Give every portfolio company its own instance, not a shared one
An accelerator cannot impose an employee-monitoring tool on companies it does not employ, and should not want to: a programme that can see inside its cohort's operations has created a governance problem for itself and a trust problem with its founders. The useful thing a programme can offer is the opposite — a tool each company runs for itself, on its own data, that solves the problem founders actually have when the first non-founder engineers arrive and nobody can say where the money went.
What goes wrong today
If none of these are familiar, this probably is not your problem.
- Portfolio companies hitting the same blind spot at the same stage, and each solving it badly and separately.
- Founders reconstructing engineering time the week before an R&D claim or a board meeting.
- A cohort spanning several jurisdictions, where what is lawful in one is a works council negotiation in another.
- Perk-programme tools that require a shared account, which makes the programme a data controller for companies it does not employ.
- Venture studios employing shared staff across several ventures, with no defensible way to split that cost between them.
What changes
With privacy-by-default metadata tracking.
- Each company gets its own organisation with its own database, so one portfolio company's activity is structurally incapable of appearing in another's reports — or in the programme's.
- Founders get contemporaneous project-level records from the first engineer, rather than starting the reconstruction habit that is expensive to break later.
- Jurisdiction guidance for the countries a cohort is actually spread across, including where consultation is required before rollout.
- For studios: shared staff time attributed per venture as it happens, which is the number an eventual spin-out will be asked to justify.
- Nothing is reported to the programme by default, because there is no mechanism by which it could be.
What the design guarantees
- per-org-database
- Each organisation's captured activity lives in its own database, so isolation is structural rather than a filter someone has to remember to apply.
- transparent-agent
- By default the person being monitored can see what is being captured on their own machine and can pause capture. The one exception is a covert investigation, which is Enterprise-only, unavailable in the EU, capped at 90 days, and audited.
- audited-config
- Every change to what an organisation captures is written to an audit log with who changed it and when.
- rtbf
- An erasure deletes the person's captured activity and the raw archive it came from, and anonymises the account itself — name, address, devices and memberships go with it; approved timesheets are kept as payroll evidence unless the organisation turns that off.
Questions from teams like yours
Can the programme see across its portfolio companies?
No, and not as a permission setting — each organisation's data lives in its own database, so there is no cross-organisation query to grant access to. If a portfolio company wants to share a figure with the programme, it exports it and sends it. That is a deliberate limit: a programme that could read its cohort's activity would be acquiring an obligation it does not want.
Our cohort spans the EU, the UK and the US. Is one rollout playbook enough?
No, and that is the main thing to plan for. Several EU jurisdictions require works council or employee representative involvement before monitoring starts, and rollouts have been blocked for skipping it rather than for what they captured. There are per-country guides covering the instrument, the consultation requirement and the order of steps.
What does this cost a pre-revenue company?
Pricing is per user per month with no seat minimum, so a four-person company pays for four people. Details are on the pricing page; perk-programme terms are a conversation rather than a published rate.
Will founders resent being told to install monitoring software?
They would, which is why the recommendation should be framed as a tool they run rather than a condition of the programme. It helps that the product is built for a team that would refuse the alternatives: keystroke content is never captured, screen capture is off by default and behind a compliance review, and the person being monitored can see what is being collected on their own machine and pause it.
A company leaves the programme. What happens to its data?
Nothing changes, because the programme never had access to it. The company keeps its own organisation, its own database and its own billing relationship.
See where the hours actually went
Free for up to three people. Windows and macOS. No keystroke content on any plan, and screenshots off unless an administrator turns them on.