Stacklok
Stacklok provides an enterprise-grade, Kubernetes-native Model Context Protocol platform that enables Fortune 500 and Global 2000 organizations to securely connect AI agents and LLMs to internal tools, APIs, and data, distributed via enterprise subscriptions built on the open source ToolHive project.
- Company typePrivate
- Founded2023
- HeadquartersSeattle, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Stacklok does
Stacklok, Inc. is a Seattle-based, venture-backed software company founded in 2023 that builds an enterprise-grade Model Context Protocol (MCP) platform for securely connecting AI agents and large language models to internal tools, APIs, and data sources. The commercial Stacklok Enterprise MCP Platform is a Kubernetes-native distribution of the open source ToolHive project (Apache 2.0, co-maintained with Red Hat) and comprises four integrated components: a Registry of curated MCP servers with provenance verification, a Runtime for Kubernetes-based deployment with OpenTelemetry and Prometheus instrumentation, a Gateway providing a single authenticated and audited endpoint, and a Portal for admin and end-user access. The MCP Optimizer sub-product reduces token usage by 60-85% per request through on-demand semantic tool discovery.
The company monetizes via annual subscription licensing for the Enterprise MCP Platform, supplemented by time-and-materials or fixed-fee implementation services and tiered support, all governed by Order Forms. Distribution combines an enterprise direct-sales motion with forward-deployed engineers against an open source product-led growth motion through ToolHive downloads. Its revenue model is enterprise subscription recurring. The commercial platform integrates with Entra ID, Okta, Google, and LDAP for identity; New Relic, Grafana, Splunk, and Datadog for observability; and HashiCorp Vault and Kubernetes Secrets for secrets management.
Stacklok serves Fortune 500 and Global 2000 enterprises across financial services, software/technology, manufacturing, retail, and telecommunications, addressing platform engineering, AI enablement, and security teams. Named public customers include a Fortune 500 financial services firm that deployed 100+ MCP servers with 500+ weekly users and improved Cursor acceptance rates from 40% to over 80% in under three months, a Global 2000 software category leader with 500+ developers that achieved 85%+ token reduction, and a Fortune 500 hardware manufacturer that adopted a centrally managed MCP registry. Strategic partnerships include Red Hat as a ToolHive co-maintainer, and ecosystem positioning through the SUSE Agentic AI Partner Ecosystem and the SUSE AI Factory with NVIDIA.
Stacklok firmographics
Firmographics- Name
- Stacklok
- Legal name
- Stacklok, Inc.
- Website
- https://stacklok.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Stacklok provides an enterprise-grade, Kubernetes-native Model Context Protocol platform that enables Fortune 500 and Global 2000 organizations to securely connect AI agents and LLMs to internal tools, APIs, and data, distributed via enterprise subscriptions built on the open source ToolHive project.
- Ownership category
- akta.pro rank
Stacklok industry classification
Industry- Product category
- Enterprise AI Agent Infrastructure (MCP Platform)
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)
Keywords
Where Stacklok is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Stacklok business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise MCP Platform Subscription: Subscription-based licensing for the Enterprise MCP Platform during a defined Subscription Term. Customers execute Order Forms specifying platform subscription, Services, Fees, and Subscription Term. The platform is licensed for customer's internal business purposes with limited, non-exclusive, non-transferable rights.
- Implementation Services: Configuration, deployment, enablement, and training services provided on a time-and-materials or fixed-fee basis as described in Statements of Work. Distinct from the Platform license grant.
- Support Services: Technical support and maintenance services provided according to support tiers specified in Order Forms, with response times and service levels defined by tier.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform subscription with support tiers |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels11 records
Stacklok product offering
Product offeringCore offering
Stacklok provides an enterprise-grade Model Context Protocol (MCP) platform — a hardened, Kubernetes-native software stack that enables organizations to securely connect AI agents and LLMs to internal tools, APIs, and data sources behind the corporate firewall. The commercial Stacklok Enterprise MCP Platform is built on the Apache 2.0 open source ToolHive project (co-maintained with Red Hat) and adds enterprise capabilities including a curated Registry of trusted MCP servers, a Kubernetes-native Runtime with OpenTelemetry integration, a Gateway providing centralized authentication and auditing, a Portal UI, and the MCP Optimizer for 60–85% token usage reduction.
Product overview
Stacklok offers the Stacklok Enterprise MCP Platform as its primary commercial product — a hardened, Kubernetes-native MCP platform enabling enterprises to securely run AI agents and connect to MCP servers in their private cloud. The platform comprises four integrated components: Registry (central catalog of trusted MCP servers with provenance verification and security controls), Runtime (Kubernetes-native deployment and management with OpenTelemetry and Prometheus integration), Gateway (single endpoint for centralized authentication, authorization, auditing, and IdP integration), and Portal (admin control panel and end-user interface for discovery and deployment). The open source ToolHive (Apache 2.0, maintained by Stacklok and Red Hat) serves as the foundation — the Enterprise Platform is a hardened distribution of ToolHive with additional enterprise capabilities, forward-deployed engineers, and support. The MCP Optimizer sub-product, embedded in the gateway, provides semantic tool discovery reducing token usage by 60-85%. The separate open source Minder project provides software supply chain security and was donated to OpenSSF in October 2024.
Differentiator
Problem solved
Functional benefit
Products and services
- Stacklok Enterprise MCP Platform Hardened, Kubernetes-native MCP platform for enterprises that need to securely run AI agents and connect to MCP servers in their private cloud behind the firewall. Comprises four integrated components — Registry (curated catalog of trusted MCP servers with provenance verification), Runtime (Kubernetes-native deployment with OpenTelemetry and Prometheus), Gateway (centralized authentication, authorization, and auditing), and Portal (admin and end-user UI) — integrated with enterprise IdPs (Entra ID, Okta, Google, LDAP), observability stacks (OTEL, Prometheus, New Relic, Grafana, Splunk, Datadog), and secrets managers (HashiCorp Vault, Kubernetes Secrets). Targeted at Fortune 500 / Global 2000 platform engineering, AI enablement, and security teams in regulated industries.
- ToolHive Apache 2.0 licensed open source MCP platform maintained by Stacklok and Red Hat with contributors from dozens of companies. Provides registry, Kubernetes runtime, gateway, and portal components. Available as a downloadable desktop app and CLI for individual developers on macOS, Windows, and Linux. Used by enterprises to pilot larger-scale self-hosted MCP deployments and run MCP infrastructure in production with IdP and observability integrations. The Stacklok Enterprise MCP Platform is a hardened distribution of ToolHive with additional enterprise capabilities and support.
- MCP Optimizer Token-optimization sub-product embedded in the vMCP gateway that uses hybrid semantic and keyword search to surface only relevant tools from the registry on demand, instead of sending the full tool manifest to the LLM with every request. Reduces token usage by 60–85% per request, improving model performance and lowering LLM costs. Deployed once at the platform level and applies savings across all users and agents.
Quantifiable outcome
- Fortune 500 FSI Cursor acceptance rates improved from 40% to over 80% in under three months
- +4 more outcomes
Companies that use Stacklok
Customer profileNamed customers3 records
Segments7 records
Ideal customer profiles2 records
Stacklok technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration19 records
AI capability9 records
Feature10 records
Stacklok partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered flagship and core.
- NVIDIAflagshipSUSE launched SUSE AI Factory with NVIDIA as a unified enterprise AI software stack. While this is SUSE's partnership with NVIDIA, Stacklok is integrated into the broader SUSE AI ecosystem, positioning Stacklok's MCP governance within NVIDIA-powered AI infrastructure.
- SUSEcoreSUSE partnered with Stacklok as part of its Agentic AI Partner Ecosystem to enable secure agentic AI operations for infrastructure management through Model Context Protocol (MCP) integration across SUSE's portfolio. Stacklok is integrated into SUSE's Agentic AI Partner Ecosystem alongside Fsas Technologies, n8n, and Revenium.
- Red HatcoreToolHive, Stacklok's open source MCP platform, is maintained by both Stacklok and Red Hat. Red Hat provides external maintainers for the project alongside Stacklok's core team. ToolHive has contributors from dozens of companies beyond Red Hat.
- OktacoreStacklok integrates with Okta for SSO (Single Sign-On) enabling enterprise workforce authentication. Customers use Okta integration for federated token exchange and identity management for MCP access.
- Entra ID (Microsoft)coreStacklok integrates with Entra ID (Microsoft's identity platform) for IdP integration, enabling OAuth/OIDC authentication flows and federated token exchange for enterprise MCP deployments.
Scale indicators8 records
Recent moves2 records
Expansion highlights5 records
Stacklok competitors and assessment
Company assessmentDirect peers
- Solo.io: Solo.io builds kgateway and AgentGateway for Kubernetes-native AI agent traffic management and MCP routing. They are the most direct technical competitor to Stacklok in the enterprise MCP gateway/runtime layer, targeting the same platform engineering buyer with similar Kubernetes-native architecture.
- Docker: Docker ships MCP Toolkit and MCP Catalog as part of its container platform, directly competing with Stacklok's Registry and ToolHive offerings. Docker's massive developer install base and brand recognition make it a primary competitor for the open-source-led PLG motion in MCP tooling.
Broad incumbents
- Microsoft: Microsoft has built native MCP support into Copilot Studio and Azure AI Foundry, positioning itself as a broad incumbent offering bundled MCP governance inside its enterprise AI platform. Customers may prefer Microsoft's integrated stack over Stacklok's specialized control plane, especially in Microsoft-heavy enterprises.
- Anthropic: Anthropic created the Model Context Protocol and continues to extend its reference implementations. As the protocol steward, Anthropic could expand its own enterprise offerings to compete directly with Stacklok's governance, registry, and gateway capabilities, leveraging its direct relationship with Claude Code and Cursor users.
- Cloudflare: Cloudflare has launched MCP server hosting and AI agent infrastructure (Workers AI, AI Gateway) that competes with Stacklok's gateway and runtime offerings. Cloudflare's global edge network and zero-trust positioning appeal to enterprises seeking managed AI agent infrastructure without operational overhead.
Others
- HashiCorp: HashiCorp provides Vault (secrets management) and Terraform (infrastructure as code), both of which integrate with Stacklok today but could expand into adjacent AI agent governance capabilities. HashiCorp's enterprise sales reach and policy-as-code expertise (Sentinel) position it as a potential competitor or acquirer.
Regional players
- SUSE: SUSE is both a strategic partner (Agentic AI ecosystem) and a potential competitor through its SUSE AI Factory with NVIDIA stack. While the current relationship is cooperative, SUSE's enterprise Linux and Kubernetes distribution reach in EMEA gives it a regional platform to bundle MCP governance for its installed base.
Emerging players
- Lasso Security: Lasso Security is an emerging AI agent security platform focused on shadow AI governance, similar to Stacklok's positioning for MCP servers. Both target enterprise CISOs and security teams concerned about uncontrolled AI tool adoption, though Lasso focuses more broadly on LLM usage rather than MCP specifically.
- Portkey: Portkey provides an AI gateway with observability, governance, and cost controls for LLM applications — overlapping with Stacklok's gateway and MCP Optimizer value propositions. As an emerging player, Portkey focuses on the broader LLM routing layer but could expand into MCP-specific governance.
- Pulumi: Pulumi offers infrastructure-as-code with AI agent capabilities (Pulumi Copilot) and could expand into MCP governance for cloud infrastructure. Its developer-first posture and Kubernetes-native approach create partial overlap with Stacklok's platform engineering buyer persona.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Stacklok social profiles
Digital presenceStacklok financial estimates
Financial estimateRevenue estimate
Valuation estimate
Stacklok leadership team
Management profileNumber of profiles
Profiles3 records
Stacklok funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Stacklok M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Stacklok
What does Stacklok do?
Stacklok provides an enterprise-grade Model Context Protocol (MCP) platform — a hardened, Kubernetes-native software stack that enables organizations to securely connect AI agents and LLMs to internal tools, APIs, and data sources behind the corporate firewall. The commercial Stacklok Enterprise MCP Platform is built on the Apache 2.0 open source ToolHive project (co-maintained with Red Hat) and adds enterprise capabilities including a curated Registry of trusted MCP servers, a Kubernetes-native Runtime with OpenTelemetry integration, a Gateway providing centralized authentication and auditing, a Portal UI, and the MCP Optimizer for 60–85% token usage reduction.
Is Stacklok a public or private company?
Stacklok is a private company. It is classified as venture growth investor backed and is currently operating.
When was Stacklok founded?
Stacklok was founded in 2023. It employs 11 to 50 people.
Where is Stacklok based?
Stacklok is headquartered in Seattle, United States, in the North America region.
How does Stacklok make money?
Three revenue lines are on record. Enterprise MCP Platform Subscription is the primary driver. The others are implementation Services and support Services.
Who are Stacklok's main competitors?
Direct peers on record are Solo.io and Docker. Broad incumbents are Microsoft, Anthropic and Cloudflare. HashiCorp is listed as an others. SUSE is listed as a regional player. Emerging players are Lasso Security, Portkey and Pulumi.
Does Stacklok have an API?
Yes. ToolHive exposes a REST API for programmatic management of MCP servers, clients, registry, groups, secrets, and configuration. Available via docs.stacklok.com/toolhive/reference/api. The API supports CRUD operations on MCP workloads, secrets management, client registration, group management, and runtime control. Language-specific protocol schemes (uvx for Python, npx for Node.js, go for Go) enable running MCP servers from package managers directly. Developer documentation is at docs.stacklok.com/toolhive/reference/api.
What industry is Stacklok in?
Stacklok's product category is Enterprise AI Agent Infrastructure (MCP Platform). Its primary akta.pro industry code is BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 5415 and its SIC code is 7372.