Encryption protects what you say, not the fact that you said it. Signal and Proton scramble the contents of a message, and the provider still sees your IP address, the timing, and who you contacted. Feed that residue to an analytics model and the envelope routinely says more than the letter.
Content privacy has been solved and then competed down to near zero margin. The unserved layer is the network itself: who you are, who you are talking to, when, and from where, plus the ability to reach the open internet at all. That layer is where censorship is actually enforced, where the AI era created new demand, and where the only durable revenue in privacy has turned out to be. Almost nobody is building it as a business.
Metadata is the layer nobody serves
The encrypted messaging market treats the message body as the asset worth defending, which made sense when the adversary was a human reading mail. It makes much less sense against a model that never reads anything and only correlates. A provider that knows your address, your correspondents, the time of every exchange and the network you connected from can reconstruct most of what matters without decrypting a single word. Vitalik Buterin makes the same point in blunter terms: whoever holds the information holds the power, and the information that leaks by default is not the content.
AI turned privacy from an ideology into a paid product
Privacy sold on principle never converted, and it started converting only when prompts became a logged asset class. A court ordering millions of ChatGPT conversations produced did more for the category than a decade of advocacy, because it converted an abstract risk into a discovery request. The response has been real: Venice reached unicorn status and Proton's Lumo passed ten million users. What almost none of it protects is the identity of the person asking. These products encrypt the prompt and leave exposed who is querying which model, from where, and how often, which for an agent operating on your behalf is the more sensitive fact.
Access itself is becoming the scarce good
The valuable half of the web is moving behind anti-bot walls, and the economics of that are shifting from exclusion to tolling. Cloudflare shows the shift most clearly, moving from blocking crawlers toward charging them through pay-per-crawl and signed-agent identity. Courts have so far largely protected the scraping of public data, so the contest is migrating from whether you may read the web to what you pay and how you prove who you are. In both cases reaching the content requires residential access rather than a datacenter IP, which turns plain reachability into a priced input.
The censorship side of this is the same problem with higher stakes. National firewalls in China, Russia and Iran block by IP address, and datacenter VPN ranges are trivially enumerated and cut. Roughly ninety percent of Iranian internet users depend on a VPN, and 2025 was the worst year on record for deliberate shutdowns. The users for whom privacy is daily-critical are therefore the users a datacenter VPN cannot reliably serve. The hardest segment to serve and the most defensible product to build require the same architecture.
The consumer market is a five-dollar contest
Consumer privacy is a commoditised race to roughly five dollars a month, competing on server counts and streaming unblocks rather than on any property a privacy engineer would recognise. The decentralised cohort that tried to fix this on ideology lost badly, and Nym and Orchid both drew down more than ninety-nine percent. The clearest measure of that gap is that only about six percent of US adults use a data-removal service, set against a data-broker industry worth hundreds of billions. Demand is loud in surveys and thin in wallets, and that gap has killed every consumer privacy company that mistook stated preference for willingness to pay.
Grass is the exception, and it locates the money precisely. Grass worked by selling verifiable residential access and web data to businesses rather than shipping another consumer app, which is the same conclusion the incumbent market reached long ago. Residential access is a one-and-a-half to two billion dollar market, and Bright Data alone runs at roughly three hundred million in annual recurring revenue. The buyer is a company with a procurement process, not a consumer choosing between a VPN and a coffee.
What the comparables actually prove
The claim that privacy does not sell is wrong, and the comparables settle it. Proton runs roughly $134 million in revenue on 671 employees, NordVPN about $357 million at a $3 billion valuation on 1,800 people, and DuckDuckGo around $200 million on 335. On the enterprise side the numbers are an order of magnitude larger: Zscaler at $3.36 billion in ARR growing 25 percent, Cloudflare at $2.81 billion growing 30 percent, both public, and Tailscale at $45 million ARR on $275 million raised at a $1.5 billion valuation. This is a multi-billion dollar market on both sides of the house.
The totals matter less than what each company demonstrates. NordVPN is the Coca-Cola of consumer VPNs, an empire built on marketing and distribution rather than on any cryptographic advantage, which is the clearest evidence that consumer privacy is won on brand rather than on architecture. DuckDuckGo shows you can monetise without a profile, matching ads to the query instead of the person. Proton shows the suite compounds: it started as encrypted email and grew into mail, VPN, drive and calendar, open source and without ads, so each product lowers the cost of selling the next.
The enterprise names prove something more valuable to anyone building at the network layer. Zscaler routes all of a company's traffic through its own cloud and replaces VPN access with per-app, identity-based access, and the market pays $3.36 billion a year for it. Cloudflare arrived from the opposite direction, as a CDN and security business, and now positions Zero Trust and WARP as the VPN replacement. Both are re-architecting how companies reach the network, and both are being paid billions to do it. Tailscale is the smallest of the six and the most instructive: $45 million in ARR built by winning individual developers with simple mesh networking and letting them pull their employers in behind them, which is the distribution model any technical network product should study.
Read the two groups together and the gap is obvious. The consumer names sell brand and convenience. The enterprise names sell access control and identity. Not one of the six sells metadata privacy, because none of them owns the layer where metadata is produced. That is the same conclusion the failed token cohort reached from the other side, and it is why the opportunity sits underneath all six rather than alongside them.
You are trusting the cap table, not the cryptography
Take ExpressVPN as the example. In 2021 it sold to Kape Technologies for roughly $936 million. Kape was until 2018 called Crossrider, a browser-extension and ad-tech platform whose toolkit was widely used to distribute adware, and it now also owns CyberGhost, Private Internet Access and ZenMate, alongside review sites that had been ranking those same products. In the same year, ExpressVPN's chief information officer entered a deferred prosecution agreement with the US Department of Justice over earlier work on a UAE surveillance programme. No cryptographic property changed on any of those days. What changed was who held the logs, and a customer had no way to observe it.
That is the structural weakness of every no-logs promise: it is a claim about a company's intentions, and companies get bought. A consumer choosing between providers is really underwriting an ownership structure they cannot inspect and cannot monitor after the fact. Verification at the network layer is the only version of this that survives an acquisition, because a proof about traffic does not care who owns the equity.
Provenance is turning into a procurement test
Residential IP sourcing is now under regulatory scrutiny, and buyers have started asking where the supply came from rather than accepting that it works. That question is difficult for any network that acquired its addresses by bundling consent into an unrelated installer, and straightforward for one built on opt-in supply with an audit trail. Consented, verifiable sourcing is moving from a marketing line to a purchasing criterion. Markets reorder on procurement rules more often than on technology.
What a network-layer answer requires
The specification is four requirements, and each one raises the cost of the next. Traffic exits through real residential addresses, because those stay authentic and unblockable when datacenter ranges get cut. Entry is decentralised and self-healing, rotating across many addresses so a censor blocking known entry points does not sever the network. Verification is mechanical rather than promised: each address is proven live, residential and performant, which converts trust our nodes into verify our nodes. Revenue comes from usage rather than emissions, because a network that needs token incentives to survive stops the day the incentives do.
URNetwork is the furthest along on all four together, and it is far enough along to be judged on operating facts rather than intent: more than one hundred thousand residential providers carrying encrypted traffic for over three hundred and fifty thousand monthly users, organised as roughly two hundred top-tier nodes with their own on-chain identity above a long tail in pools that supplies geographic density. A Bittensor subnet funds and scores the supply side so coverage grows faster than organic demand would allow, and a business VPN aimed at developers and smaller companies earns revenue today.
The two costs that killed the category
Every previous attempt at network-level privacy failed on one of two taxes. The first is latency, and Nym is the cautionary case: a mixnet that genuinely obscured traffic patterns and was too slow for anyone to use voluntarily. The second is crypto friction, where a wallet, a token and a bridge sit between a person and a working VPN, which loses the entire non-crypto market immediately. Any winner has to deliver network-layer privacy without either, which in practice means the token has to be invisible behind a product that behaves like software people already know how to use.
The latency tax is a function of hop count, and that relationship sets the ceiling on every design in the category. A single-server VPN is one hop: fast, and the operator sees everything. Tor takes three relays and pays for it in hundreds of milliseconds. A mixnet adds batching and cover traffic, which is what actually defeats timing analysis, and costs seconds. Multi-hop routing across two or three residential nodes sits in between: no single node sees the full path, and the cost is still measured in milliseconds rather than seconds. That is the position worth holding, and the open research question is how much partial mixing can be borrowed from the mixnet literature before the speed advantage disappears. The tiers below are orders of magnitude rather than benchmarks.
The purists raised the money and never found the users
Take Nym as the example: it is the most cryptographically serious project the category has produced, a real mixnet with batching and cover traffic, and the only design on this list that defeats timing analysis rather than merely hiding an IP address. It was funded accordingly, backed by Andreessen Horowitz, Polychain and Binance Labs, and it shipped what it promised. The token is down more than ninety-nine percent from its peak, and the reason is not that the cryptography failed. The cryptography worked, and it cost seconds of latency, which no ordinary person will trade for a guarantee they cannot perceive.
Orchid raised roughly $48 million from Andreessen Horowitz and Sequoia to build a bandwidth marketplace with staking and per-packet payment. Mysterium ran an ICO on the same premise. Both put a wallet, a token and a funding step between a person and a working connection, and both were competing with a five-dollar product that opens and connects. Every one of them treated distribution as somebody else's problem, on the assumption that a sufficiently correct design would find its own users. None of them did.
Set that against what actually got bought. NordVPN offers weaker guarantees than any of them and runs $357 million of revenue on 1,800 employees. Proton, which is genuinely open source and audited, runs $134 million and grew by adding mail, drive and calendar rather than by adding cryptographic strength. The purists were right about the threat model and wrong about everything downstream of it. Correctness was sold to a market that was buying convenience.
The lesson for anyone building at the network layer is narrow and expensive to ignore. The bar is not a stronger guarantee than Nym managed but a guarantee that costs the user nothing to adopt: no wallet, no token, no bridge, and no perceptible latency. That constraint eliminates most of the architectures the category has tried, which is precisely why the position is still open. The same trap is also still open, and a team that ships proofs before it ships a product people will actually keep installed ends up exactly where this cohort did.
The position is the asset, not the product. Content privacy is a crowded market for a solved problem. Access to the open internet is becoming a priced, contested input for humans and for agents, and the layer that decides reachability has no serious commercial owner. Sitting underneath the stack takes longer to build than competing inside it and is correspondingly harder to displace.