The promise sounds almost quaint now: autonomous software agents that book your flights, reconcile expenses, maybe even fill out visa applications while you sleep. The reality? They're running headfirst into CAPTCHA walls, timing out mid-workflow, and collapsing the moment a website tweaks its CSS.
That gap between aspiration and execution has opened a lane for Rindler, a two-person operation out of Boston that emerged from Y Combinator with what might charitably be called perfect timing. The company's pitch is deceptively simple—turn chaotic websites into clean, predictable tools that AI agents can actually use—but the execution involves navigating a minefield of authentication protocols, bot detection systems, and the fundamental fact that most of the web actively resists automation.
Michael Serrano and Arthur De Los Santos, who met at MIT and founded Rindler in 2025, have built what they call a hosted Model Context Protocol server. Strip away the jargon and it's infrastructure that sits between AI agents and the messy reality of the modern web. Instead of sending agents to fumble through raw HTML and JavaScript challenges, Rindler maps entire sites into structured, typed interfaces—returning neat JSON objects where others return DOM trees.
When Bots Meet Walls
The obstacles are considerable. Recent industry analysis suggests that more than three-quarters of agent failures trace back to bot detection systems, with major platforms like Cloudflare and Akamai blocking substantial percentages of agent traffic under certain conditions. Even when agents break through, they burn through computational resources parsing HTML, retracing their steps with each visit, and breaking silently when sites run A/B tests or push interface updates.
Rindler's answer involves mapping each website once—cataloging screens, actions, possible outputs—then exposing those mappings as reliable tools. The company claims this yields threefold reductions in task failures, fourfold speed improvements, and sixfold cost savings versus traditional browser automation. Those numbers come from internal testing, though, without published methodology or independent verification. Take them as directional rather than gospel.
The technical architecture centers on a fixed set of primitives: start_session, dispatch_action, extract_content, extract_document, close_session. Each supported site gets squeezed into this consistent interface. Responses come back structured, not as tangled HTML. When a site lacks clean schema, the system falls back to an ARIA tree representation—still structured, if less elegant.
Authentication Without Exposure

Perhaps the trickier problem is authentication. Agents need to log into services, but handing over credentials to autonomous software introduces obvious risk. Rindler routes users through a hosted browser flow where they complete password entry, multi-factor steps, or CAPTCHA challenges directly. The agent never touches credentials. Sessions get encrypted with AES-256-GCM and reused until they expire.
Error handling aims for machine-readable specificity: rate_limited_burst, session_expired, auth_required. The idea is that agents can branch on precise signals rather than attempting to parse vague error messages—a reasonable approach, assuming sites cooperate by failing predictably.
Sites can be mapped on request, with automated verification systems and what Serrano and De Los Santos describe as "self-healing configs" meant to survive layout changes. Their demo environment currently lists nineteen sites—LinkedIn Jobs, Airbnb, Instacart, Amazon, Chase, Bank of America, United Airlines, Zillow among them. Worth noting: this is a demonstration catalog, not evidence of formal partnerships.
The Founders and the Framing
Serrano holds degrees from MIT in physics and computer science and spent time working on large language model research at CSAIL before building machine learning infrastructure at Roblox. De Los Santos graduated from MIT with a focus on computer science, AI, and machine learning. Both are early in their careers; Rindler is their first venture.
They joined YC under partner Ankit Gupta and announced the company publicly around mid-July, describing use cases that span procurement portals like SAP Ariba and Coupa, government registries, healthcare clearinghouses, applicant tracking systems, and banking interfaces. Some of these verticals are in production. Others are available on request, contingent on appropriate compliance frameworks—HIPAA, business associate agreements, the usual bureaucratic machinery of regulated industries.
Pricing follows a familiar SaaS model: free tier with full catalog access, a Teams plan at $1,000 monthly for expanded credits and dedicated site mappings, custom Enterprise deals beyond that. There's a limited-time promotional code (YCLAUNCH) offering 25 percent off for three months. The company's terms of service, updated in mid-July, emphasize that users bear responsibility for complying with underlying site terms—Rindler provides infrastructure "as-is," with no warranty that automation will keep working indefinitely.
That disclaimer isn't merely legal boilerplate. It reflects genuine uncertainty.
An Arms Race Without Resolution

Rindler enters a market where the ground keeps shifting. Browserbase launched managed browser agents recently, emphasizing verified identity and hardened anti-bot measures. Apify's MCP server connects agents to thousands of prebuilt scraping actors. AWS released a generally available MCP server earlier this year, a signal that the protocol has achieved something resembling mainstream legitimacy.
Meanwhile, defensive technologies are evolving in parallel. Cloudflare and Google have updated documentation around bot authentication, promoting cryptographic request signing to verify agent identity. Academic research has detailed methods for distinguishing automated agents from human users with high accuracy. The tension between agent builders and site operators hasn't resolved—if anything, it's accelerating.
Whether Rindler's deterministic mapping layer proves durable depends partly on how broad they can make their site coverage and partly on whether emerging bot detection standards allow for legitimate agent use cases. Some fraction of sites may eventually embrace sanctioned automation; others will treat all agents as adversaries.
For now, though, Rindler's pitch centers on something practical: a structured response to the fact that the web was never designed for autonomous software, and coaxing it into cooperation requires infrastructure that most startups can't justify building themselves. The question isn't whether the problem is real. It's whether this particular solution can stay ahead of the countermeasures.
