Behavioral trajectory simulator
Know what happens next, before it happens
Shadow forecasts what your live user segments will do if you change nothing — the decline, the confidence band, and the worst case — grounded in your own product data and backtested for calibration. Built for CTOs, product, and engineering leaders.
Current → p50
63% → 0%
Decline prob
0%
Fewer activations · 30d
~0
How to read it: the line is the median outcome (p50). The cone is the range 80% of simulated futures fall inside — its floor is your worst case. It widens with time because uncertainty compounds the further out you forecast.
Not synthetic personas
Shadow runs on your real users' behavior — not made-up profiles or interviewed strangers.
Not another churn score
Full 7/14/30-day trajectories with calibrated confidence bands and a worst case — not a single opaque number.
Not AI testing
Shadow forecasts your live users, not your code or click flows. It answers "what happens if we do nothing?"
Analytics explains what happened.
Shadow shows what happens next.
Every insight comes with a forward-looking trajectory. Where a cohort is too small or too new to forecast honestly, Shadow leaves it blank and tells you which check it missed.
Segment-Level Forecasts
7/14/30-day trajectories for every simulated segment, with a p10–p90 confidence band: 80% of simulated futures land inside it, and p10 is your realistic worst case.
Cost of Inaction
Every forecast quantifies what doing nothing costs — e.g. reviews lost over 30 days — with risk and escalation probability.
Production Safe
Read-only connector. No writes, no PII, no production impact. Encrypted and isolated by design.
Fast Integration
Connect the analytics you already run. Read-only, no SDK, no code changes — first forecasts in 3–5 working days.
You will see how often we were right
Before you act on a single forecast, we re-run the model against your own history and show how often reality actually landed inside the band we predicted — per cohort, including the ones we got wrong. If the bands don't hold on your product, you hear it from us first.
We simulate futures, not people
For every cohort we run twenty thousand possible futures and show you the middle one and the range. No invented users, no personas.
Your data, not a proxy
We read the events your product already sends to your analytics. Nothing invented, nobody interviewed.
Twenty thousand futures
We fit each cohort's recent trend, then run it forward thousands of times carrying the uncertainty that fit implies. The spread of those runs is your confidence band.
Every number is arithmetic
Rates, bands, probabilities and cost of inaction are all computed. None of them is written by a language model.
Where AI is, and where it isn't
In one place, and only when you ask for it. Press Ask why on a segment and a language model reads the numbers already computed and writes what an analyst would write: likely drivers, what's uncertain, and what would prove the projection wrong. It cannot produce a figure and it cannot change one. Every number on your screen is identical whether you press it or not.
From intro call to first forecast in 3–5 working days
A Shadow forward-deployed engineer does the work. Your side of it is roughly four hours of people-time, spread across the week — no code changes, no SDK, no data migration.
Scoping call
Day 0 · 45 minYou: One product leader and one data or analytics person. You name the metric that worries you and the cohorts you care about.
Shadow: We check whether your events can actually support that metric, and tell you honestly if they can't yet.
Read-only access
Day 1 · 60 minYou: Issue an Amplitude Export API key (or a read-only warehouse role). Your infra or data team, one ticket.
Shadow: We deploy the ShadowConnector — a Docker container that runs inside your infrastructure, pulls read-only, and never writes back. No PII leaves your boundary.
Ingest and event mapping
Days 1–2 · asyncYou: Answer questions over Slack as they come up. Usually 30 minutes total.
Shadow: We pull 90 days of history, infer your metric definitions, and map raw events to the behaviour they represent. This is the step that needs a human — event taxonomies are always messier than the docs say.
Segment discovery and gating
Days 2–3 · asyncYou: Nothing.
Shadow: We enumerate candidate cohorts, run data-sufficiency checks on each, and discard the ones too thin to forecast honestly. You will see exactly which segments were excluded and why.
Backtest and calibration
Days 3–4 · asyncYou: Nothing.
Shadow: We re-run the model at past cutoffs against what actually happened on your data, and publish the coverage. If the bands are not calibrated on your product, you find out before you trust a single forecast.
Readout
Day 5 · 60 minYou: Bring whoever owns the roadmap.
Shadow: We walk your ranked risk segments, the cost of inaction, and the calibration evidence. You leave with a shortlist of cohorts to act on — or a clear statement that nothing is currently at risk, which is also a valid answer.
What can slow this down. Fewer than 28 days of clean history, cohorts too small to forecast honestly, or the same user action firing under three different event names. We will tell you on the scoping call if we think you're in that position — a forecast built on thin data is worse than no forecast, so we won't ship one.
Read-only. Encrypted. Isolated.
Shadow is a read-only simulation layer that fits into the same trust boundary as Amplitude, Mixpanel, or your observability pipeline — with stricter isolation. It never takes action on users or production systems.
Shadow never takes action on users or production systems
No writes to production. No outbound user communication. No side effects (emails, billing, webhooks). No autonomous decisions.
Data Minimization
No raw PII ingested by default. User identities are represented by anonymized or hashed identifiers. Only the minimum behavioral state required to simulate is used.
- Aggregated behavioral signals only
- Sensitive fields excluded, tokenized, or hashed at source
- Permission-scoped state access
Encryption & Isolation
Every layer of the stack is encrypted and sandboxed. Simulation environments are logically and cryptographically isolated from your production systems.
- TLS 1.2+ in transit, AES-256 at rest
- Dedicated sandboxed simulation environments
- No shared execution context with production
Production Separation
Shadow traffic is explicitly tagged and separated. Simulations run outside your runtime with no access to write paths, user-facing channels, or billing systems.
- Read-only connector, never writes back
- Tagged and separated from production traffic
- Security team approved in a single review
Priced like infrastructure, not seats
Usage-based on the users and segments you monitor — not per head. Read-only and no-PII, inside the same trust boundary as your analytics.
You already spend six figures a year on analytics and observability — Amplitude, Datadog, Pendo. Shadow is the forward-looking layer on top, at a fraction of that.
Starter
Single team, one data source.
$1,000/mo
Up to 250k monitored MAU
- Segment forecasts + confidence bands
- Backtesting & calibration
- Amplitude or Demo connector
- On-demand AI interpretation
- Email support
Every plan includes the read-only connector, calibrated confidence + backtesting, and the INSUFFICIENT SIGNAL guardrail. Indicative pricing — design-partner terms for the first cohort.