# VPNCheap Feedback Portfolio and Release Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **92/100**. Use this versioned release repository as the portfolio documentation owner while GitHub remains the operational source of truth. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Why this repository owns the portfolio layer

- **MEASURED:** the physical `VPNCHEAP/` parent is not a valid Git repository.
- **MEASURED:** this repository already owns shared native release assets and public issue intake.
- **PROPOSED:** it owns generated portfolio views, support policy, and release discovery, but never becomes the default code-fix destination.

Canonical home choice: `vpncheap-app`, **91/100**. It is versioned and already release-facing. Storing canonical docs in the unversioned parent scores **24/100**. Building a second custom issue database scores **37/100** because it would drift from GitHub.

## Current state

`☐☐☐ | 0/0/3/0`

| State | IDs | Portfolio obligation |
|---|---|---|
| `☐` | VPN-18, VPN-19, VPN-20 | Unified ownership view, support matrix, and release index remain open. |

```text
BEFORE  issue lands anywhere -> owner guessed -> release path rediscovered
AFTER   one intake -> canonical owner -> acceptance receipt -> release indexed
```

## Canonical VPNCheap fingerprint registry

This is the single portfolio score for VPN-01 through VPN-20. Shared work such as VPN-12 appears once even when several component plans contribute.

| ID | State | Required outcome | Breakdown `H+R+E+L+U+V` | Score | Band | Accountable repo and dominant factor |
|---|---|---|---:|---:|---|---|
| VPN-01 | `☐` | Confirm the affected desktop platform, then diagnose connect-then-drop before changing teardown. | `24+3+12+5+5+10` | 59 | P2 | A: `vpncheap-app` intake; R: provisional Windows candidate, confirmed client/core owner, node operations if measured; blocker harm plus missing platform/timeline. |
| VPN-02 | `△` | Verify shipped Flutter macOS disconnect fix. | `24+7+12+5+10+10` | 68 | P2 | A: `vpncheap-flutter`; R: Flutter host/core boundary; real-device closure missing. |
| VPN-03 | `△` | Prove purchase and account freshness end to end. | `24+7+12+15+10+10` | 78 | P1 | A: `vpncheap-apple-native`; R: Store flow + Xboard account truth; money/access truth dominates. |
| VPN-04 | `△` | Prove bounded Apple TV refresh on hardware. | `16+7+12+10+10+10` | 65 | P2 | A: `vpncheap-apple-tv`; R: tvOS node rendering/cache; hardware proof missing. |
| VPN-05 | `☐` | Eliminate macOS green-without-internet. | `30+3+12+10+10+10` | 75 | P1 | A: `vpncheap-macos`; R: macOS core/OS route-DNS boundary; false-green is outage-level correctness. |
| VPN-06 | `☐` | Attribute desktop slowness across client and service phases. | `16+7+12+15+5+10` | 65 | P2 | A: `vpncheap-app`; R: Windows, macOS, node/service operations; portfolio leverage plus absent attribution. |
| VPN-07 | `△` | Verify Android selected-node persistence. | `24+7+12+5+10+10` | 68 | P2 | A: `vpncheap-android`; R: Android node repository; lifecycle proof missing. |
| VPN-08 | `△` | Verify Android cold Quick Settings start. | `24+7+12+5+10+10` | 68 | P2 | A: `vpncheap-android`; R: Android tile/controller; cold-process proof missing. |
| VPN-09 | `△` | Measure Android QUIC/DoT fallback latency. | `24+7+12+5+10+10` | 68 | P2 | A: `vpncheap-android`; R: Android config builder + node operations if measured; causal before/after missing. |
| VPN-10 | `△` | Pass Android TV node-state release matrix. | `24+15+12+15+5+10` | 81 | P1 | A: `vpncheap-android-tv`; R: TV client + Xboard node service; systemic recurrence and no TV receipt. |
| VPN-11 | `△` | Prove old-token rejection and new-token success. | `30+3+12+15+10+10` | 80 | P1 | A: `Xboard`; R: token middleware + app/edge cache; access-security harm dominates. |
| VPN-12 | `△` | Pass one released-build native node matrix. | `24+15+12+15+5+10` | 81 | P1 | A: `vpncheap-app`; R: all supported native clients, including Windows, + Xboard node service; sole canonical cross-client score. |
| VPN-13 | `☐` | Design signed official-client capability. | `24+3+5+15+0+7` | 54 | P3 | A: `Xboard`; R: Xboard auth + every supported client identity adapter; still an evidence-gate proposal. |
| VPN-14 | `△` | Retry TLS fix on affected macOS machine and release. | `24+3+12+5+5+10` | 59 | P2 | A: `vpncheap-macos`; R: TLS classifier/failover; affected-device proof missing. |
| VPN-15 | `△` | Prove one selection equals one actual egress. | `30+3+12+10+10+10` | 75 | P1 | A: `vpncheap-macos`; R: config adapter/election/core; traffic-identity correctness dominates. |
| VPN-16 | `☐` | Deliver Android forgot-password recovery. | `24+3+12+0+5+7` | 51 | P3 | A: `vpncheap-android`; R: Android recovery UI + Xboard reset contract; account-access harm, local scope. |
| VPN-17 | `☐` | Publish server revision and cross-client freshness semantics. | `24+15+12+15+5+10` | 81 | P1 | A: `Xboard`; R: Xboard state/cache + every supported client adapter; systemic reach and no receipt. |
| VPN-18 | `☐` | Generate one GitHub-backed feedback board. | `16+15+12+15+5+7` | 70 | P2 | A: `vpncheap-app`; R: owning repo maintainers; portfolio reach and leverage dominate. |
| VPN-19 | `☐` | Publish one support matrix from project truth. | `8+3+20+10+5+7` | 53 | P3 | A: `vpncheap-app`; R: Apple Native + macOS release owners; measured policy contradiction. |
| VPN-20 | `☐` | Publish a canonical release index. | `16+3+12+15+5+7` | 58 | P2 | A: `vpncheap-app`; R: every client release owner; release-discovery debt and leverage dominate. |

Registry check: `20/20`; `○0 / △11 / ☐9 / X0`; all factor values, sums, bands, and sole VPN-12 mapping validated.

## Durable evidence index

Evidence envelope:

- Audit snapshot: **2026-07-31 JST**.
- Recall window: **[2026-07-02 15:00 UTC, 2026-07-31 15:00 UTC)**.
- VPN scores do **not** use ReplyTower production volume. The Reach factor uses only the incident clusters and recurrence shown below, plus a systemic path verified in the owning repository. ReplyTower conversation, message, user, and attachment counts never enter a VPN score.
- Synthetic conversations are excluded. This index contains no customer-specific network address or topology, raw transcript, customer identifier, or credential; generic protocol classes remain only where needed to identify the code path under test.
- A code path or unit test is an implementation receipt, not closure. `△` requires the named device, store, production, or cross-client acceptance receipt before promotion to `○`.
- Historical-source counts are per fingerprint and are not additive across the registry. One privacy-safe source can support several distinct customer journeys; each row below remains one deduplicated fingerprint.

### Privacy-safe historical source receipts

These receipts are paraphrased from the recall ledger. They retain timing, evidence class, affected surface, journey, deduplication, and recurrence basis while omitting session references, storage locations, raw customer wording, customer identity, and network details.

| ID | First observed, JST | Last observed, JST | Evidence class | Platform and version | Customer journey | Deduplicated incident and source count | Recurrence basis |
|---|---|---|---|---|---|---|---|
| VPN-01 | 2026-07-04 22:51 | 2026-07-04 22:51 | `QUOTED_CUSTOMER` | Windows assumed; app version unknown | Desktop connect to seconds-later disconnect | 1 incident cluster / 1 source to 1 fingerprint | Single report; earlier suspected causes were already disproven, but no second source was retained. |
| VPN-02 | 2026-07-09 15:58 | 2026-07-09 15:58 | `QUOTED_CUSTOMER` | Flutter macOS, historically labeled legacy; app version unknown | Connect to recurring disconnect | 1 incident cluster / 1 source to 1 fingerprint | One owner relay explicitly described repeated user reports; the underlying user count was not retained. |
| VPN-03 | 2026-07-11 20:40 | 2026-07-11 20:40 | `QUOTED_CUSTOMER` | Apple native client; OS and app version unknown | Purchase to refreshed account access | 1 incident cluster / 1 source to 1 fingerprint | One post-change regression report; broader recurrence not claimed. |
| VPN-04 | 2026-07-12 12:45 | 2026-07-12 12:45 | `QUOTED_CUSTOMER` | tvOS; affected app version unknown | Manual refresh to responsive node view | 1 incident cluster / 1 source to 1 fingerprint | One quoted report; hardware recurrence not retained. |
| VPN-05 | 2026-07-15 15:08 | 2026-07-15 15:08 | `QUOTED_CUSTOMER` | macOS 2.0.26, build 179 | Node selection to usable internet | 1 incident cluster / 1 source to 1 fingerprint | One support case with an exact affected build; later releases do not prove closure. |
| VPN-06 | 2026-07-15 15:23 | 2026-07-15 15:23 | `QUOTED_CUSTOMER` | Windows and macOS; versions unknown | Desktop connect to acceptable responsiveness | 1 cross-platform incident cluster / 1 source to 1 fingerprint | One relay explicitly described recurring reports on both desktop families; per-platform user counts were not retained. |
| VPN-07 | 2026-07-17 08:57 | 2026-07-17 08:57 | `QUOTED_CUSTOMER` | Android; affected version unknown | Process death to selected-node restoration | 1 incident cluster / 1 source to 1 fingerprint | One detailed report; kept separate from the other same-source Android journeys. |
| VPN-08 | 2026-07-17 08:57 | 2026-07-17 08:57 | `QUOTED_CUSTOMER` | Android; affected version unknown | Cold Quick Settings action to connection | 1 incident cluster / 1 source to 1 fingerprint | One detailed report; no independent recurrence retained. |
| VPN-09 | 2026-07-17 08:57 | 2026-07-17 08:57 | `QUOTED_CUSTOMER` | Android v2; exact build unknown | Everyday browsing to acceptable response time | 1 incident cluster / 1 source to 1 fingerprint | One perceived-performance report; recurrence requires controlled measurement. |
| VPN-10 | 2026-07-17 08:57 | 2026-07-17 08:57 | `QUOTED_CUSTOMER` | Android TV 2.0.25 | App start to available node list | 1 incident cluster / 1 source to 1 fingerprint | One version-specific report; cross-client recurrence is tracked separately as VPN-12. |
| VPN-11 | 2026-07-17 17:37 | 2026-07-17 17:37 | `DIRECT_OWNER` | Xboard account service; client version unknown | Subscription reset to old-link rejection | 1 invariant incident / 1 source to 1 fingerprint | Direct owner observation of a security and access invariant; no customer-volume claim. |
| VPN-12 | 2026-07-18 | 2026-07-27 | `QUOTED_CUSTOMER` | Android 2.0.27 plus other native clients; other versions unknown | Login or refresh to available nodes | 2 incident clusters / 2 sources to 1 fingerprint | Recurrence spans two date clusters and expands from Android and TV to other native clients. |
| VPN-13 | 2026-07-18 14:23 | 2026-07-18 14:23 | `DIRECT_OWNER` | Xboard plus supported native clients; versions unknown | Official-client access to authorized subscription retrieval | 1 requirement incident / 1 source to 1 fingerprint | Direct owner requirement; systemic reach comes from the shared access path, not complaint volume. |
| VPN-14 | 2026-07-19 00:36 | 2026-07-19 00:36 | `QUOTED_CUSTOMER` | macOS; affected version unknown | Login attempt to trusted service access | 1 incident cluster / 1 source to 1 fingerprint | One support case after common local remediations failed; affected-device retest remains missing. |
| VPN-15 | 2026-07-25 21:57 | 2026-07-25 21:57 | `QUOTED_CUSTOMER` | macOS; affected version unknown | Automatic selection to one truthful connection identity | 1 grouped tester incident / 1 source to 1 fingerprint | Several correctness symptoms from the same tester were deduplicated because they share one connection-identity acceptance outcome. |
| VPN-16 | 2026-07-26, time unknown | 2026-07-27, time unknown | `QUOTED_CUSTOMER` | Android native; affected version unknown | Login failure to password recovery | 1 backlog incident / 1 source to 1 fingerprint | One relayed backlog item on 2026-07-31; recurrence count was not retained. |
| VPN-17 | 2026-07-26, time unknown | 2026-07-27, time unknown | `QUOTED_CUSTOMER` | Supported native clients; versions unknown | Top-up or renewal to fresh account and node state | 1 grouped freshness incident / 1 source to 1 fingerprint | Several stale-state symptoms in one relay were deduplicated under one shared freshness contract; Apple-specific purchase regression remains VPN-03. |
| VPN-18 | 2026-07-26, time unknown | 2026-07-27, time unknown | `DIRECT_OWNER` | Portfolio governance; version not applicable | Feedback intake to accountable owner and receipt | 1 operating-model requirement / 1 source to 1 fingerprint | Direct CEO requirement relayed on 2026-07-31; systemic reach comes from all owning repositories. |
| VPN-19 | 2026-07-26, time unknown | 2026-07-27, time unknown | `DIRECT_OWNER` | Apple native and macOS; product versions not applicable | Install or upgrade decision to clear support eligibility | 1 policy-gap requirement / 1 source to 1 fingerprint | Direct owner observation; recurrence is the measured contradiction across project sources, not customer count. |
| VPN-20 | 2026-07-26, time unknown | 2026-07-27, time unknown | `DIRECT_OWNER` | Cross-repository release operations; version not applicable | Build request to discoverable release path | 1 operating-gap requirement / 1 source to 1 fingerprint | Direct owner observation relayed on 2026-07-31; systemic reach comes from fragmented release paths. |

Historical-receipt check: `20/20` IDs present exactly once; VPN-12 is the sole two-source deduplication. Unknown time or version is stated rather than inferred.

| ID | Stable source reference | Current receipt or gap |
|---|---|---|
| VPN-01 | Provisional candidate only: `vpncheap-windows` `src/VpncheapWindows.Core/Vpn/VpnService.cs:74-114`; `HttpTunnelProbe.cs:17-75`; `VpnServiceTests.cs:309-349` | The Windows probe path is covered by a regression test, but the affected platform is unconfirmed. Portfolio intake must confirm client family/build before transferring accountability or running a platform diagnostic; no timeline attributes the seconds-later drop. |
| VPN-02 | `vpncheap-flutter`: commits `e0ea9e43`, `a6e8e38a` | The legacy macOS teardown fix is on `origin/main`; only static tests/builds are recorded, with no shipped-version adoption and real-device recurrence receipt. |
| VPN-03 | `vpncheap-apple-native`: commits `4dababf`, `8441f43`; `SubscriptionViewModel.swift:814-867`; `SubscriptionViewModelTests.swift:106-147` | Purchase-state polling and regressions exist; a sandbox/store purchase round trip on a released build is missing. |
| VPN-04 | `vpncheap-apple-tv`: commits `b1fc80c`, `b0f9004`; `NodeDisplaySanitizer.swift:65-108` | Cache implementation, benchmark, and 160 passing tests are recorded; Apple TV hardware/store-build refresh proof is missing. |
| VPN-05 | `vpncheap-macos`: commit `e1e111f`; `handoff.md:254-262`; `ProxyChainConnectivityProbe.swift:12-33` | The earlier routing change predates the later report, and connected state still lacks an end-to-end egress-liveness receipt. |
| VPN-06 | `vpncheap-macos`: commit `9910e21`; `ConfigAdapterService.swift:762-791`; `handoff.md:277-288`; `vpncheap-windows` current connection path | macOS has candidate mitigations, Windows has no matching root-cause commit, and no synchronized client/service phase trace identifies the earliest slowdown. |
| VPN-07 | `vpncheap-android`: commit `387467f`; `NodeRepository.kt:47-64,80-99,116-120` | Selection persistence is implemented; process-kill and relaunch verification on a supported device is missing. |
| VPN-08 | `vpncheap-android`: commit `387467f`; `LibboxVpnController.kt:132-163`; `VpnTileService.kt:48-59` | Cold-process fallback exists behind a live-session gate; supported-version Quick Settings cold-start proof is missing. |
| VPN-09 | `vpncheap-android`: commit `387467f`; `SingBoxConfigBuilder.kt:290-330` | The fallback mechanism is implemented; controlled before/after latency evidence on a real device is missing. |
| VPN-10 | `vpncheap-android-tv`: commits `1036061`, `ccfa613`, `493b981`; `AppContainer.kt:175-312`; `NodeListViewModel.kt:145-155` | Failover, self-heal, and refresh paths plus 85 tests exist; current Android TV device/network acceptance is missing. |
| VPN-11 | `Xboard`: `UserController.php:164-172`; `Helper.php:123-142`; `Client.php:19-31` | Reset and middleware paths imply old-token invalidation; a live old-token rejection, new-token success, and cache-boundary receipt is missing. |
| VPN-12 | Native clients: Android commits `b797aec`, `e88b5a9`, `464adea`; Android TV `1036061`, `ccfa613`, `493b981`; Apple Native `4dababf`; Apple TV `96e7662`; macOS `43c1b8f`; Windows `XboardNodeService.cs:55-91,164-234`, `NodeSelectionViewModel.cs:203-230` | Matching self-heals exist across several clients and Windows has node-fetch/refresh paths, but recurrence outlived unit/build evidence. One released-build matrix including Windows across login, refresh, subscription state, and account switch is missing. |
| VPN-13 | `Xboard`: `routes/web.php:90-92`; `Client.php:19-31`; `ClientController.php:61-87`; client identity adapters in Android `AppContainer.kt:126`, Android TV `AppContainer.kt:67`, Apple `XboardApiService.swift:240,248`, Windows `AppNetworkIdentity.cs:6-19` | Current identity strings select representation rather than authorize access and are inconsistent; a signed capability contract and compatibility rollout are not designed. |
| VPN-14 | `vpncheap-macos`: commit `92fcf17`; `UserFacingErrorMessage.swift:162-189` | TLS classification and failover hardening plus tests exist; retry on the affected machine using the released build is missing. |
| VPN-15 | `vpncheap-macos`: commit `9910e21`; `ConfigAdapterService.swift:771-791`; `AutoElectionReconciler.swift` | Election reconciliation and connection interruption plus 298 tests exist; no post-fix device capture proves displayed selection and actual egress agree. |
| VPN-16 | `vpncheap-android`: `ui/login/LoginScreen.kt`; `RegisterScreen.kt`; repository search over `app/src/main` and tests | Login and registration exist, but no reset route, backend contract, success/expiry UX, or acceptance tests were found. |
| VPN-17 | Apple `SubscriptionScreen.swift:57`; Android profile refresh callers around `AppContainer.kt:540-562`; Xboard state/cache paths | Partial refresh behavior exists; no universal authoritative-field, cache-invalidation, forced-refresh, and stale-state contract spans every supported client. |
| VPN-18 | `vpncheap-ai-loop`: `PREVIEW.md:1-27,44-49`; `drafts/issues_index.json`; this portfolio repository | Weekly intake is partial and issue handling remains manual; no authoritative, versioned cross-repository board with owner and receipt fields exists. |
| VPN-19 | `vpncheap-apple-native`: `VPNCheap.xcodeproj/project.pbxproj:605,632,700-701,758`; `CLAUDE.md:17`; `docs/00-MASTER-PLAN.md:83-93` | Build settings and planning/support documents declare conflicting minimum versions; no single derived support matrix exists. |
| VPN-20 | Flutter `.github/workflows/release.yml:1-60`; Apple Native `.github/workflows/ios-testflight.yml:1-61`; macOS `.github/workflows/release-macos.yml:1-23`; workflow inventories in Android, Android TV, Apple TV, and Windows | Release automation is fragmented and readiness varies; no canonical index records exact path, inputs, signing readiness, artifact, owner, and last verified run. |

Evidence-index check: `20/20` IDs present exactly once. Stable references are reviewable without retaining customer text or sensitive network details.

## Ranked plan

### Shared performance ownership

VPN-06 has one accountable integration owner: `vpncheap-app`. Responsible component owners are `vpncheap-windows`, `vpncheap-macos`, and VPNCheap node/service operations. This portfolio plan owns the synchronized test window and final receipt; each component owner supplies privacy-safe phase or service evidence and fixes only its earliest proven failure.

### 1. GitHub-backed portfolio board, program value: 88/100

**PROPOSED:** one GitHub Project or generated read-only view aggregates canonical issue, customer fingerprint, platform/client family, app version, cause family, accountable owner, responsible repositories, priority, `○/△/☐/X`, verification receipt, release, and last update. Repositories remain source of truth.

Preferred generated GitHub view: **93/100**. Copying issues into one repository: **29/100**. A bespoke kanban database: **37/100**.

### 2. Portfolio release index, program value: 83/100

**PROPOSED:** document for every client the canonical repo, workflow, trigger, required inputs, secret/signing readiness, artifact, distribution channel, owner, rollback, and last verified run. Link workflows; do not duplicate them here.

### 3. Routing contract, program value: 81/100

**PROPOSED:** route by client family, version/build, install source, and channel. Current standalone macOS routes to `vpncheap-macos`; explicit legacy Flutter macOS routes to `vpncheap-flutter`. Public intake is not code ownership. Ambiguous evidence stays NEEDS-INFO.

### 4. Supported-platform matrix, program value: 76/100

**PROPOSED:** derive minimum OS, architecture, distribution channel, latest supported version, legacy boundary, and end-of-support date from each project source of truth. Resolve the current iOS documentation contradiction and publish macOS 14 consistently.

## Proposed durable artifacts

- `docs/portfolio/support-matrix.md`
- `docs/portfolio/release-index.md`
- `docs/portfolio/feedback-owner-map.md`
- `docs/portfolio/verification-receipts/`
- a generated board schema that reads GitHub issues and releases without copying their bodies

## Phases

- **0-30:** approve owner map and schema; inventory workflows, signing readiness, client identifiers, and support baselines; backfill the 20 canonical VPN fingerprints with source pointers for VPNCheap's 20 historical feedback records; do not import ReplyTower's 18 historical records or current seed.
- **31-60:** publish the generated GitHub-backed view and release index; keep the support matrix as an evidence-only draft; add routing fixtures for every client family and unknown cases.
- **61-90:** after scheduled P0-P2 gates close, publish the support baseline/matrix; automate weekly freshness checks and stale-owner alerts; require verification receipts for release closure.

Portfolio phase gates:

- **Day 30 exit:** 100% evidence coverage for the 20 canonical fingerprints, including accountable owner, source pointer, privacy classification, and required acceptance receipt.
- **Day 60 exit:** every scheduled P1 has its named acceptance receipt or an approved `X`; every scheduled P2 has an evidence envelope, accountable owner, acceptance card, and active execution slot.
- **Day 90 exit:** no scheduled P1/P2 remains at `△` or `☐`, or lacks an approved `X`; two consecutive canary windows complete without P1/P2 regression for changed cross-client, account, or release contracts.
- **Stop:** any listed guardrail breach stops the affected lane and prevents phase promotion until contained and reviewed.
- **P3 acceleration:** allowed only through the governance contract's documented exception; it cannot displace P0-P2 work or weaken their exit gates.

## Acceptance and stop conditions

- 100% of active fingerprints have one accountable owner and one canonical GitHub issue.
- No public-intake issue is treated as a code owner without routing.
- Every supported client has a discoverable release path and a last verified run.
- No P1 is called complete without a device/prod receipt.
- Stop if automation writes duplicate issues, copies private support text, leaks network details, or mutates releases without an explicit human gate.
