# VPNCheap Windows Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **90/100**. Capture decisive connect-time evidence before changing the current probe, then join shared freshness and desktop performance contracts. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Evidence and state

- **OBSERVED:** a desktop client connected for seconds and dropped; the platform is unknown. Windows is only an inferred candidate, and prior suspected causes were disproven.
- **MEASURED:** Windows currently uses a bounded connect-time HTTP probe and disconnects when it fails. This is candidate-path evidence, not attribution; no post-report evidence identifies the affected platform, timeout, DNS, route, process, port, or service cause.
- **OBSERVED:** severe slowness recurs across Windows and macOS; stale renewal/node state is a shared client contract gap.

`☐☐☐☐ | 0/0/4/0`

| State | IDs | Local obligation |
|---|---|---|
| `☐` | VPN-06, VPN-12 contribution, VPN-17, VPN-13 adoption | No real end-to-end closure exists. VPN-01 remains a portfolio-owned NEEDS-INFO item and is excluded from this local tally until the platform is confirmed. |

```text
BEFORE  12s gate fails -> disconnect -> generic ticket
AFTER   classified phase timeline -> owning layer -> bounded recovery -> receipt
```

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Scores below are canonical registry references, not local rescores: item 1 is the provisional VPN-01 candidate lane and is excluded from the local tally; items 2-5 -> VPN-06, VPN-12, VPN-17, and VPN-13 respectively.

### 1. Conditional connect-drop evidence card: 59/100, P2

Breakdown: `24 + 3 + 12 + 5 + 5 + 10`.

**PROPOSED:** `vpncheap-app` remains accountable for intake and platform confirmation. Preserve a redacted Windows timeline template for process start, port bind, config acceptance, route/TUN readiness, DNS, bounded probe, state transition, user cancel, and teardown; run it and transfer ownership here only if the affected platform is confirmed as Windows. Do not change the 12-second gate from an assumed platform.

### 2. Cross-desktop slowness attribution: 65/100, P2

Breakdown: `16 + 7 + 12 + 15 + 5 + 10`.

**PROPOSED:** run controlled Windows/macOS measurements against the same account, node cohort, time window, and service metrics; attribute startup, latency, loss, DNS, first-byte, and sustained throughput independently.

Ownership: `vpncheap-app` is A for VPN-06; `vpncheap-windows`, `vpncheap-macos`, and VPNCheap node/service operations are R for their measured layer.

### 3. Released-build native node matrix contribution: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** add Windows to the shared VPN-12 matrix across existing/new login, subscription state, empty list, manual refresh, account switch, cached-state expiry, and released-build recovery. Submit a Windows receipt to `vpncheap-app`; do not infer Windows success from other native clients.

### 4. Account/node freshness adoption: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** consume Xboard generation/revision, add explicit pull refresh and stale reason, invalidate account caches on top-up/renewal, and never require re-login for a valid server change.

### 5. Signed client capability: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Inventory the current versioned client identity and token/session flow before adopting Xboard's signed contract. UA-only authorization scores **18/100**.

Rejected shortcut: remove or lengthen the probe from anecdote alone, **34/100**. It may hide the symptom while allowing a false-connected state.

## Phases and acceptance

- **0-30:** help portfolio intake confirm VPN-01's platform without changing Windows code; if confirmed, reproduce with the diagnostic timeline; create the released-build Windows VPN-12 matrix card; freeze the P1/P2 freshness envelope; baseline cross-desktop performance.
- **0-30, P3 evidence only:** inventory signed-capability dependencies and collect its evidence envelope; this is ordinary evidence collection, not P3 acceleration, and no exception is claimed.
- **31-60:** run the Windows VPN-12 matrix; change only the proven failing layer; add probe classification, cache, account-switch, port, proxy-lock, and lifecycle tests.
- **61-90:** canary current Windows release and monitor connect-drop phase, false-connected, slowness, refresh, and re-login-required events; after scheduled P0-P2 gates close, define and adopt the signed-capability contract.
- `○` requires a real Windows tunnel transition and changed public egress on supported OS versions.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- No P3 acceleration is claimed; signed-capability work starts in 61-90 only after P0-P2 gates close.

## Guardrails

- Connect-time gating may withhold connected; no post-connected supervisory probe may auto-teardown.
- Never expose node address, ingress detail, protocol, subscription URL, or raw config in UI, logs, telemetry, or support bundle.
- Preserve DPAPI storage, list-only node presentation, Liquid Glass simulation, and UI-thread continuation rules.
- Stop on proxy residue, route leak, OS instability, sensitive logging, or false-connected acceptance.
