What the company can and cannot measure
Month one ends today. The sprint ran from 10 August to 11 September, and this edition is the written record the review reads from.
This week the work turned from Mysterium's data to Mysterium's own reporting. We read every all-hands deck from January 2024 to September 2026, opened the picture layer that earlier passes could not see, and separated two questions that had been running together: what the company stopped telling itself, and whether the numbers still exist to tell. Alongside that we read the customer estate through five independent openers, closed a seven-day investigation into where a customer's intention survives a transition, and built a working demonstration of a complete consumer product.
None of it is a commercial outcome. No intervention has run, and no revenue, retention, reliability or cost figure has moved. This edition reports evidence, corrections, and the decisions the evidence now makes available.
What we did
Artifacts produced, heaviest job first — not a list of activities.
1. Read the all-hands deck series end to end, including the picture layer.
- Opened all 33 dated decks as OOXML. There is no machine-readable chart layer anywhere in the corpus: zero native chart parts and zero embedded workbooks. Every chart the company has shown its staff in three years is a flat picture.
- Read all 187 unique images, by optical character recognition and again visually, each visual read done by a reader given a neutral extraction brief and no hypothesis. Until that pass ran, every claim about a missing metric was an upper bound rather than a fact. It is now closed, and closing it moved one answer.
- Separated disclosure from capability for each metric: whether the deck series once showed it, and whether the warehouse can produce it today. Paid acquisition and the cost side answer one way; churn, retention and lifetime value answer the other. Paid acquisition is the harder of the two.
- Named the three ways the finding could have been wrong and tested each: a cost metric hiding inside the 2025 and 2026 chart images, a separate finance forum carrying the reporting, and a corpus with missing decks. The first moved the date by which reporting stopped. The other two are refuted.
2. Read the customer estate through five independent openers, and produced the customer evidence the product argument rests on.
- Coded every free-text answer in the in-app cancellation survey against one codebook, and dated the wrong-plan complaint to a specific product change.
- Ran twenty blind stratified customer journeys across six keys, naming the screened and excluded cases rather than dropping them.
- Completed the paying-account map: every qualified 2026 closed-cycle account dispositioned, with the blind support audit run to completion and its coverage recorded beside it.
- Extracted the company's growth-metrics workbook twice, blind and independently, then red-teamed the difference on denominators before anything was reported from it.
- Reconciled two warehouse sources that disagree about refunds, and located most of the money difference on dates that only one of the two sources returns.
3. Closed the seven-day investigation into where a customer's intention survives a transition, which is also where the product reliability evidence came from.
- Tested what survives a replacement purchase, a subscription resume, an address refresh and a changed observation window. Those are the transitions where the customer has already decided and the product still has to deliver.
- Reproduced, at pinned client source, a case where accepting the resume prompt drops the customer's requested exit address from the retry. A one-line candidate retains it. Opposing review accepted the source reading and did not establish installed-build behaviour, so it stays unadopted.
- Established what the public node listing does and does not measure, after our own two-hour experiment produced a result the instrument could not support.
- Built and browser-tested a private matched comparison of two retry designs, and ran offline playback experiments on public traces to test whether a warning can be given early enough to act on.
4. Rebuilt the residential-versus-datacenter job test after an opposing session found a power defect in it.
- The plan reached its third version through three blind review rounds. A fourth reader then showed that at the only published base rate, the test as designed could not have detected the effect it was built to find. All three earlier rounds missed it, and so did we.
- Inverted the selection rule: pick the task classes on documented operational blocking rather than on terms of service, after verifying at source that one major service's terms restrict geography and never mention proxies at all.
- Dropped one whole task class on a design argument rather than a measurement one. Repeated requests from rotating residential exits against a third party's booking systems is a cost we would be imposing on someone who never agreed to the experiment.
5. Took the network's direct product economics apart from first principles.
- Derived the physical floors of a residential-address VPN, wrote the cheap falsifier under each, and checked them against our own source and registry findings rather than against marketing.
- Compared what the network pays its operators against the capacity those operators have installed. Paid usage sits orders of magnitude below that capacity, and the gap held at the most generous corner of a sensitivity grid. The capacity side counts earning identities, which are not the same thing as independent households, so it is an upper bound.
- Ran it past two peer sessions and landed both sets of corrections, including one that walked back two of our own overclaims about routing and one that disqualified vendor valuation figures as evidence that residential access works. The same rule disqualifies Mysterium's own marketing.
6. Built a working demonstration of a complete consumer product.
- Elsewhere shows one continuous journey: arrival, purchase, use, a recoverable interruption handled without asking the customer to retry, and the end of the job. It runs in a browser and needs no sign-in.
- It is a demonstration, not a proposal for a venture and not a commitment anyone has made. Its connection outcomes are authored; no network performance is measured by it, and nothing in it is an MN production change.
- The point it is built to make is narrow: the work a customer should never have to notice is the product, not a missing button.
7. Kept the data estate and the delivery surfaces working, and put a comment layer under everything we ship.
- The one-page opportunity portfolio for the September board meeting is live behind access and reads correctly for the core tier.
- The complaints work now ships as a ranked briefing rather than a certified study, after the first version was read and found unclear.
- Root-caused the daily brief's staleness to a disk exhaustion that silenced the scheduled run, repaired the failure path, and red-tested the repair.
- Diagnosed three co-timed monitoring alerts as one cause, and not the cause they named: the machine had lost its uplink. The watches now separate an offline machine from a dead instrument.
- Built Margin, a mark-and-comment layer, across the War Room. A reader can now mark a passage and answer it where it stands, so access and delivery of a finding no longer end at reading it.
What we found
Each line opens with how much weight it can carry.
- Verified The cost side left the company's own reporting in January 2025, and the picture layer is where the last of it was hiding. Acquisition cost carried a numeric target with monthly actuals through 2024; a single January 2025 slide set revenue against costs; nothing after it does. What survives of paid acquisition reporting is three adjectives in twenty months, and the most recent one glosses the term for its own audience.
- Verified Acquisition cost is not producible from the warehouse today. No cost, spend, budget or ad-platform column exists in any dataset, no pipeline has ever landed spend, and the attribution table that holds the other half of the ratio now assigns almost every purchase to direct or none. This is a capability finding, not an accusation, and it is the stronger of the two because it does not depend on anyone's motive.
- Verified Churn, retention and lifetime value are the opposite case. Those tables are live and were refreshed the same week the deck was presented, and a monthly consumer-VPN churn series is one join away from two of them. Not showing them is a choice; not showing acquisition cost is a limit.
- Verified A reported year-on-year improvement in the staff survey is a response-rate artefact. The score rose while the number of favourable respondents fell, because a large part of the previous year's respondents did not answer at all. Participation was disclosed on its own slide; the disclosure and the comparison were kept apart, and a shrinking response base is not a comparable series.
- Verified A flow presented as releasing next week was not in production three days later, on the company's own task board. The survey that asks people why they cancelled has been collecting answers for about fifteen months while the flow to let them cancel was still being built.
- Inference The claim that acquisition is now bringing higher-quality users is equally explained by a shift toward longer prepaid terms, which books more revenue per transaction without any change in the customer. It is decidable against the warehouse by decomposing year-on-year August revenue per transaction by plan term. That decomposition is pre-registered and its method passed a blind cross-family review this week; it runs next. If term mix and price carry the lift, the claim currently justifying the acquisition strategy is unevidenced.
- Inference What the network pays its operators, set against the capacity those operators have installed, implies utilisation far below one percent. If it holds, the node network is not a supply constraint waiting to be relieved but an asset with almost no demand against it. Two things would kill it. Off-chain revenue invisible to an on-chain decode would have to run more than a hundred times the decoded settlement before capacity binds at all. And the capacity side counts earning identities rather than independent households, so a mapping that collapses many identities onto one connection closes the gap directly. Opposing review accepted the observation this week and refused the stronger reading, so demand limitation stays a hypothesis beside geographic scarcity rather than a conclusion.
- Verified The public node listing can omit an eligible node simply because a different subset was returned. The endpoint applies a per-country record cap while iterating an unordered map, and filters afterwards. A direct lookup returned every one of a seeded sample of nodes the listing had just omitted.
- Verified The exhaustion notice a customer sees when refreshing an address does not measure exhausted supply. The client emits it when successful refresh registrations reach a location count, without inspecting distinct returned addresses or requiring a failed attempt.
- Killed Mysterium's residential inventory as an uncontested network-measurement business does not survive its incumbents. One vendor already sells measurement from end users' home networks, and another excludes VPN-hosted probes by design because tunnelling distorts the route being measured. What remains is narrower: selected additional vantage points for an existing buyer, conditional on node-local execution, origin and measurement quality being demonstrated.
What we changed our mind about
What we got wrong, printed next to what replaced it. The week this section is empty is the week to distrust the page.
- Our own two-hour node-availability experiment was measuring the wrong thing. The apparent disappearance of nodes between samples was the listing endpoint's sampling behaviour, not provider churn, and the geography of the effect is what exposed it. The reliability reading is withdrawn; the falsification and the retrieval rule that follows from it are the results that stand.
- The residential-versus-datacenter test plan had a power defect that three blind review rounds missed, and so did we. A test that cannot detect the effect it is built to find returns a null that says nothing about the world, so the null we would have reported next week would have been about the instrument, not about residential addresses.
- Our reading of the 2024 advertising-return figures took a threshold row for a monthly actual. We re-read the raw slide markup for the three months concerned and corrected it. The finding it sat inside was unaffected; the number was not ours to get wrong.
- A cancellation-cause table was sorted by row count while displaying user count, which inverted the top pair. Something breaking leads, not the subscription no longer being needed. The sort is corrected, and so is the prose that rested on it.
- A peer session's conclusion that supply cost consumes most of revenue used a revenue baseline our own facts board strikes through. At the measured denominators it is a far smaller share, and we reconciled the rate contradiction rather than letting the two numbers stand side by side.
- Last week's paid-acquisition ask is withdrawn, because we answered it ourselves from a source we already held. A current internal workbook shows material weekly paid spend by product, which settles the fork the ask existed to settle. What it does not carry is the channel and campaign split, and we will ask for that only when a specific allocation decision needs it.
- Last week's attribution-owner ask is parked for the same reason rather than reprinted. We have reached the ceiling of what internal evidence can establish about the attribution lineage; the remaining facts are live platform configuration, which is worth a request only against a decision.
- The Pipedrive ask is reprinted below rather than quietly dropped. It has gone unanswered for two weeks, and the credential still does not authenticate.
Next week
Committed, and checkable against next Friday's edition.
- Run the plan-term decomposition on year-on-year August revenue per transaction and report whether the higher-quality-users claim survives it, including if it does not.
- Run the rebuilt residential-versus-datacenter test at its corrected base rate, one variable at a time, and report the power calculation beside the result.
- Close the seven-day investigation's remaining transition questions with a changed contract or a genuinely different source, not another catalogue entry or another synthetic click-through.
- Take the customer estate's five reads into one connected customer picture, preserving the distinctions between contacts, accounts, people and outcomes.
- Install the comment layer on the remaining Kairos pages, so that every finding we ship can be answered where it is stated.
What we need from you
Ranked by what it unblocks. Named person, exact thing, by-when.
first one with a date of its own · Šarūnas, Wed 16 Sep — ask 2 (then 4 more). The order below is what each one unblocks, not when it is due.
- Robertasby the end of today's review
the continuation decision, its scope, and who owns it. Month one ends today, continuation was always conditional on it, and everything below assumes an answer to this one.
- Šarūnasby Wed 16 Sep
the VPN and SuperProxy revenue split for August. The 4 September revenue bridge does not close from the deck's own figures, and the split is the one thing that would close it.
- Šarūnasby Wed 16 Sep
the replacement Ahrefs key requested on 5 September. The existing key has not authenticated since 27 August, and the search room reports a dead source every day it stays that way.
- Robertasby Wed 16 Sep
confirmation of whether the cancellation flow is in production, and the name of the person who can confirm it. The board saw it as releasing; the task board three days later did not.
- Šarūnasby Wed 16 Sepcarried from week 3
the read-only Pipedrive grant. The current credential still returns an authentication failure, and the CRM room stays uncommissioned until it lands.
Notes
The caveats that belong on the record, not in the call.
Every figure behind these findings — the deck values, the survey counts, the warehouse denominators, the customer records and the reviewer receipts — stays in the protected Kairos room and travels in the call. This public weekly carries the decisions, the evidence limits, the corrections and the asks.
The commitments under Next week are ours to keep and are checkable against next Friday's edition. They assume the engagement continues past today's review; if it does not, this edition is the closing record rather than a midpoint.
The mechanical sweep first counted every dated record inside the seven-day window, then selected records carrying both a Kairos or Mysterium scope term and a landed-work term. Classification is first-match-wins in the published rule order, and every selected record carries its matched scope, landed and rule terms without raw log text. Two new included groups were added this week for the seven-day investigation and the all-hands deck series; three new parked groups cover machine upkeep, private working notes and agent plumbing, none of which produced a client artifact.