No formal rank swap. Payment Recovery remains #1; Retention Economics remains #2 and gains the strongest new signal; GoProxies remains #3 with its economic gate overdue; Residential Vantage remains #4; Crypto-native Access remains #5 and becomes the weakest hold. Delight stays inside #2. Key Maker is pressure on #5, not rank #6. No candidate is yet a proven opportunity.
- Inner ring
- 01 Payment Recovery (measured validation lead) · 02 Retention Economics (conviction up; Delight inside the lane) · 03 GoProxies conversion system (funnel visible; paid-test economics parked and overdue) · Poland incentives (reserve, drop-lean).
- Generative ring
- G1 plan-migration · G2 VPN↔proxy cross-sell · G3 node-community launch audience · G4 winback engineering · G5 B2B packaging (held). All L0 by definition; ranked on asset-fit, never dressed as validated.
- Separate Kairos slate
- K1 cross-boundary exception room · K2 Standard-of-Performance ratchet · K3 managed relay applications · K4 Key Maker. Key Maker has first-party MN problem signal and stronger adjacent-category/commercial evidence than #5, but its external buyer, price and delivery economics remain unverified.
- Outer ring
- 04 overall · Residential Vantage (discovery; supply falsifier first) · 05 overall · crypto-native access wedge (weakest hold; smoke test still unrun) · provenance (hold, folded) · grant-CR (one bounded pass).
- Method
- Thresholds before data; L0–L4 evidence ladder with A–D grades per claim; proceed needs ≥L2 numbers plus L4 semantics; flip conditions published; blind re-derivation adjudicated before release.
- Blindspots
- Twelve untouched areas, now a working map: ten quests in three lanes (warehouse · human · corpus) plus one watched and one standing row, each with a decision rule written before the data, an owner column, a predicted days-to-signal, and a status derived from the map's own event record. Warehouse lane leads with non-Stripe payment funnels (~62% of July gross); human lane leads with metric lineage and the owner map (the L4 gate). The map carries its own kill test: unused by day 21, it says so.
- Access effect
- Eleven source connections: 2 SOURCE_READY, 3 MAPPING_PARTIAL, 6 SOURCE_BLOCKED. BigQuery and Slack lower time-to-signal for internal lanes; GoProxies economics and Vantage supply still depend on MN-side evidence.
- Acquisition watch
- Context lane only. It raises the weight of retention, revenue quality, margins, distribution, reliability and transferable assets; Key Maker reduces diligence friction but does not create acquisition value.
- Authority
- No material pursuit, build, outreach programme, transfer or spend is authorized by this page. Product-touching generative tests are joint decisions with an MN owner; market-side tests run in Kairos authority.