Competitive intelligence / critical reconstruction

Runlayer, under the hood

What it is really building, what customers are actually running, how it gets bought, where the story outruns the proof, and what Decawork should learn.

Research cutoff August 10, 2026 Scope Product, code artifacts, customers, founders, sales, market Method Official, independent, customer-side, archived, technical, legal
Core verdict

Runlayer used MCP security as an enterprise wedge into a much larger ambition: become the neutral system of record and execution boundary for governed company capabilities.

Reality check

The mature proof is a gateway, endpoint hooks, identity, audit, connector operations, and a white-glove rollout. Native agents are real, broad, and newer. Public customer evidence still centers on governed human tool use.

01 / Executive truth

The company behind the category story

Runlayer is a real, fast-moving technical company. It is also a repeat-founder commercialization machine with unusually strong protocol, Cursor, investor, CISO, and prior-team advantages. Both facts matter.

What exists today

A three-path control plane: managed MCP gateway traffic, endpoint and client hooks for local/shadow activity, and a sandboxed native agent runtime. Identity, policy, scanning, approvals, telemetry, and deployment unify those paths.

Public implementation evidence is unusually strong for a private enterprise product: a large Apache-licensed Python CLI, two hooks SDKs, detailed docs, Kubernetes and ECS deployment material, public connectors, and a rapid release cadence. See PyPI, documentation index, and GitHub.

What gets bought

Companies buy a paved road from scattered employee experimentation to approved access. Runlayer discovers existing usage, installs a catalog and gateway, connects the high-demand systems, brings Security into the request loop, trains employees, and only then expands into enforcement and agents.

This is adoption infrastructure with security inside it, not merely a threat product. The best buyer owns both velocity and risk.

Proven wedge

MCP lifecycle, OAuth, policy, audit, connector deployment, employee enablement, and supported endpoint discovery.

Expansion

Agent identity, normalized sessions, Guard, skills, native agents, evals, spend, ROI, self-improvement, browser and custom runtime hooks.

Missing proof

Autonomous job completion at customer scale, independent security efficacy, hard business ROI, gross margin after rollout, and cold-sales repeatability.

Confidence convention

A detailed operational evidence, ideally corroborated by customer-side or independent material. B credible signed or production relationship, thin scope. C logo, endorsement, or company claim only. Not customer trial, partner, validator, or failed commercial relationship.

02 / Non-obvious findings

The ten points worth remembering

  1. The platform thesis came before MCP. Vowel was already becoming an AI command center that queried company apps and initiated actions. Early Anysource described an AI enablement layer with connectors, identity, observability, no-code agents, SSO/SCIM/RBAC, and private deployment. MCP supplied a sharp, urgent category wedge.
  2. The hidden product is forward-deployed transformation. Gusto received connector building and recurring training. Homebase had engineers in Slack daily. The field team says its bottleneck is converting pilots to thousands of users. Software is only part of the delivered outcome.
  3. Runlayer learned that fear did not close. Its founder says the early security pitch was backwards. Customers moved when the pitch became “help the company adopt AI faster without losing control.” Governance supports the purchase; acceleration drives it.
  4. The new agent story is ahead of the public customer proof. The runtime is technically substantial, but the clearest case metrics are users, MCP counts, integration time, and human connector calls. Homebase explicitly calls the full agent operating model its next phase.
  5. Watch is a supported-surface product, not omniscience. It finds configs, artifacts, processes, transcripts, and hook events on managed devices. Client and operating-system coverage differs. Linux is detect-only; unmanaged endpoints and many cloud paths remain outside it.
  6. “Local MCP” does not mean local policy. The CLI can keep actual execution local while sending eligible tool metadata, arguments, and outputs to tenant pre/post endpoints for policy and scanning. Customer hosting changes the destination, not the conceptual flow.
  7. ToolGuard is young. Its public model changelog starts April 2026 and records rapid retraining and architecture changes. Published performance numbers lack an independent public corpus or replication.
  8. Notion reveals a second business. Its official subprocessor register names Runlayer for security for MCP connections. The likely surface is Notion Custom Agents, but Notion does not map specific controls to Runlayer. This is embedded agent-product infrastructure, not the standard employee control-plane sale.
  9. The first customer graph overlaps the investor and advisor graph. Gusto, dbt, AngelList, Opendoor, Lemonade/SVCI, protocol creators, Cursor leaders, and security executives appear across customers, advisors, investors, and partners. It is brilliant distribution, but not a neutral sample of cold-market conversion.
  10. Rippling exposes the danger of the motion. Runlayer says a near-year prospective trial involved code and roadmap access before a competing product appeared; Rippling denies misuse. The uncontested lesson is that long embedded trials need commercial and information boundaries.
03 / Product anatomy

Three execution planes, one control model

The durable product is not “an MCP proxy.” It is normalization: different clients and runtimes become the same identity, permission, scanner, approval, and trace model.

SurfaceUnder the hoodWhat it controlsLimit
MCP GatewayTenant proxy for Streamable HTTP/SSE plus local FastMCP proxyTool visibility, filtering, identity, OAuth, arguments, output, policy, logsTraffic must route through it or a supported hook
Catalog / Unified PluginApproved MCPs, skills, plugins, agents; a two-tool search/execute interface can dynamically route callsDiscovery, reuse, lifecycle, simplified client tool list18,000 ecosystem entries should not be read as maintained integrations
WatchMDM-distributed signed binary, config/process scanning, native hooks, bounded transcript tailersInventory, drift, supported pre/post call enforcement, some prompt/session captureCoverage is client-, OS-, and deployment-dependent
Identity and policyFGA roles, PBAC rules, runtime conditions, SSO/SCIM, OAuth broker, agent accounts and OBOUser, group, agent, connector, tool, argument, session-context scopeSome agent-account and approval functions remain beta/new
GuardTool list/call/intent classifiers plus PII, credential, invisible-character, skill, and trajectory scanningAlert, mask, block, approval, stop future tool callsPublic efficacy claims are self-reported
Sessions / auditNormalized events from hooks, agents, inference SDKs, browser, and imports; hot DB plus object-store pipelinesPrompt, reasoning, tool, response, denial, cost, lifecycle visibilitySessions are short-term operational data and not the same as SIEM-exported audit
Runlayer AgentsSandbox with shell/files/browser, persistent workspace and SQLite memory, triggers, approvals, subagents, artifacts, evalsInteractive and autonomous execution on the same governed capabilitiesNewer and less independently customer-proven than gateway core
DeploymentDedicated hosted AWS, customer AWS/ECS/EKS, Kubernetes/Helm/operator, air-gapData residency, network path, isolation, enterprise operationsShared OAuth broker unavailable self-hosted; customer owns patching and some retention duties

Native agent runtime: more than a prompt wrapper

Execution

Writable /tmp/workspace, shell, files, edits, Git, Node, Python, package managers, database clients, HTTP utilities, and a real Chromium browser.

State

Per-agent persistent filesystem, persistent SQLite memory, and user/channel-scoped memory. The docs warn that neither should replace source-of-truth systems.

Triggers

Interactive chat, Slack, schedules, webhooks, Runlayer audit events, and Slack channel monitors. Webhook authorization is optional and off by default, so the URL is a secret.

Control

Daily/weekly budgets, human approvals that pause/resume runs, tool and connector scope, agent accounts, security results, version history, and disable controls.

Composition

Skills, artifacts, model choice, up to 20 subagents, reusable templates, privacy modes, cloning, and programmatic management through Runlayer MCP.

Evaluation

Historical tasks with mocked MCP outputs by default. Shell and filesystem still execute; real-tool mode can create side effects. Strong foundation, not a proof of customer reliability.

04 / Technical reality

What crosses the boundary and where it can fail

The architecture is conventional and credible. The hard diligence questions are coverage, data flow, fail-open behavior, model efficacy, and how much is actually contractual.

Managed remote MCP

AI client -> tenant /api/v1/proxy/{server_id}/mcp -> authentication and caller identity -> FGA / PBAC / runtime-condition evaluation -> input scanner and optional approval -> tenant-held OAuth or static credential -> upstream MCP -> output scanner and masking -> client -> audit log and optional Sessions stream

Local MCP

AI client -> local Runlayer FastMCP proxy -> tenant /api/v1/local/{server_id}/pre may filter, block, require approval, or rewrite arguments -> local stdio / SSE / HTTP server executes -> tenant /api/v1/local/{server_id}/post may block, mask, or rewrite output -> AI client
Meaning

Execution can remain on the laptop while policy decisions and eligible payloads leave it. Credentials use the OS keychain where available, with a YAML fallback on headless systems. This is a centralized control plane, not an offline endpoint firewall.

Endpoint and browser gaps

Client semantics differ

Windsurf cannot block or rewrite outputs. Cline CLI enforcement is macOS-only, best-effort, and fail-open on hook failure. Gemini output masking can become a full block. Qwen users with local control can disable hooks, producing drift rather than prevention.

Linux is discovery-only

Current docs describe Detect on macOS, Windows, and Linux, but Protect/Enforce remain OS- and client-specific. A marketing page that only names macOS enforcement appears to lag the broader current docs, which still contain important gaps.

Browser response control is late

The managed extension covers selected AI sites on macOS. Some sites are observation-only. Responses are captured after rendering, so output scanning cannot retract content already displayed.

Unmanaged paths stay outside

BYOD without the binary, unsupported clients, local admins, unknown browser sites, and cloud agents that do not inherit endpoint hooks can bypass Watch. The gateway still controls traffic voluntarily routed through it.

Identity and credentials

  • Agent Accounts use OAuth client credentials and RFC 8693 token exchange for delegated on-behalf-of access. Effective permission is the intersection of agent and user policy.
  • Agent identity lives in Runlayer, not necessarily as an Okta or Entra service identity. One-hour tokens mean secret rotation does not revoke already-issued stateless tokens immediately.
  • Resource/audience enforcement is documented as optional and off by default. Delegation and OAuth session grants have separate revocation paths.
  • The hosted OAuth broker simplifies vendor callbacks for a limited set of services. Self-hosted customers must bring their own vendor applications.
  • Identity Forward supports preferred short-lived EdDSA JWTs or plain headers. Plain headers are spoofable unless direct upstream access is blocked by the network.

Guard maturity

SignalEvidenceInterpretation
First public model bundleApril 28, 2026 in the model changelogThe security ML is materially young
Training dataSynthetic plus anonymized production traffic; corpus expanded 2.7x in AugustReal feedback loop is plausible; privacy, opt-out, and definition of anonymization need diligence
Model changeTool Call Guard moved to a neural MLP in AugustFast iteration, but historical benchmarks may not describe today's model
Published metrics50-100 ms, about 99% ROC-AUC, 95.6% accuracy, and false-positive reductionCompany-reported; no public independent test set or reproduction found
AgentGuardTrajectory-level detection of steering, reasoning pivots, and slow driftExistence is documented; architecture and quality evidence are not public

Infrastructure

Public docs and trust material point to React, FastAPI/Alembic, PostgreSQL, Redis, S3 or GCS, background workers, OpenTelemetry, AWS ALB/WAF/ECS/Fargate/Aurora/ElastiCache, plus EKS/GKE/Helm/operator self-hosting. Hook/session pipelines use streaming and object-store/Parquet materialization. WorkOS supports enterprise identity, with KMS/Secrets Manager and Sentry-related components disclosed in the trust center.

This is good enterprise engineering, not a proprietary new computing substrate. The moat must come from surface coverage, policy semantics, operational data, customer rollout, and embedded workflows.

Inference, not fact

The native runtime hook lifecycle closely resembles OpenCode's plugin API. A fork or embedded harness is plausible at medium-high confidence, but no public statement proves it. This matters only for patch cadence and ownership, not whether the runtime exists.

Public artifact trail

ArtifactCurrent public evidenceWhat it reveals
runlayer CLI0.29.9 on August 7, 2026; first public release October 6, 2025; Apache-2.0; 234 files and roughly 2.46 MB of sourceLocal FastMCP proxy, Watch, hooks, deployment, catalog, plugin, and skill logic. Dependencies expose MCP, OAuth, Docker, keyring, RE2, and OpenTelemetry choices.
TypeScript Hooks SDK0.3.0 on July 31; first released June 9Adapters for Claude Agent SDK, Vercel AI/Eve, OpenAI Agents SDK, Google ADK, and LangChain.
Python Hooks SDK0.2.1 on July 30; first released June 9Same pre/post policy and telemetry model for Python runtimes.
GitHub organizationFour small public repositories at cutoffCore backend/frontend/models/infrastructure remain private. Public work shows plugins, deploy examples, and patched connector forks.
DocumentationMore than one hundred public pages, still changing through AugustDetailed operational surface, but docs are currently marked noindex,nofollow.

The CLI shipped roughly 75 versions between October 2025 and August 2026. That cadence is evidence of execution and also of product volatility. Package, docs, SDK, Terraform, and plugin versions do not always move together.

What Watch uploads and does not upload

Metadata-first discovery

The signed aiwatch binary runs as root or SYSTEM. It scans known client configs, MCPs, skills, plugins, agent definitions, process tables, and listening sockets. Public docs say it does not inspect network packets, process memory, or environment variables and does not upload raw MCP config files.

Content still crosses for classification

Skills and plugins can send bounded text, up to 1 MB per file and 5 MB per artifact. Agent definitions send metadata and content hashes rather than raw definitions. Process command lines are scrubbed and bounded, with a one-way hash retained for correlation.

Sessions go deeper

Supported hooks and transcript tailers can send prompts, reasoning, tool calls, responses, and native permission events. Turning off prompt/reasoning capture can reduce Sessions data, but enforcement still transmits the tool payload needed for policy and scanning.

Zero transmission is a product choice

Compliance feeds are monitoring-only. Public docs say truly avoiding Watch transmission requires not installing it. Customer-hosting relocates the control plane but does not eliminate the need for centralized decisions.

Other interception points

PointStatusBoundary
Custom agent framework hooksShipped SDKsCorrect adoption is required. Tool outputs are truncated before upload, and lifecycle telemetry is generally best-effort. Fail semantics vary by adapter.
Anthropic inference hookShipped against Anthropic betaDoes not imply coverage for Bedrock or Vertex-hosted Anthropic use.
Provider compliance importsShippedPost-hoc monitoring only. Cannot prevent an action.
LLM GatewayEarly access, self-hosted onlyOpenAI, Anthropic, and compatible dialects. No native Gemini, Vertex, Bedrock, or Azure upstream. Published sub-millisecond overhead uses a loopback mock, not live provider traffic.
Anthropic MCP TunnelsIntegration documented against Anthropic betaRunlayer says it collaborated with Anthropic, but no Anthropic primary source naming Runlayer was found.

Connector work is pragmatic, not magical

ConnectorWhat Runlayer really suppliesCustomer work that remains
Google WorkspaceRunlayer-built services across Gmail, Calendar, Drive, Docs, Sheets, Slides, and Forms, with broad read/write toolsCustomer creates/configures the Google OAuth application and accepts scopes
Microsoft 365Graph-based Outlook, Calendar, OneDrive, SharePoint, and Teams; server-side text extraction for selected office files up to documented limitsCustomer Entra application and admin consent
SnowflakeNarrow read-only five-tool serverCustomer OAuth and warehouse configuration; user queries inherit Snowflake rights
WorkdayBeta deploy-only direct REST integration, including sensitive write actionsTenant-specific functional security and OAuth create significant implementation/support work
SlackCurrent strategy proxies Slack's vendor-hosted MCPRunlayer's older first-party Slack connector is explicitly unmaintained, showing willingness to abandon custom ownership when a native server is better
Long tailProxy vendor servers, fork and pin community packages, deploy customer Docker MCPs, and patch incompatibilitiesUncataloged servers can violate MCP, reject proxies, lack public endpoints, or require days/weeks of compatibility work

Evidence-based maturity map

CapabilityStatus at cutoffConfidence / caveat
MCP gateway, catalog, tool filtering, OAuth, policy, audit, custom deployMature coreHigh. Present from initial wedge with code/docs/customer evidence.
SSO/SCIM, dedicated AWS, customer ECS/EKS/KubernetesEnterprise coreHigh. Detailed deployment and shared-responsibility surface; operationally heavy.
Watch DetectShippedHigh on macOS/Windows/Linux. Detection is not universal interception.
Watch Protect/Enforce and browserPartialHigh. Client-specific gaps, Linux detect-only, browser package currently macOS-only.
Sessions and SDK hooksShipped, newHigh on existence. Cross-surface completeness depends on hooks/imports.
Agent Accounts and human approval rulesBeta/newHigh. Agent Accounts were beta in January and moved rapidly into core messaging.
ToolGuard, AgentGuard, SkillGuardShipped, youngHigh on existence; low on independently validated efficacy.
Native Agents and offline evalsShipped, new layerHigh on implementation; limited independent customer reliability proof.
LLM GatewayEarly accessHigh. Self-hosted only and provider-limited.
Terraform provider and IncidentsBetaHigh. Repositories/generated SDK are private.
AgentCore/Lambda alternate runtimesFeature-flag evidenceMedium. Code paths exist; general availability cannot be inferred.
Self-healing, universal visibility, 18,000 maintained connectorsMarketing-sensitiveDirection or count exists, but the common interpretation outruns public evidence.

External partnership validation

  • Cursor: Cursor's own Hooks partner material and marketplace validate the endpoint integration. Cursor security leaders are also advisors/investors, so testimonial and customer status are separate questions.
  • Box: Box's own blog confirms marketplace, identity enforcement, audit, and scanning around Box MCP.
  • 1Password: 1Password confirms op:// request-time secret retrieval without storing those secrets on disk or in Runlayer's database.
  • AARM: an external conformance review validates Runlayer within its declared interception surface. AARM is young and does not prove universal coverage or model efficacy.
  • AAIF: the Linux Foundation announcement lists Runlayer as a Gold member/supporter. Anthropic, Block, and OpenAI supplied the founding project contributions. “Founding member” should not be read as co-author of MCP.
05 / Customers and relationships

What each account is actually buying

A logo is not a deployment. The table below separates detailed production evidence, thin but credible usage, hidden vendor evidence, endorsements, and a failed trial.

Gusto

A / detailed
Buyer
Mike Wittig, CISO and CIO; earlier IT experience leadership
Scale
3,000+ knowledge workers, four-week integration, 84 MCP servers
Under hood
Gmail, Slack, Snowflake, Confluence, then Workday, NetSuite, GitHub; Slack connector requests; Security disables destructive tools; raw request/response audit; weekly training
Work
Salesforce context into Slack/email, conversational cross-SaaS work across functions
Close
Top-down security and enablement plus embedded FDEs; likely warm access through Gusto cofounder and Runlayer supporter Tomer London
Caveat
No hard public autonomous-job or ROI metric. “All teams” is not the same as daily use by 3,000 people.

Source: detailed case study

Jane App

A / detailed
Buyer
Mark Hazlett, Chief AI Transformation Officer
Scale
800+ workers, two weeks, 36 MCPs, company claims 100% organizational adoption
Under hood
Claude with Drive, Calendar, Gmail, Atlassian, Fellow, Slack, Notion, HubSpot, Jira, GitHub, Canva; Watch; AppSec catalog approval; PHI Drive-folder exclusions
Work
Marketing SEO/site workflows plus governed company knowledge and productivity
Close
Found through AI/MCP community, alternatives evaluated, short POC, annual contract within ten days
Caveat
“100% adoption” is undefined. Public workflows remain primarily human-initiated.

Source: detailed case study

Homebase

A / detailed
Buyer
Justin Nazari, Senior Manager of AI Acceleration
Scale
400+ employees, under one month integration, under five months to broad rollout, 27,000 human connector calls
Under hood
Okta; Datadog, Databricks, CrowdStrike, Sentry, GitHub, Slack, Figma, Workspace; custom MCPs; natural-language Slack agent builder
Work
Claude Code postmortems from Slack, Linear, Datadog, Confluence; business-team Claude usage; marketer becomes an agent builder
Close
Runlayer engineers embedded in Slack daily; power-user usage productized into company registry
Caveat
The case calls the full agent operating model the next phase. Best current metric explicitly says human connector calls.

Source: detailed case study

Opendoor

A- / production
Champions
Morgan Brown, growth; Jonah Back, engineering
Under hood
Google Ads, SEO, and marketing-metrics MCPs built in days; broader golden-path scope not public
Evidence
Archived customer quotes plus later production grouping and customer-side “secret sauce” language
Close
Strong warm-path inference: seed lead Keith Rabois is deeply connected to Opendoor
Caveat
Do not turn a specific marketing deployment into a claim that Runlayer operates all Opendoor agents.

Source: launch archive

Instacart

A-/B+

Champion: Karthik Halukurike, AI Lead. Archived testimony says Runlayer solves building, hosting, accessing, and keeping agent tools current. Runlayer later groups Instacart agents as production.

Unknown: exact connectors, user scale, buyer/signatory, and runtime depth.

dbt Labs

A-/B+

Customer-side material describes an “Okta for MCPs and Skills” paved road: Claude Code Enterprise, Notion “hive mind,” and Runlayer-managed Notion, Omni, and Glean, with nontechnical hack-day adoption.

Close inference: dbt founder Tristan Handy is a Runlayer investor.

AngelList

B+

Head of Security Alberto Martinez describes Runlayer as a design partner and says its endpoint detection beat his Cursor-built approach for shadow OpenClaw. He is also a Runlayer angel.

The relationship blends customer, design partner, and investor.

Lemonade

B

Signed/running is credible; CISO Jonathan Jaffe says Runlayer brings order to chaos. No public workflow, scale, connector, or outcome evidence.

Likely route: SVCI security network. SVCI invested in Runlayer.

Decagon

B

Officially named signed/running. Runlayer collectively mentions identity, access, scans, traces, skills, and sandboxes for companies including Decagon.

There is no account-specific buyer or proof that this governs Decagon's customer-facing CX agents rather than employee AI.

Notion

A / embedded OEM

Notion's own official subprocessor list names “Anysource Inc., dba Runlayer” for “Security for MCP connections.” This means Runlayer may process Notion customer personal data while providing Notion's service, which is stronger evidence than a logo.

Timing and product scope make Notion Custom Agents' external MCP connections a plausible surface. Notion documents unique agent credentials, read/write controls, confirmation modes, result scanning, schema validation, and an outbound proxy, but it does not say which specific controls Runlayer implements. Do not attribute the whole design to Runlayer.

Notion subprocessor list · Custom Agents MCP docs

PagerDuty

C / logo

Current official logo placement, but no public buyer, workflow, deployment depth, or customer-side confirmation found. PagerDuty is also an ecosystem platform with its own MCP and agent products.

Anonymous bank

B- / anonymous

Fortune reports a large bank monitoring 100,000 employees across 200,000 devices. That is strong Watch fleet coverage if accurate, but not proof that those employees actively use governed agents.

Xcel Energy / b.well

C / validators

Archived CISO/CSO endorsements; both executives are in the SVCI network. Xcel's quote mentions custom threat detectors, while b.well's is generic. Neither has enough later evidence to call production customer.

Rippling

Not customer

A near-year prospective trial/collaboration ended without an agreed price. Runlayer sued, alleging NDA-protected code and roadmap information informed a clone. Rippling denies misuse and disputes the allegations.

Independent dispute coverage

Ramp

Unverified

Appears in derivative early lists and in the OAuth-broker integration set, but no solid first-party customer deployment evidence was found. Do not count it.

Metric trap

The customer proof ladder is: device coverage, enabled users, active users, connector calls, completed jobs, reliable autonomous jobs, hard business outcome. Runlayer publishes mostly the first four. The strategic promise lives in the last three.

06 / Go-to-market

The actual closing machine

The sales loop combines founder credibility, strategic networks, a diagnostic wedge, embedded engineering, change management, and land-and-expand product packaging.

STEP 1

Find the dual-mandate owner

CISO+CIO, AI transformation, AI acceleration, AI lead, platform engineering, or a senior growth/engineering operator. They need both adoption velocity and authority to create a company standard.

STEP 2

Run Watch

Discovery converts invisible shadow usage into an inventory. Runlayer's public playbook suggests a period of observation with little or no enforcement, followed by stakeholder-specific policy.

STEP 3

Deliver value in days

Configure SSO and three to five high-demand connectors. Those systems usually account for most early traffic. Build or curate custom MCPs where necessary.

STEP 4

Embed and teach

Daily Slack access, live technical deep dives, recurring training, and agent-building sessions turn a software install into behavior change. This is central to the outcome.

STEP 5

Expand control

Move from catalog and gateway into policy, audit, Guard, agent identity, skills, Sessions, native agents, spend, and ROI. Convert the pilot into thousands of seats.

COMMERCIAL

Enterprise-led

No public rate card or self-serve buying path. Public terms support custom order forms and usage fees. Hiring seeks six-figure enterprise deal experience. Actual ACV and ARR remain undisclosed.

Buyer profile

RoleUrgencyWhat they need to believeProof Runlayer uses
CIO / CISO hybridEmployees are already connecting sensitive systemsSanctioning can be safer and faster than prohibitionDiscovery, identity, catalog, policy, complete call logs, deployment options
AI transformation / accelerationExecutive mandate exists, but nontechnical adoption is weakA shared paved road can unlock every functionSame-day connectors, Slack request loop, training, agent builder, usage visibility
AI/platform engineeringBuilding and maintaining every connector and agent path is draining resourcesRunlayer is credible infrastructure and remains neutral across modelsPrivate deployment, SDK/hooks, deploy CLI, policies, observability, FDE depth
Security/AppSec/IAMShadow MCPs, identity sprawl, prompt injection, audit gapsCoverage is broad enough and fail-safe enough for their fleetWatch, Guard, delegated identity, tool-level rules, SIEM exports, trust material
Power operatorA high-value local workflow already worksThe company route will preserve speed and make it shareableClient choice, unified plugin, curated connectors, templates, minimal setup

Why it works

Reframed fear as momentum. Security is not the headline outcome. It is the mechanism that lets the company say yes.

Gives every stakeholder something. IT gets inventory, Security gets control, AI leaders get adoption, users keep their preferred clients, executives get a transformation story.

Uses the customer as product research. FDEs see connector, identity, policy, and change-management friction firsthand, then rapidly add product surfaces.

Converts protocols into distribution. MCP, Cursor Hooks, Box, 1Password, Anthropic Tunnels, AAIF, AARM, and the investor/advisor graph transfer trust and create warm access.

Makes the sanctioned path easier. One catalog, inherited identity, managed OAuth, and two-tool dynamic search reduce configuration while increasing control.

Supports procurement. Dedicated accounts, customer hosting, Kubernetes, SSO/SCIM, security addendum, and a Vanta trust center meet enterprise process requirements.

A second GTM lane: embedded infrastructure

Notion is the clearest evidence that Runlayer can sell into an agent-product builder rather than an internal AI transformation team. In that lane, Runlayer becomes part of another company's security and MCP connection path and may process that company's end-customer data. The buyer is more likely product, platform, and product security; the integration and contract are closer to OEM infrastructure; the unit of expansion is product usage rather than employee seats. Exact Notion implementation, champion, and economics are not public.

Main scale risk

The company itself says deployment is the bottleneck. A three-person FDE team was expected to grow to ten and then multi-region. If every thousand-seat rollout needs identity archaeology, connector construction, training, and daily Slack presence, growth and gross margin depend on turning that work into repeatable product quickly.

07 / History and product evolution

The wedge narrowed, then the platform reappeared

The simplest public story says Runlayer started as MCP security and expanded. The evidence suggests a broader pre-existing AI command-center thesis, temporarily narrowed for market entry.

At Vowel, Berman describes the bottom-up shadow-IT loop that Runlayer later repeats: employees love a tool, small teams spread it, then IT purchases compliance and control. Vowel is reframed toward an AI command center.

Zapier acquires the Vowel team after the Vowel service had sunset in December 2023. Berman becomes Director of AI; the team builds Central, AI Actions, Agents, and early remote MCP work.

anysource.dev is registered and Anysource, Inc. is formed in Delaware, months before the simplified public “founded in August” story.

Early Anysource positioning already describes the broad enablement layer: registry, identity, policy, observability, connectors, no-code agents, SSO/SCIM/RBAC, VPC/on-prem.

Founders leave Zapier, file the Runlayer trademark, register the assumed name, and ship the first public CLI. Package links still carry Anysource residue.

Public launch and $11M seed. The legible category is enterprise MCP infrastructure: gateway, catalog, inherited identity, threat detection, audit, and private deployment. Company claims dozens of customers and eight unicorn/public companies.

AAIF supporter status, Cursor Hooks, Box, Watch, connector health, Agent Accounts beta, Agent365, OAuth skills, and one-click deploy widen the surface.

1Password partnership, deeper policy and agent identity, AARM alignment, and the first public ToolGuard model releases move the story toward runtime security.

Anthropic MCP Tunnels and a “golden path” narrative position Runlayer as neutral enablement plus control. The team reports fast headcount and revenue growth and names deployment as the bottleneck.

$30M Series A led by Felicis with Khosla participating. Runlayer announces the full control plane and says it is ahead of its seed roadmap.

Native Agents, skills, plugins, sessions, browser hooks, spend/ROI, self-improvement, broad SDK coverage, and the Rippling lawsuit make the larger ambition explicit.

Founding advantage

Andrew Berman

Finance and VC background, Nanit COO/cofounder, Vowel CEO, Zapier AI leader. His edge is fundraising, category creation, recruiting, and enterprise distribution. Vowel's acquisition amount was undisclosed and followed product sunset, so avoid inventing a large exit.

Tal Peretz

Air-force control/data-fusion systems, data-science leadership, third-party cyber risk at Panorays, Magical AI, and Zapier MCP. An unusually relevant mix of control systems, identity-risk thinking, and connector infrastructure.

Vitor Balocco

Zapier Agents technical lead, Stedi, ESLint TSC. Runtime and tooling expert who built direct MCP attack experience. Strong security practitioner, but not a conventional career cybersecurity founder.

The preassembled pod

They brought a working Zapier Agents/MCP group and adjacent specialists, including agent-engineering and design leaders, rather than assembling a new team around a deck. The advisor/investor layer adds MCP creators, Anthropic and Cursor figures, dbt and Neon founders, identity/security leaders, and CISO network access. This compresses product learning, recruiting, credibility, partnerships, and customer introductions.

Funding arithmetic

Publicly announced rounds are $11M plus $30M, which equals $41M. Runlayer, Felicis, and Fortune say $42M total. No public Form D found under Runlayer or Anysource resolves the extra $1M. It could be an earlier instrument or rounding, but that is not proven.

08 / The bet

The capability layer becomes the durable asset

The narrow framing is “Okta for MCP.” The larger framing is a system of record for governed capabilities that survives model, client, and agent churn.

01

Clients fragment

Enterprises use five to twenty AI clients, not one. Claude, Cursor, Codex, browser tools, custom agents, and vendor suites coexist. Neutrality has value.

02

Actions converge

Useful agents eventually cross into tools, systems, credentials, and side effects. That boundary is a more stable control point than the conversation UI.

03

Control must accelerate

If the approved path is slower, employees route around it. Catalog, OAuth, dynamic search, and inherited access turn governance from a tax into a product.

04

Traces compound

Discovery reveals useful behavior; policy sanctions it; repeated runs reveal operating procedure; skills encode it; evals and review improve it.

05

Knowledge stays owned

The model is rented. The company's maintained job definition, context, identity, integrations, approvals, and learned skill should remain company property.

06

Control plane expands

A gateway can become inventory, IAM, security, runtime, spend, ROI, skill registry, and agent factory. Each layer makes replacement harder if the data model is coherent.

The flywheel they are trying to create

shadow usage -> discovery and inventory -> approved catalog and connector -> identity + policy + audit -> repeated human workflows -> reusable skill / agent -> trace + eval + improvement -> more sanctioned adoption -> more usage data and expansion
Non-obvious insight

The reusable unit is not “the agent.” It is an identity-bound capability with a prompt contract, tool ceiling, credentials, context, approval rules, execution history, and maintenance loop. Any client or runtime can invoke it. Owning this layer could matter more than owning the current chat surface.

09 / Competition

A crowded stack, with bundling as the real threat

Runlayer competes across several markets because its platform spans them. The nearest startup is not necessarily the greatest strategic threat.

ArenaExamplesWhat they can win onRunlayer response
MCP gateway/controlMintMCP, Obot, TrueFoundry, Webrix, CData Connect AI, Docker MCP Gateway, Kong, Solo.ioFocused gateway economics, open infrastructure, existing API-gateway footprintBroader endpoint discovery, identity, native agents, skills, rollout, and client neutrality
Tool/connectivity platformsComposio, Arcade, Workato, Zapier, CDataConnector breadth, developer adoption, action reliabilityGovernance and enterprise deployment wrapped around connectivity
Agent identity/securityOkta, Noma, Zenity, WitnessAI, Oasis, Astrix/Cisco, 1PasswordInstalled base, identity authority, secrets, posture and risk distributionOwn the action path and adoption experience, integrate rather than replace IdP/vault
Cloud control/runtimeMicrosoft Agent 365, AWS AgentCore, Google Cloud, CloudflareBundled runtime, infrastructure, procurement, data gravityCross-cloud, cross-model, cross-client neutrality plus customer hosting
Enterprise suitesServiceNow AI Control Tower, Salesforce Agentforce, MicrosoftWorkflow system of record, incumbent enterprise distribution, bundled governanceFaster horizontal enablement across systems and preferred user tools
Employee agent buildersGlean, Dust, Gumloop, Workato, Zapier, Salesforce, MicrosoftEnd-user experience, knowledge retrieval, templates, workflow depthProvide builder plus governed connector/capability foundation
DIYAPI gateway + IdP + OPA/Cedar + vault + SIEM + MDM + frameworkMaximum control, existing team expertise, lower license spendFaster rollout, maintenance, coverage, and organizational adoption

Threat ranking

  1. Microsoft / Okta / AWS / ServiceNow: most dangerous because procurement and control can be bundled into installed platforms.
  2. Native model and client vendors: can make gateway and policy features default, especially within their own surfaces.
  3. Direct MCP control startups: closest feature overlap and pricing pressure, but equally exposed to bundling.
  4. Agent builders and connector platforms: can move upward into governance once they own repeated workflow usage.
  5. Internal platform teams: remain the alternative when control requirements or economics justify assembly.

Runlayer's strongest defense is not “more security features.” It is becoming the neutral adopted layer across otherwise competing ecosystems, then owning the inventory, capability graph, policy, trace, and improvement loop.

10 / Claim audit

What to believe, discount, and ask next

Claim or impressionVerdictReason
“Broad, shipped enterprise platform”BelievePublic CLI/SDK code, docs, deployment architecture, releases, and detailed cases support it
“18,000 integrations”Discount wordingLikely indexed MCP catalog; historical language moved between connectors and MCP servers, while current material separately references about 200 prebuilt connectors
“Complete visibility / every agent”BoundedOnly routed traffic and supported endpoints/hooks are visible; unmanaged and cloud paths can escape
“ToolGuard performance”UnvalidatedExistence is real; accuracy and latency are self-reported with no public independent benchmark
“Tamper-proof audit”Ask howPublic docs do not demonstrate WORM/Object Lock, hash chains, or signed checkpoints
“Self-healing / improving agents”Real directionTrace-to-skill and eval mechanisms exist; production reliability outcomes are not independently shown
“100% adoption”UndefinedCould mean enabled, onboarded, or active. No cohort/frequency definition supplied
“Customer logos prove deployment”FalsePagerDuty is logo-only; Xcel/b.well are validators; Rippling was a failed trial; depth varies widely
“$42M raised”UnresolvedAnnounced $11M + $30M rounds total $41M; extra $1M is not publicly explained
“HIPAA/GDPR compliant”Contract-specificMarketing labels are not a healthcare certification; scope, BAA, deployment, and controls need account diligence
“Runlayer founded in August 2025”SimplifiedDomain and legal formation began March-May; full-time operating start may still be August
“AAIF founding member”NuanceFounding supporter/Gold sponsor, not MCP creator or sole foundation architect

Twenty diligence questions

1. How many customer-native agents run weekly, versus humans making connector calls?

2. What percentage of enabled users are weekly active?

3. What are autonomous job success, intervention, and retry rates?

4. What hard business outcomes have customers measured?

5. What FDE hours and gross margin are required for 1,000 seats?

6. Which account logos are paid production, paid pilot, free trial, or design partner?

7. What content leaves endpoints in each Watch and Sessions mode?

8. What are default retention, deletion, backup, residency, and legal-hold rules?

9. Is customer traffic used for Guard training by default, and can customers opt out?

10. Where do Guard models execute in hosted, self-hosted, and air-gapped deployments?

11. What independent red-team or benchmark evidence exists?

12. How is “tamper-proof” audit immutability implemented?

13. Why is agent token audience/resource enforcement off by default?

14. How are approvals expired, deduplicated, and protected from replay?

15. Which hooks are fail-closed by version, and which are observational?

16. What is the default sandbox backend and tenant-isolation test suite?

17. How is OAuth grant selection handled when several users have grants?

18. Is the runtime derived from OpenCode, and who owns patch cadence?

19. What is revenue mix across gateway, Watch, Guard, and native agents?

20. What is net retention after the first annual contract?

Legal and commercial limits

Public terms support custom order forms, possible usage billing, auto-renewal, and up to a 5% renewal increase absent different order terms. Beta services can be withdrawn. Security commitments include encryption, testing, log and recovery targets, but customer-hosted customers must apply patches and customers retain responsibility for backup/archive/retention of their data. The website terms say feature, security, compliance, and future descriptions are informational and non-contractual. Trust reports are gated.

Use the MSA, Security Addendum, DPA, and Trust Center as diligence sources, not the homepage badges alone.

11 / Decawork implications

Steal the learning, not the surface area

The overlap is now substantial. That is category validation, not a reason to force artificial differentiation. The best lessons concern wedge, buyer, rollout, durable ownership, and honest measurement.

  1. Land on a useful existing agent. A creator with repeat usage and a second user proves the job before IT buys infrastructure. Start from demonstrated pull, then promote the agent into company operations.
  2. Make the diagnostic show useful work and risk together. Inventory agents, skills, credentials, schedules, owners, clients, and successful repeated workflows. Do not reduce discovery to a scary count of shadow tools.
  3. Target a buyer who owns both adoption and control. CISO approval without an AI operator produces shelfware. An AI champion without IT authority produces shadow infrastructure. The dual mandate closes.
  4. Observe before enforcing. A defined visibility phase identifies real usage, stakeholders, and permission boundaries and avoids breaking the power users creating internal pull.
  5. Embed deeply, but productize aggressively. FDE work is priceless early discovery. Track each custom connector, identity exception, policy, and training intervention until repeated work becomes standard product.
  6. Own the maintained job, not the current interface. Claude Code, Codex, Cursor, Slack, and future agents are work surfaces. Durable value is job definition, context, credentials, approvals, schedule, execution, recovery, and operator responsibility.
  7. Measure work completed without the creator. Second-user adoption, scheduled-run reliability, completed jobs, intervention rate, recovery time, and business outcome are stronger than seats and tool calls.
  8. Protect the pilot. Agree on price range, conversion date, success criteria, source access, roadmap disclosure, ownership, and clean termination before embedding for months.
  9. Keep an evidence-grade customer ledger. Separate paid production, paid pilot, free trial, design partner, investor/advisor, ecosystem partner, logo permission, active-user depth, and actual autonomous runtime.
  10. Do not underread Runlayer. It is no longer merely MCP security. It is moving toward the same company-agent operating layer. Decawork can coexist in a large market while learning from a formidable adjacent execution.

The opening

Runlayer's strongest proof is governed access from many work surfaces. Decawork's strongest long-term promise is to take operating responsibility for the job: deploy, maintain, recover, and keep it running after the creator leaves. Treat that as an operational truth to prove, not a slogan to differentiate prematurely.

The warning

Runlayer shows how quickly a gateway wedge expands into agents, identity, runtime, skills, and ROI. Surface-level positioning will converge. Defensibility must come from customer-owned jobs, reliable operations, accumulated maintenance knowledge, and measurable completed outcomes.

Two-minute next action

Add these five fields to Decawork's active design-partner ledger: existing useful agent, second user, IT/security owner, success metric based on completed work, and dated paid conversion decision.

12 / Source ledger and methodology

How this reconstruction was made

Sources were triangulated across official pages, technical artifacts, customer-side posts, independent reporting, archived pages, legal terms, job descriptions, registries, forums, and ecosystem evidence. Official claims are not treated as independent proof.

Product and technical
Customers and GTM
History, founders, funding, legal
Competitive reference points
Research limits

No private customer contracts, board materials, revenue data, SOC 2 report, internal benchmarks, product telemetry, or source repositories were available. LinkedIn posts and company metrics are labeled as self-reported or inference where relevant. “All information possible” here means an exhaustive public-source review at the stated cutoff, not unknowable private facts.