How Founderr works

From your URL to a working team

Scan first, add your company context, then choose what every agent is allowed to carry out.

The operating loop

Work moves. You stay in control.

Step 1

Connect your company context

Add your product, records, and the integrations you choose. Every workspace stays scoped to its organization.

Step 2

Start with the brief

Casey turns your recorded work, risks, and open decisions into a morning brief delivered through Telegram.

Step 3

Review consequential actions

Outbound work and changes enter one approval queue, with the proposing agent, the draft, and its recipient attached; the outcome is written to the work log.

Step 4

Execute after approval

Approved outreach, follow-ups, customer replies, and code fixes can run. The result returns to the work log.

Tools that are live

Use the surface that fits the job.

Run a public URL report before signing up. Afterward, use the dashboard or nine MCP tools through a revocable workspace key.

One of the nine lists the actions your agents have queued and not taken. Approving stays in the dashboard — the tool is read-only on purpose.

  • Security Scanner
  • Uptime Monitor
  • SEO Analyzer
  • Landing Page Vitals
  • Tech Stack Analyzer
  • RedditPilot
  • LaunchPad
  • CommunityBlitz
  • AI Employee Cost Calculator
01Coverage proof

See what the report checked

Each report separates verified readings from signals the scan could not reach. Point Founderr at a URL you already own and the sensors start reading: domain expiry, TLS, page performance, uptime, security headers and DNS records. No OAuth screen, no API key, nothing to paste.

Every check that could not run is reported beside the ones that did, with the reason it failed. A report cannot read “clear” while anything went unmeasured. It reads “incomplete” instead, and names what it missed.

RENEWAL RISK · example reportincomplete
  • Domain expiry214 days

    Registrar transfer lock is on. Flagged at 45 days, urgent inside 14.

  • TLS certificate67 days

    Flagged at 21 days, urgent inside 7 — browsers give no grace at all.

  • Uptime99.94%

    2,014 checks over 7 days, one every five minutes.

  • Page performancenot checked

    Why: Lighthouse could not load the page at all

coverage: 3 of 4 measuredThree readings came back healthy. The verdict is still not “clear”.

Anyone can show you a green dashboard. This is the same report on a site where everything measurable is fine — and it still will not call itself clear, because one signal went unread.

Other sentences our reports actually return
  • no_expiry_publishedthe registry withholds the expiry date for this TLD
  • no_checks_recordedno uptime checks have been recorded for this site yet
  • dns_inconclusivethe DNS scan confirmed nothing: some of its lookups failed and the rest reported no finding, and a correctly configured domain and one we could not read look identical from here.
  • no_field_dataCrUX has no real-user sample for this site, so the field numbers are absent — not zero, and not fast.
Where the boundary sits today

Approved outreach, customer replies, and fix pull requests execute today. Payments and infrastructure changes remain founder-executed.

Agents run Gemini 3.7 Flash on Vertex. Production scans exclude IAST and out-of-band checks; WhatsApp delivery remains template-gated.

02Connections and evidence

How Founderr connects

Read the mechanism and evidence behind each live connection.

  • GitHub

    GitHub App, read-only

    Choose repositories; Sam reads commits, pull requests, and CI while Morgan reads issues.

    You choose which repositories the App can see. Sam reads commits, open pull requests and CI checks. Morgan reads your open issues, so product demand comes from people who filed something. There is no token for you to paste: we mint a short-lived installation token and cache it until it expires.

    One click, on GitHub's own screenRead-only App; one click; short-lived installation token
  • Claude, Cursor and any MCP client

    MCP server over streamable HTTP

    Run scans, read findings, check uptime, pull briefs, and ask any agent.

    Start a security scan, read its findings, check your uptime, pull the morning brief, or put a question to any agent on your team. It is the same workspace you log into, scoped by an API key you can revoke.

    One command in your editorStreamable HTTP; revocable workspace API key
  • Domain registries

    RDAP, the IETF successor to WHOIS

    Reads registration expiry and flags it 45 days out, urgent inside 14.

    Reads your domain's registration expiry straight from the registry that holds it. We raise it 45 days out and call it urgent inside 14, because a lapsed domain takes the site, the email and the password resets at the same instant.

    Nothing to connectRDAP; zero setup
  • TLS certificates

    Read from the handshake itself

    Reads the public certificate; flags expiry at 21 days, urgent inside seven.

    Opens a TLS connection to your site and reads the certificate you serve. Nothing is authorised and nothing is stored — the certificate is public to anyone who connects. Expiry is flagged at 21 days and urgent inside 7, where browsers give no grace at all.

    Nothing to connectLive handshake; zero setup; zero storage
  • Google PageSpeed Insights

    PageSpeed Insights API, with CrUX field data

    Shows Core Web Vitals from CrUX, marking insufficient field data as absent.

    Core Web Vitals for your public URL. Real-user numbers from the CrUX dataset when your traffic is enough to produce them, and reported as absent — not as a good score — when it is not.

    Nothing to connectPublic URL; zero setup
  • Uptime monitoring

    Founderr's own checks, every five minutes

    Records status and latency every five minutes; waits for enough samples before scoring.

    We fetch your public URL from our own infrastructure and record the status code and the latency. If we have not checked yet it says so, rather than reporting a comfortable 100%. A percentage is withheld until there are enough samples to mean anything.

    Built inFounderr infrastructure; zero setup
  • Resend

    Outbound transactional email

    Sends verification, password resets, and security reports through Founderr's account.

    Verification, password resets and your security reports leave through Resend. It is listed because it handles your address, not because it is something you connect: the integrations API offers no provider at all.

    Built in — our account, not yoursBuilt in; no customer connection

five of these seven ask nothing of you — no key, no OAuth screen, no account — and each card says exactly what it needs. The list is short because it is complete: every line on every card is pinned in our test suite to the file that implements it, so changing one without the other fails the build.

Common questions

The short answers

What do the agents actually do?

They brief, draft, scan, prioritize, and queue consequential actions. Casey coordinates the roster; each specialist works from records and tools scoped to your organization.

What happens after I approve something?

Outreach, follow-ups, customer replies, and code fixes can execute. Payments and infrastructure changes remain yours to carry out after approval.

Is the security scanner included?

Yes. The Security Scanner runs on every plan and produces prioritized findings. Scans consume the credits included with your plan.

Can I use Founderr from my editor?

Yes. A revocable workspace API key exposes nine MCP tools for scans, findings, uptime, briefs, renewal risk, approvals, GitHub issues, and agent questions.

How are briefs delivered?

Telegram delivery is live. WhatsApp support exists, but scheduled delivery depends on an approved message template.

Can an agent act without my approval?

Consequential actions wait in the approval queue. Every decision and resulting action is written to the work log.

Put the work around your product in motion.

Start free