Methodology
How verification works
Every number on Foundr carries a label saying where it came from. This page shows the whole pipeline — including what we deliberately don't do.
Data vendors estimate private-company numbers from the outside. We read them at the source.
Traditional private-market datasets are assembled by large research and data-operations teams. Foundr's verified metrics come from direct, founder-authorised API connections instead.
1 · Founders connect their sources
A founder authorises Stripe and (optionally) GitHub via OAuth. The scopes are the providers' standard grants — broader than we use — so the honest claim is about our behaviour, not the scope: our code only ever reads. We never create, modify, or move anything on a connected account, and we never touch money.
2 · We pull raw numbers, on a fixed cadence
Every 6 hours, a scheduled job re-syncs each connected source. From Stripe: MRR, gross retention (30d), ARPU, active subscriptions, active customers, churned (30d), and revenue (30d). From GitHub: commits (90d), contributors, and stars. Nothing in the verified set is typed in by hand.
3 · Tokens and data are locked down
Access tokens are encrypted at rest with AES-256-GCM, are used only on our servers, and are only ever sent back to the provider that issued them — your browser never sees them. Your browser also cannot read startup or financial data from our database directly: client SELECT privileges on every data table are revoked, so those reads flow through our server, where access rules apply. We keep personal data out of application logs.
4 · Every figure is labelled — and summaries are audited
Each number renders with one of three provenance labels: Verified · Stripe, Verified · GitHub, or Self-reported. Self-reported figures are always attributed to the founder and never presented as verified. The weekly AI brief is descriptive only, and every brief stores the exact prompt version that produced it — an audit trail for how it was written.
The spec sheet
6h
sync cadence, scheduled
AES-256-GCM
token encryption at rest
3
provenance labels, on every figure
0
composite scores — ever
Common questions
- How can a startup prove its MRR is real instead of a screenshot?
- Connect the billing account directly so the numbers are read by API rather than typed or pasted. On Foundr, a founder connects Stripe via OAuth; Foundr derives seven revenue and retention figures (MRR, revenue over 30 days, gross retention, ARPU, active subscriptions, active customers, and cancellations over 30 days) and re-syncs every 6 hours. The OAuth scope Stripe grants is broader than Foundr uses — the guarantee is behavioural: Foundr's code only ever reads and never calls a write endpoint. Each figure is displayed with a source label (Verified · Stripe) and the time it was last pulled, so a viewer can tell verified data from a founder's own claim.
- What does 'verified metrics' mean on Foundr?
- It refers to the data's origin, not to any judgement about the company. A verified figure is one Foundr retrieved from a connected API source at the timestamp shown. Foundr does not verify, endorse, or recommend any startup, and it publishes no scores, rankings, or merit-ordered lists.
- Is Foundr free for founders?
- Yes. Founders connect a source, see a private benchmark of their own metrics against other connected startups, and list their company at no cost. Foundr's only planned revenue is investor subscriptions; where it charges, it charges for access to platform features. It takes no commission, success fee, or any compensation tied to a transaction between users.
- How do investors get access to Foundr?
- Access is invite-only and gated. An investor applies through the waitlist, attests to accredited status, and declares their country of residence; investors in markets where Foundr has not completed its legal review are held out. Anyone who does not attest to accredited status cannot access the investor product at all.
- What does Foundr deliberately not do?
- It publishes no composite scores, no rankings, and no merit-ordered lists; it makes no investment recommendations; it sells no placement or featured position (listing order is time-based); it never holds funds, executes transactions, or charges success fees; and individual company financials are never public — they sit behind an invite-gated, accredited-attested login. Nothing on Foundr is investment advice, and Foundr is not a broker-dealer, investment adviser, or securities exchange.
- Where do the numbers on a startup's Foundr profile come from?
- From three labelled sources. Verified · Stripe covers revenue and retention pulled from the founder's connected Stripe account. Verified · GitHub covers engineering activity such as commits over 90 days. Self-reported covers anything the founder typed in, including team background, and is always labelled as such and never presented as verified.
What we deliberately don't do
Most of these are legal commitments, not just preferences. They're written into our terms.
- No scores, rankings, or merit-ordered lists — we publish data points with provenance, never a verdict.
- No recommendations. Nothing on Foundr says a company is a good or bad investment.
- No pay-for-placement. Listing order is time-based; nobody can buy position.
- No open access to verified financials — investors attest to accredited status, and access is geo-controlled while our market-by-market legal review completes.
- No money movement. We never hold funds, execute transactions, or charge success fees.