Lowlights

  1. Two enterprise deals slipped on SOC 2 Type II

    Both groups completed commercial evaluation and stalled at security review, which requires a Type II report we will not hold until Q4. Together they represent $14,000 of monthly recurring revenue, and neither has gone to a competitor.

    Evidence: pipeline review Jul 21; both accounts in security review since May.

    Mitigation: audit window opens Aug 17 with a fixed report date of Nov 6. Devon owns it, reported weekly. We are offering both groups a Type I report plus our penetration test summary in the interim.

  2. Churn crossed 1.0% and NPS fell three points

    One single-site clinic closed its practice, which took churn to 1.1%. Separately, an SMS retry defect caused duplicate reminders for clinics in two time zones for eleven days before we caught it, and it accounts for every detractor comment in the quarter.

    Evidence: churn ledger Q2; NPS verbatims, Jun 2026; incident INC-2038.

    Mitigation: defect fixed Jul 18 and we wrote to all 22 affected clinics before they contacted us. Churn now has a named owner reporting weekly rather than a dashboard nobody read.

  3. We planned Q2 from our best month

    The seventy-clinic target was extrapolated from March, our strongest month on record. Nothing underperformed in the quarter; the target was wrong when we set it, and that cost the team confidence they had not lost.

    Evidence: Q2 plan memo, Mar 30 2026.

    Mitigation: Q3 targets are set from the trailing three-month median. Q3 plan: 78 clinics, $52k MRR.