Runlayer

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2025
Funding $42M
Last updated 2026-07-09

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Runlayer sells enterprises a platform that lets employees build AI agents while the security team keeps control of identity, policy, threat screening, and audit. Press names Instacart, Opendoor, and dbt Labs among dozens of customers. That roster, assembled barely a year in, is what stands out. Gusto's security chief and Jane's AI transformation lead praise the product publicly. The co-creator of the protocol that lets AI agents reach tools advises the company alongside Cursor's head of security. Revenue stays undisclosed behind a fast 30 million dollar Series A. Larger players are buying into the space, with Snowflake agreeing to buy the rival gateway Natoma and Check Point the AI-security vendor Lakera. Those logos and that insider standing are a head start, not yet a durable lead.

Sourced Details

Description Runlayer: an AI enablement and control platform that lets enterprise employees build and use AI agents while security teams govern them, routing agent access to MCP tools through one control plane with identity, policy, threat screening, shadow-AI discovery, and audit logs. [f1]
Founded 2025 [f2]
Funding $42M total [f1]
Latest funding Series A of 30 million dollars (June 2026), led by Felicis with Khosla Ventures [f3]
Deployment SaaS, Self-hosted [f4]

Products

Product What it does
Runlayer Runlayer: an AI enablement and control platform that lets employees build and use AI agents while security teams govern access to MCP tools through identity, policy, threat screening, and audit logs.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Runlayer is an AI enablement and control platform whose governed MCP gateway routes agent access to tools through enterprise identity, policy, threat screening, shadow-AI discovery, and audit logs. It is mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Runlayer names the enterprise IT and security team that must let employees use AI agents without losing control of what those agents reach, but the framing is now broad and vendor-shaped, bundling enablement, security, and control (s7, s8). Independent corroboration speaks to the general adoption-versus-control gap rather than quantifying Runlayer's exact problem: the Rising in Cyber CISO survey (more than 70 percent running agents, 11 percent calling AI security comprehensive) and Gartner's MCP risk warning (s11, s12). Present but unproven. [s8, s11, s12]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Public docs are detailed, covering hosted and self-hosted AWS deployment, threat screening and session-level behavior monitoring, shadow-AI discovery deployed to managed devices through device management, and integrations across major SaaS tools (s5, s17). The external signals are ecosystem endorsements and named-customer testimonials rather than an independent efficacy benchmark, OSS, or third-party technical evaluation (s3, s10), and no detection benchmark is public. Concrete on the vendor's own pages but not independently validated, level with the MCP-gateway peers. [s5, s17, s3, s10]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Anthropic released MCP in 2024 without built-in security and enterprise adoption outran it, the enabler that makes an agent access-control platform newly needed. Buyer-side demand is corroborated: the Rising in Cyber CISO survey reports more than 70 percent running agents and 11 percent calling their AI security comprehensive, and Gartner warns MCP adoption elevates risk (s11, s12). Visible budget movement shows in a wave of acquisitions in this slot (s14). It holds at 4 without a named analyst category for MCP gateways. [s11, s12, s14]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 The founders built canonical MCP tooling before Runlayer: CEO Andy Berman co-founded Nanit and Vowel (acquired by Zapier) and was Director of AI at Zapier, Tal Peretz built Zapier's MCP integration, and Vitor Balocco is a Zapier AI engineer who speaks on MCP security (s3, s10). The advisor bench is unusually strong for the stage, but advisors are relationships, not the team's own record, and the verifiable exit was in productivity software rather than a dedicated security vendor. It holds at 3 with the MCP-gateway peers, below the prior-security-founder bar that lifts a same-cluster peer to 4. [s3, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Runlayer launched naming enterprise customers and now shows public executive endorsements: Gusto's CISO and CIO and Jane's Chief AI Transformation Officer are quoted by name, and press names Instacart, Opendoor, Decagon, and dbt Labs among dozens of customers within months of stealth (s4, s7, s10). A $30 million Series A led by Felicis and Khosla and a Cursor Hooks partnership extend the motion. Multiple named references across non-vendor sources put it above thinner-traction signals, though undisclosed revenue keeps it below a corroborated-scale top mark. [s4, s7, s10]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Prior 3 to 2. The $30 million Series A landed roughly eight months after the seed round and about a year after founding, lifting the total to $42 million with no disclosed revenue, margin, or retention (s7, s8). Under the recalibrated scale, a sizeable round whose commercial proof is named logos rather than disclosed revenue scores low even while the company ships and signs customers, because the raise is fast and revenue-silent. [s7, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Runlayer has repositioned from an MCP security gateway to a broader AI enablement and control platform, which SecurityWeek labels an AI enablement and control platform and the company calls the golden path for AI (s7, s8). Agent access control and MCP governance are recognizable in parts, but the bundled enablement-plus-security-plus-control framing is vendor-coined and still needs explanation, and the MCP security category itself only formed after the 2024 protocol release. Fits a nascent, contested category that needs vendor coaching. [s7, s8, s9]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Gating which tools an agent may reach is the most common MCP security product, and TechCrunch names Cloudflare, Docker, and Wiz already shipping it (s9). Consolidation is visible: Snowflake signed to acquire the rival MCP gateway Natoma, a platform owner taking the exact slot, while Check Point bought the broader AI-security vendor Lakera (s14, s15). Runlayer's broadening into an enablement platform plus named enterprise deployments raise switching and replication cost, but no structural moat a platform owner could not eventually bundle appears, matching the cluster. [s9, s14, s15]
Business Risks A platform owner holding the customer's data or identity, such as Microsoft, Google, AWS, or Snowflake, could ship native agent tool-gating inside tools enterprises already license, removing the third-party budget line Runlayer's platform depends on…
  • A platform owner holding the customer's data or identity, such as Microsoft, Google, AWS, or Snowflake, could ship native agent tool-gating inside tools enterprises already license, removing the third-party budget line Runlayer's platform depends on.
  • Cloudflare, Docker, and Wiz already sell MCP security, so the gateway function could commoditize on features and push Runlayer to compete on price or on advisor and partner relationships rather than on product.
  • Runlayer's relevance rests on MCP remaining the dominant agent-to-tool standard, so a shift toward vendor-native tool calling or a rival protocol would erode both the problem and the insider advantage.
  • The named customers are press-reported logos and vendor-hosted testimonials with no disclosed contract size or retention, so a buyer relying on durable revenue proof has adoption signals rather than evidence the accounts have expanded.
  • A larger security or platform vendor could acquire Runlayer for its team and relationships before it builds a standalone franchise, the path implied by Check Point's Lakera deal and Snowflake's pending agreement to buy Natoma.
  • The $30 million Series A raised with no disclosed revenue raises the bar for commercial proof, so a slow conversion of logos into paying, expanding accounts would leave the raise ahead of results.
Problem & Market Runlayer sells to the enterprise IT and security team caught between two pressures: employees want to build and use AI agents everywhere, and the team is accountable for what those agents reach…

Runlayer sells to the enterprise IT and security team caught between two pressures: employees want to build and use AI agents everywhere, and the team is accountable for what those agents reach. The company frames the answer as a golden path, one platform that enables agent use while keeping identity, policy, threat screening, and audit in the security team's hands.

Independent reporting grounds the pain rather than leaving it as vendor framing. The Rising in Cyber 2026 survey of CISOs reports more than 70 percent running AI agents in production while only 11 percent rate their AI security as comprehensive. Gartner warns that building agentic AI on MCP raises new attack vectors, and TechCrunch points to real MCP failures in GitHub's and Asana's servers.

The Model Context Protocol is why the problem exists at this scale. Anthropic released MCP in 2024 and enterprises adopted it quickly to let agents act inside real systems, but the protocol shipped without much built-in security, so identity, access control, threat screening, and audit became the buyer's problem to solve. [s2, s11, s12, s9]

Product Capabilities Runlayer has widened from a security gateway into a platform with three jobs: enable, secure, and control…

Runlayer has widened from a security gateway into a platform with three jobs: enable, secure, and control. On enablement, it lets teams start from more than 18,000 available MCP servers, approve and publish a vetted set, and serve them through a governed gateway to the AI clients employees use. On security and control, it ties access to enterprise identity, applies policy, screens tool calls, monitors agent sessions, and keeps audit logs.

The platform screens agent tool calls for MCP-specific attacks. SecurityWeek reports it aims to identify and block prompt injections, tool poisoning, data exfiltration, output manipulation, intent drift, shadow MCPs, and unmanaged agents, and the docs add session-level behavior monitoring that flags manipulation across an agent's run. A separate shadow-AI capability deploys configuration and controls to managed devices through mobile-device-management tools to surface and block unsanctioned MCP servers and skills. Independent research grounds why the screening matters: the MCPTox benchmark characterizes tool poisoning, malicious instructions hidden in a tool's metadata, as a fundamental MCP attack surface.

External validation is strong for a company this young, though it is endorsement rather than measured efficacy. The co-creator of MCP and Cursor's head of security advise the company, and public docs back the marketing pages with deployment guides for hosted and self-hosted AWS, Kubernetes, and Terraform. No independent efficacy benchmark of the screening is public. [s5, s17, s8, s13, s3]

Competitive Positioning Runlayer competes in the most crowded corner of AI security…

Runlayer competes in the most crowded corner of AI security. TechCrunch calls the gateway the most common type of MCP security product and names Cloudflare, Docker, and Wiz already shipping in the space, so the core gating function is close to table stakes rather than a differentiator.

Runlayer's visible edge is trust, reach, and breadth rather than a unique mechanism. The co-creator of MCP advising, Cursor's head of security endorsing, and named enterprise customers give it standing rivals cannot easily copy, and the move into enablement aims to make Runlayer the place employees build agents, not just the checkpoint they pass through.

The structural question is who ends up owning this layer. A platform that already holds the enterprise's data, identity, or developer tools is the natural owner of agent tool access too, and larger vendors are buying in rather than only building. Snowflake signed a definitive agreement to acquire Natoma, an MCP gateway, and Check Point agreed to acquire Lakera, an agentic-AI security platform. Runlayer is betting it can build an independent business in this layer before a platform owner bundles it away. [s9, s1, s14, s15]

Go-to-Market & Traction Runlayer launched naming recognizable enterprise customers and now shows named executives vouching for it…

Runlayer launched naming recognizable enterprise customers and now shows named executives vouching for it. The engineering pages carry endorsements from Gusto's CISO and CIO and Jane's Chief AI Transformation Officer, who calls Runlayer the backbone of Jane's AI strategy. The Series A blog names Instacart, Gusto, Decagon, Opendoor, dbt Labs, AngelList, and Lemonade plus a number of Fortune 500s, and The AI Insider reports dozens of customers within months of stealth while TechCrunch reports eight unicorns or public companies among them.

Partnerships extend the motion beyond a customer list. Runlayer's own blog says it is an official Cursor Hooks launch partner able to allow or deny MCP tool calls inside Cursor, a channel that puts the product in front of developers where they already work. That is a distribution path a feature-copying rival cannot reproduce by writing software alone.

The funding has stepped up behind that motion. An initial seed led by Keith Rabois of Khosla Ventures and Felicis preceded the named-logo launch, and a $30 million Series A led by Felicis in June 2026 brought the total raised to $42 million. What the public record still lacks is contract size, retention, or revenue, so the logos and the follow-on round are adoption evidence rather than proof the accounts have expanded. [s4, s7, s10, s9, s16, s8]

Team & Credibility Runlayer's founders built AI products and MCP tooling before starting the company…

Runlayer's founders built AI products and MCP tooling before starting the company. The about page says the founding team raised over $200 million cumulatively across prior companies and created Zapier MCP and Agents. CEO Andy Berman co-founded Nanit and Vowel, which Zapier acquired, and was Director of AI at Zapier. TechCrunch frames him as a three-time founder building a tool to keep business users' AI agents operating securely.

The co-founders bring complementary depth. Tal Peretz led machine learning in the Israeli Air Force and built Zapier's MCP integration, and Vitor Balocco was a staff AI engineer at Zapier who speaks publicly on MCP security. The advisor bench is unusually strong for the stage, including the MCP co-creator, Cursor's head of security, the CEO of Neon, and the chief product officer of SentinelOne.

The credibility gap is that the verifiable prior exit was a productivity product rather than a security company. Berman's track record is real and traceable through a named acquisition, but it sits in workflow software, so the team reads as strong AI builders newly entering security rather than repeat security founders with an established buyer relationship. The advisor relationships help a buyer choose but are not an asset the company owns. [s3, s10, s9]

Trust Readiness Runlayer backs its assurance claims with an inspectable trust portal rather than footer badges alone…

Runlayer backs its assurance claims with an inspectable trust portal rather than footer badges alone. The Trust Center at trust.runlayer.com, rendered this analysis, lists SOC 2 Type 2, HIPAA, and GDPR in its compliance section and offers a SOC 2 Type II report, a penetration test, and security policies under an access request rather than open download. It also names its subprocessors, including AWS and WorkOS for authentication and directory sync.

The product's own controls are the rest of the trust case. Runlayer ties access to enterprise identity through single sign-on and SCIM directory sync, applies policy to agent connections, screens tool calls, and keeps request and response logs for compliance and incident response. A self-hosted deployment in the customer's own AWS account answers the concern of regulated buyers who will not route agent traffic through a vendor.

The gap a reviewer would still note is breadth and openness of assurance. No ISO 27001 certification appears, the SOC 2 and penetration-test reports sit behind an access request, and no third-party efficacy benchmark of the screening is public. For a company founded in 2025 the attestations also carry a short track record, so a security reviewer pairs the published controls with the gated artifacts and a sales conversation. [s6, s2, s5, s1]

Competitors Natoma, Lakera, MintMCP, Lunar.dev, Cloudflare, Wiz…
Company Relationship Note Compare
Natoma competes with Governed MCP gateway treating agents as non-human identities, the same tool-gating and authorization slot, which Snowflake signed a definitive agreement to acquire.
Lakera competes with Runtime AI security and guardrails for LLM and agent applications, an adjacent AI-security position, which Check Point agreed to acquire.
MintMCP competes with Direct MCP-gateway peer governing agent access to tools, the same tool-gating slot without Runlayer's named-customer roster.
Lunar.dev competes with MCP gateway and control plane for agent-to-tool access, a direct pure-play peer in the same category. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Cloudflare competes with Named by TechCrunch among the big vendors already shipping MCP security, a platform with the reach to bundle a gateway as a feature.
Wiz competes with Named by TechCrunch among established vendors shipping MCP security, able to attach agent tool security to an existing cloud-security platform.

Add analyzed competitors to compare them side by side with Runlayer.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Runlayer is hard to build and easy to substitute. Screening every agent tool call for attacks on MCP, the tool standard agents use, takes real security engineering, and named enterprises run it with public executive endorsements. But the pieces a rival would copy are reproducible: an approved-tool catalog built on public MCP data, threat screening with no disclosed private threat data, and SOC 2, HIPAA, and GDPR credentials that clear procurement but do not block a switch. No regulation makes it required, and its standing with MCP insiders is reputation, not an owned asset. It is most defensible where a customer has made Runlayer its home for agent work, weakest as a standalone control a platform owner holding the customer's data or identity can replace inside a contract already signed.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Runlayer is configurable software the public docs offer hosted or self-hosted, with self-hosted deployments running in the customer's own AWS account and the customer configuring access and policy (s5, s2). The public materials describe tooling and deployment options, not a managed detection service or human accountability layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Runlayer sits inline in the agent-to-tool path with single sign-on and SCIM, policy, an approved-tool catalog, and audit logs, and customers can build agent workflows on it, so leaving would likely mean rebuilding that configuration and re-integrating (s4, s5). That is real revert cost, and an executive describes it as the backbone of their AI strategy, but it still sits over the customer's own identity and cloud with no data residency lock or cross-customer network effect.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Runlayer publishes an inspectable Trust Center with SOC 2 Type 2, HIPAA, and GDPR, but these are commercial, table-stakes attestations that ease procurement without blocking a substitute, and no federal authorization or regulatory mandate making the class required appears in the reviewed sources, so 1.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Building the control plane is hard engineering: screening tool calls in real time for MCP-specific attacks like tool poisoning, prompt injection, and data exfiltration, allowing or denying those calls inside the AI client, running policy and audit across agent connections, and provisioning configuration to devices managed through the customer's MDM takes specialized expertise (s8, s13, s16, s17). This scores the complexity of building that control plane, not proven superior detection, which is unbenchmarked.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyer is enterprise IT and security, reached through single sign-on and SCIM that themselves pass procurement. Named customers include Gusto, Opendoor, Instacart, Decagon, and dbt Labs, plus unnamed Fortune 500s, with public executive endorsements from Gusto and Jane (s4, s7, s10). That is above thin single-account traction and consistent with a procurement-gated enterprise buyer.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Prior 2 to 3. Runlayer is the governed entrypoint for approved agent tool access, a single MCP entrypoint and gateway across every major AI client, and it extends enforcement to managed devices through mobile-device-management provisioning (s1, s16, s17). Removing it interrupts approved agent access until traffic is re-routed, which places it with the two closest MCP-gateway peers scored at this level as infrastructure the workload depends on rather than a control beside it.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The approved-tool catalog appears to be per-customer configuration over broadly available MCP ecosystem data a funded rival can rebuild, the threat screening rests on detection logic with no disclosed private attack corpus or cross-customer flywheel, and no named non-public dataset appears in fetched sources, so 1.
Strategic Market Segmentation Runlayer sells to the enterprise IT and security team accountable for how employees' AI agents reach company tools…

Runlayer sells to the enterprise IT and security team accountable for how employees' AI agents reach company tools. The buyer is the team that must enable agent use across the business while keeping identity, policy, and audit in its own hands, not the individual developer wiring up a personal key.

Independent reporting confirms the pain. The Rising in Cyber 2026 CISO survey reports more than 70 percent running AI agents in production while only 11 percent rate their AI security as comprehensive. Gartner frames the same gap, warning that building agentic AI on MCP raises new attack vectors and immature practices elevate risk.

The segment is broad on paper and concentrated in evidence. Runlayer supports the range of AI clients an enterprise uses and lets teams draw from more than 18,000 available MCP servers, positioning it for any team adopting agents, yet the named customers in fetched sources are a specific set, Gusto, Instacart, Decagon, Opendoor, dbt Labs, and Jane, plus unnamed Fortune 500s. How far it reaches beyond that early cohort the public record does not yet answer.

Product Capabilities & AI Advantages Runlayer is a platform that enables agent use and secures it in the same place…

Runlayer is a platform that enables agent use and secures it in the same place. It lets teams draw from more than 18,000 available MCP servers, approve and publish a vetted set, and serve them through a governed gateway to the AI clients employees use, then ties that access to enterprise identity, with its trust center listing WorkOS for single sign-on and SCIM directory sync. The stated technical claim is control over the whole agent-to-tool path rather than a single integration.

The platform screens agent tool calls for the protocol's own attack surface. Per SecurityWeek it aims to identify and block prompt injections, tool poisoning, data exfiltration, output manipulation, intent drift, shadow MCPs, and unmanaged agents, and the docs add session-level behavior monitoring that flags manipulation across an agent's run. A separate shadow-AI capability, deployed through the customer's mobile-device-management tools, surfaces shadow MCP usage and can block servers not managed by Runlayer. Independent research corroborates the surface: the MCPTox benchmark characterizes tool poisoning, malicious instructions hidden in a tool's metadata, as a fundamental MCP vulnerability distinct from attacks in tool outputs.

External validation is strong for the stage, though it is endorsement rather than measured efficacy. The co-creator of MCP and Cursor's head of security are listed among its advisors and backers, and public docs detail hosted and self-hosted AWS, Kubernetes, and Terraform deployment. No independent benchmark of the screening's detection quality appears in fetched sources, so the efficacy claims rest on the vendor's description plus ecosystem endorsements.

Sales Engagement & Go-to-Market Runlayer launched out of stealth naming recognizable enterprise customers and now shows named executives endorsing it…

Runlayer launched out of stealth naming recognizable enterprise customers and now shows named executives endorsing it. The AI Insider reports dozens of customers within months of quiet operation, TechCrunch reports eight unicorns or public companies among them, and the company's own pages carry endorsements from Gusto's CISO and CIO and Jane's Chief AI Transformation Officer, who calls Runlayer the backbone of Jane's AI strategy. Named references across non-vendor sources are the clearest traction signal in the record.

Partnerships extend the motion past a customer list. Runlayer's own blog says it is an official Cursor Hooks launch partner able to allow or deny MCP tool calls inside Cursor, putting the product in front of developers where they already work. That is a distribution channel a feature-copying rival cannot reproduce by writing software alone.

The funding has stepped up behind that motion. An initial seed led by Keith Rabois of Khosla Ventures and Felicis preceded the named-logo launch, and a $30 million Series A led by Felicis in June 2026 brought the total raised to $42 million. What the public record still lacks is contract size, retention, or revenue, so the logos and the follow-on round are adoption evidence rather than proof the accounts have expanded.

Pricing Model Runlayer publishes no price in fetched sources, so the charged unit and list rate stay private…

Runlayer publishes no price in fetched sources, so the charged unit and list rate stay private. The site routes buyers to a demo rather than a self-serve tier, the posture of a vendor selling negotiated enterprise deals, which fits the enterprise IT and security buyer it names.

The likely metering unit is inferable but unstated. Because Runlayer governs access for users, teams, and agents and screens every tool call, cost would plausibly track seats, connected agents, or call volume, the consumption logic adjacent gateway products use, but no fetched page states the unit. What Runlayer believes buyers pay for stays an inference.

The hidden-price posture signals where the company expects the deal to happen. A negotiated enterprise sale may fold the cost into a larger security or platform agreement, though the public record does not describe Runlayer's contract structure, and a developer evaluating the product finds no transparent paid plan or published commercial entry point. Confirming the unit and whether usage is capped would require a sales conversation.

Product Delivery & Operations Runlayer is delivered as software the customer deploys and configures…

Runlayer is delivered as software the customer deploys and configures. Its docs offer a hosted deployment or self-hosting in the customer's own AWS account through Kubernetes, Helm, and Terraform, so a security team chooses the placement that fits its environment, and the shadow-AI controls deploy through the customer's mobile-device-management tools.

The operational promise is governed access without slowing developers. Approved servers are published to users while unvetted ones go through review, and the same identity and policy the enterprise already enforces apply to agent connections. Runlayer pitches the platform as enforcement that keeps pace with developer demand rather than a review queue teams route around.

The operational risk profile leans on the customer, especially when self-hosted. A self-hosting buyer configures policy and runs the software in its own environment, and the public materials describe tooling and deployment options rather than a managed detection service or an outcome guarantee. Published uptime, support commitments, and incident-response terms do not surface in fetched pages, so a buyer resolves those in the contract.

Earning Customers' Trust Runlayer backs its assurance claims with an inspectable trust portal rather than footer badges alone…

Runlayer backs its assurance claims with an inspectable trust portal rather than footer badges alone. The Trust Center at trust.runlayer.com, rendered this analysis, lists SOC 2 Type 2, HIPAA, and GDPR and offers a SOC 2 Type II report, a penetration test, and security policies under an access request. It names its subprocessors, including AWS and WorkOS for authentication and directory sync, useful procurement assurance for a product in the path of agent access to sensitive systems.

The product's own controls are the rest of the trust case. Runlayer ties access to enterprise identity with single sign-on and SCIM, applies policy to those connections, and screens tool calls, allowing or denying them. Its documentation adds session-level behavior monitoring that the company says detects manipulation across an agent's full run. A self-hosted deployment lets a regulated buyer keep agent traffic inside its own environment.

The gap a reviewer would still note is breadth and openness of assurance. No ISO 27001 certification appears, the SOC 2 and penetration-test reports sit behind a request gate, and no third-party efficacy benchmark of the screening is public. For a company founded in 2025 the attestations carry a short track record, so a reviewer pairs the published controls with the gated artifacts and a sales conversation.

Platform Strategy & Ecosystem Positioning Runlayer positions itself as the control point for the whole enterprise agent estate, not a single integration…

Runlayer positions itself as the control point for the whole enterprise agent estate, not a single integration. It brokers access between AI clients and the MCP servers, skills, and agents they call, lets teams vet and publish a set drawn from more than 18,000 available servers, and serves them across the AI clients an enterprise uses. The platform claim rests on owning the chokepoint every agent connection passes through.

That chokepoint also makes Runlayer dependent on the ecosystem around it. Its MCP gateway and approved-tool catalog are exposed if MCP stops being how agents reach tools, though the company also sells controls that sit beside the protocol, including enforcement hooks inside the Cursor client and session-level monitoring of an agent's run, and it integrates with identity providers, AI clients, and servers it does not own. The Cursor Hooks partnership shows the upside, an enforcement point inside a popular client, and the dependency in the same move, since that channel belongs to Cursor.

What exposes Runlayer is who ends up owning this layer. A platform that already holds the enterprise's data, identity, or developer tools is the natural owner of agent tool access too, and the nearest rivals drew buyers on exactly that logic. Snowflake signed a definitive agreement to acquire Natoma to extend its governance from data to AI actions, and Check Point agreed to acquire Lakera to fold agentic-AI security into its stack, so the layer Runlayer is building independently is ground platform owners are well placed to absorb.

Team & Execution Capability Runlayer's founders built AI products and MCP tooling before starting the company…

Runlayer's founders built AI products and MCP tooling before starting the company. The about page says the founding team raised over $200 million cumulatively and created Zapier MCP and Agents, and names CEO Andy Berman for Nanit and for Vowel, which Zapier acquired. TechCrunch frames him as a three-time founder building a tool to keep business users' AI agents operating securely.

The insider standing around the company is unusual for its stage. The co-creator of MCP and Cursor's head of security advise it, and SentinelOne's chief product officer appears among the backers Runlayer lists publicly, signals from the protocol and tool ecosystem rather than vendor demos. That standing helps a buyer choose among gateways that look alike on a feature sheet, though it is a relationship rather than an asset the company owns.

The credibility gap is that the cited prior company exit was in productivity software rather than a dedicated security vendor, though the record shows MCP-security expertise through Balocco. Berman's exit is traceable through a named acquisition but sits in workflow software, so the team reads as strong AI builders newly entering security rather than repeat security founders with an established buyer relationship.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 SecurityWeek: Runlayer, an AI enablement and control platform press 2026-07-06
f2 TechCrunch on Runlayer launching from stealth press 2026-06-13
f3 SecurityWeek: Runlayer Series A announcement, June 25, 2026 press 2026-07-04
f4 AI Defense Matrix Catalog entry other 2026-06-10
f5 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Runlayer homepage: AI enablement, security, and control in one platform
“Give every employee the golden path to use agents. AI enablement, security, and control in one platform.”
official 2026-07-06
s2 Runlayer for IT & Security page
“Enable and secure AI. Give teams a golden path to AI usage, with security and governance built in.”
official 2026-07-06
s3 Runlayer about page: founding team and advisors
“Our founding team has built AI at scale and raised over $200M cumulatively. We created Zapier MCP and Agents. Vitor Balocco is a recognized MCP security expert. Advisors: David Soria Parra (Co-Creator of MCP, Anthropic), Travis McPeak (Head of Security, Cursor), Ely Kahn (CPO, Sentinel One).”
official 2026-07-06
s4 Runlayer for AI platform page: named customer endorsements
“Runlayer helped us unlock a new, fundamentally different way to do our jobs. Mike Wittig, CISO & CIO, Gusto. Runlayer has become the backbone of our AI strategy at Jane. Mark Hazlett, Chief AI Transformation Officer, Jane.”
official 2026-07-06
s5 Runlayer documentation: hosted or self-hosted AWS deployment
“Runlayer runs as a hosted deployment or self-hosted in your own AWS account, integrating with existing Terraform and Kubernetes workflows.”
official 2026-07-06
s6 Runlayer Trust Center (SOC 2 Type 2, HIPAA, GDPR; WorkOS identity), rendered this session
“Compliance: SOC 2 Type 2, HIPAA, GDPR. Resources: SOC 2 Type II, Penetration Test, Access Control Policy. WorkOS - Auth & Identity: Authentication & identity (SSO/SAML, OIDC, SCIM 2.0 directory sync, MFA).”
official 2026-07-06
s7 Runlayer Series A blog (Andy Berman, June 24 2026): $30M round and customers
“We've raised a $30M Series A from Felicis and Khosla Ventures, bringing total funding to $42M. Since coming out of stealth 6 months ago, we've already signed some of the fastest-growing companies like Instacart, Gusto, Decagon, Opendoor, dbtLabs, AngelList, Lemonade, and a number of Fortune 500s.”
official 2026-07-06
s8 SecurityWeek: Runlayer Raises $30 Million in Series A Funding
“AI enablement and control platform Runlayer... According to Runlayer, its platform can also identify and block prompt injections, tool poisoning, data exfiltration, output manipulation, intent drift, shadow MCPs, and unmanaged agents.”
press 2026-07-06
s9 TechCrunch on Runlayer's launch and the crowded MCP gateway category
“Such security issues have given rise to numerous MCP security products, including products from big-name companies like Cloudflare, Docker, and Wiz. The most common type of MCP security product these days is a gateway.”
press 2026-07-06
s10 The AI Insider on Runlayer leaving stealth with named enterprise customers and the MCP creator as advisor
“The company was founded by serial entrepreneur Andrew Berman, known for building Nanit and the AI platform Vowel, which was acquired by Zapier in 2024. In just four months... Runlayer has signed dozens of customers, including major enterprises such as Gusto, dbt Labs, Instacart, and Opendoor.”
press 2026-07-06
s11 New-TechEurope on the Rising in Cyber 2026 CISO survey and cyber M&A
“More than 70% of surveyed CISOs reported that AI agents are already operating in production environments within their organizations, yet only 11% described their existing AI security tools as comprehensive, effective, or best in class.”
press 2026-07-06
s12 Gartner: MCP-based agentic AI raises new attack vectors and risk exposure
“As organizations continue to build and integrate agentic AI applications using technologies such as Model Context Protocol (MCP), new attack vectors and immature security practices will significantly elevate risk exposure.”
research 2026-07-06
s13 arXiv: MCPTox, a benchmark for tool poisoning attacks on real-world MCP servers
“we investigate a more fundamental vulnerability: Tool Poisoning, where malicious instructions are embedded within a tool's metadata without execution.”
research 2026-07-06
s14 Snowflake press release: definitive agreement to acquire Natoma, an enterprise MCP platform
“today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents. Closing of the acquisition is subject to customary closing conditions.”
press 2026-07-06
s15 Check Point press release: acquires Lakera, an AI-native security platform for agentic AI
“today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-07-06
s16 Runlayer blog: official Cursor Hooks launch partner
“Runlayer is an official Cursor Hooks launch partner. With Cursor Hooks, securely allow or deny MCP tool calls with Runlayer's enterprise MCP platform.”
official 2026-07-06
s17 Runlayer docs index (llms.txt): session monitoring, MDM provisioning, self-host deployment
“AgentGuard: Session-level behavior monitoring that detects manipulation across an agent's full trajectory. Deploy automatic configuration provisioning to macOS devices managed by Mosyle Business. EKS + Terraform: Deploy production-ready Kubernetes infrastructure on AWS EKS using Terraform.”
official 2026-07-06
Deep-Dive Sources (17)
Id Source Tier Accessed
s1 Runlayer homepage: AI enablement, security, and control; 18,000+ MCPs, governed gateway
“Give every employee the golden path to use agents. AI enablement, security, and control in one platform. Start with 18,000+ MCPs for the tools your company runs. Add internal MCPs, approve the right set, and serve them through a governed MCP gateway across every major AI client.”
official 2026-07-06
s2 Runlayer for IT & Security page
“Enable and secure AI. Give teams a golden path to AI usage, with security and governance built in.”
official 2026-07-06
s3 Runlayer about page: founding team and advisors
“Our founding team has built AI at scale and raised over $200M cumulatively. We created Zapier MCP and Agents. Vitor Balocco is a recognized MCP security expert. Advisors: David Soria Parra (Co-Creator of MCP, Anthropic), Travis McPeak (Head of Security, Cursor), Ely Kahn (CPO, Sentinel One).”
official 2026-07-06
s4 Runlayer for AI platform page: reusable capabilities and named customer endorsements
“Publish approved tools and agents as reusable infrastructure across teams. Runlayer has become the backbone of our AI strategy at Jane. Mark Hazlett, Chief AI Transformation Officer, Jane. Runlayer helped us unlock a new, fundamentally different way to do our jobs. Mike Wittig, CISO & CIO, Gusto.”
official 2026-07-06
s5 Runlayer documentation: hosted or self-hosted AWS deployment
“Runlayer runs as a hosted deployment or self-hosted in your own AWS account, integrating with existing Terraform and Kubernetes workflows.”
official 2026-07-06
s6 Runlayer Trust Center (SOC 2 Type 2, HIPAA, GDPR; WorkOS identity, AWS), rendered this session
“Compliance: SOC 2 Type 2, HIPAA, GDPR. Resources: SOC 2 Type II, Penetration Test, Access Control Policy, Cryptography Policy. Subprocessors: Amazon Web Services (ECS/EKS, RDS, S3, KMS, Secrets Manager); WorkOS - Auth & Identity (SSO/SAML, OIDC, SCIM 2.0 directory sync, MFA).”
official 2026-07-06
s7 Runlayer Series A blog (June 24 2026): $30M round, model-neutral platform, customers
“We've raised a $30M Series A from Felicis and Khosla Ventures, bringing total funding to $42M. Since coming out of stealth 6 months ago, we've already signed some of the fastest-growing companies like Instacart, Gusto, Decagon, Opendoor, dbtLabs, AngelList, Lemonade, and a number of Fortune 500s.”
official 2026-07-06
s8 SecurityWeek: Runlayer Raises $30 Million in Series A Funding
“AI enablement and control platform Runlayer... According to Runlayer, its platform can also identify and block prompt injections, tool poisoning, data exfiltration, output manipulation, intent drift, shadow MCPs, and unmanaged agents.”
press 2026-07-06
s9 TechCrunch on Runlayer's launch and the crowded MCP gateway category
“Such security issues have given rise to numerous MCP security products, including products from big-name companies like Cloudflare, Docker, and Wiz. The most common type of MCP security product these days is a gateway.”
press 2026-07-06
s10 The AI Insider on Runlayer leaving stealth with named enterprise customers and the MCP creator as advisor
“The company was founded by serial entrepreneur Andrew Berman, known for building Nanit and the AI platform Vowel, which was acquired by Zapier in 2024. In just four months... Runlayer has signed dozens of customers, including major enterprises such as Gusto, dbt Labs, Instacart, and Opendoor.”
press 2026-07-06
s11 New-TechEurope on the Rising in Cyber 2026 CISO survey
“More than 70% of surveyed CISOs reported that AI agents are already operating in production environments within their organizations, yet only 11% described their existing AI security tools as comprehensive, effective, or best in class.”
press 2026-07-06
s12 Gartner: MCP-based agentic AI raises new attack vectors and risk exposure
“As organizations continue to build and integrate agentic AI applications using technologies such as Model Context Protocol (MCP), new attack vectors and immature security practices will significantly elevate risk exposure.”
research 2026-07-06
s13 arXiv: MCPTox, a benchmark for tool poisoning attacks on real-world MCP servers
“we investigate a more fundamental vulnerability: Tool Poisoning, where malicious instructions are embedded within a tool's metadata without execution.”
research 2026-07-06
s14 Snowflake press release: definitive agreement to acquire Natoma, an enterprise MCP platform
“today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents. Closing of the acquisition is subject to customary closing conditions.”
press 2026-07-06
s15 Check Point press release: acquires Lakera, an AI-native security platform for agentic AI
“today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-07-06
s16 Runlayer blog: official Cursor Hooks launch partner
“Runlayer is an official Cursor Hooks launch partner. With Cursor Hooks, securely allow or deny MCP tool calls with Runlayer's enterprise MCP platform. Runlayer identifies shadow MCP usage and surfaces it before it becomes a problem.”
official 2026-07-06
s17 Runlayer docs index (llms.txt): session monitoring, MDM provisioning, self-host deployment
“AgentGuard: Session-level behavior monitoring that detects manipulation across an agent's full trajectory. Deploy automatic configuration provisioning to macOS devices managed by Mosyle Business. EKS + Terraform: Deploy production-ready Kubernetes infrastructure on AWS EKS using Terraform.”
official 2026-07-06

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.