Runlayer
Runlayer is an enterprise AI control plane for MCPs, skills, and agents, providing threat detection, identity-enforced permissions, audit logging, and a curated MCP catalog to Fortune 500s and AI-native companies, generating revenue via quote-based enterprise subscriptions.
- Company typePrivate
- Founded2025
- HeadquartersNew York, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Runlayer does
Runlayer (legally Anysource, Inc.) is a Delaware-incorporated, New York-headquartered enterprise software company founded in 2025 that builds an AI control plane for the Model Context Protocol (MCP) ecosystem. The platform sits between AI clients (Cursor, Claude Code, ChatGPT, VS Code, GitHub Copilot, Codex, Windsurf, and others) and MCP servers (Postman, Okta, GitHub, Slack, Snowflake, Box, and 18,000+ others), providing a managed gateway with custom MCP-specific threat detection (ToolGuard and AgentGuard), fine-grained permissions integrated with enterprise identity providers, a private AI registry and curated MCP catalog, MDM-deployed shadow-MCP discovery and enforcement, and tamper-proof audit logging with SIEM export. The product is deployable as Runlayer cloud or self-hosted inside a customer VPC and is certified for SOC 2 Type II, HIPAA, GDPR, and AARM Extended Conformance (R1-R9). Runlayer employs an enterprise field-sales motion with quote-based pricing accessed via a Book a Demo flow that qualifies prospects by company size, and augments direct sales with embedded distribution partnerships (Cursor Hooks, Box Integrations Center) and ecosystem positioning as a Gold-tier founding member of the Linux Foundation's Agentic AI Foundation. Customers include over 12 unicorns and public companies such as Instacart, Gusto, Opendoor, dbt Labs, AngelList, Rippling, Lemonade, Xcel Energy, Decagon, and bwell, plus an unnamed Fortune 500 bank monitoring AI usage across 100,000 employees and 200,000 devices.
Runlayer firmographics
Firmographics- Name
- Runlayer
- Legal name
- Anysource, Inc.
- Website
- https://runlayer.com
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Runlayer is an enterprise AI control plane for MCPs, skills, and agents, providing threat detection, identity-enforced permissions, audit logging, and a curated MCP catalog to Fortune 500s and AI-native companies, generating revenue via quote-based enterprise subscriptions.
- Ownership category
- akta.pro rank
Runlayer industry classification
Industry- Product category
- AI Security & Governance Software
- NAICS
- Computer Systems Design Services (541512), Computer Systems Design and Related Services (5415)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industries
- Model Hosting, Serving & Inference Platforms (HDAAACAB), Model Deployment, Serving & Inference Platforms (HDAAABAF), Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
Keywords
Where Runlayer is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Runlayer business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Enterprise SaaS Subscription (inferred): Runlayer sells an enterprise SaaS platform for MCP governance, security, and observability. Pricing is quote-based, accessed through a 'Book a Demo' sales motion with company-size qualification (1-250, 250-1,000, 1,000-5,000, 5,000+). Customers include Fortune 500 enterprises, public companies, and high-growth unicorns (12+ unicorns, 8 within the first four months). Land-and-expand is supported via connectors, agents, skills, and plugins added to workspaces.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise pricing |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
Runlayer product offering
Product offeringCore offering
Runlayer (Anysource, Inc.) sells an enterprise AI control plane that sits between AI clients (Cursor, Claude Code, ChatGPT, VS Code, GitHub Copilot, Codex, Windsurf, etc.) and Model Context Protocol (MCP) servers. The platform provides custom MCP-aware threat detection, fine-grained permissions integrated with enterprise identity providers, full audit logging with SIEM export, shadow-MCP discovery and blocking, and a curated private MCP catalog. It is sold as a SaaS subscription (with a self-hosted VPC deployment option) to enterprise security, IT, and engineering teams.
Product overview
Runlayer is a single unified enterprise AI control plane platform, not a modular assembly — its core offering is a centralized governance, observability, and compliance layer for MCPs, skills, and AI agents across the enterprise. The Runlayer Platform anchors the suite and is composed of tightly integrated components including ToolGuard and AgentGuard (the AI security suite protecting against prompt injection, tool poisoning, and credential exfiltration), MCP Watch (shadow MCP discovery), Enforce (shadow MCP blocking), Runlayer Deploy (deployment management), Audit Logs (tamper-proof logging with SIEM export), Skills (composable modular resources with OAuth), Plugins (bundles of tools/prompts/skills), Subagents (delegated child agents), Custom MCP Hosting, No-Code MCP Building, and Runlayer Agents (the AI agent framework). The platform is accessed via the Runlayer MCP server (a Model Context Protocol interface for audit log tools, policy CRUD, and server management) and the Runlayer Plugin (for distribution to clients like Cursor, Claude, ChatGPT). Together these form the golden path for enterprise AI adoption, securing both the AI clients (Cursor, Claude Code, ChatGPT, Codex, etc.) and the MCP servers (Postman, Okta, GitHub, Slack, Snowflake, Box, etc.) they connect to.
Differentiator
Problem solved
Functional benefit
Products and services
- Runlayer Platform Unified enterprise SaaS platform that sits between AI clients (Cursor, Claude Code, ChatGPT, VS Code, GitHub Copilot, Codex, Windsurf, etc.) and Model Context Protocol (MCP) servers, providing custom threat detection, fine-grained identity-bound permissions, audit logging with SIEM export, shadow-MCP discovery and enforcement, a private curated MCP catalog, no-code MCP composition, and a deployable-as-cloud or self-hosted VPC runtime. Sold to enterprise security, IT, and engineering teams.
- Runlayer ToolGuard Multi-tier AI security suite that scans MCP tool-call inputs and outputs to detect prompt injection, tool poisoning, credential exfiltration, and shadow-MCP threats; provides PII masking across tool inputs, outputs, and embedded resources, with custom detectors trained on continuously updated MCP-specific attack patterns.
- Runlayer AgentGuard Runtime security model for autonomous AI agents that operate with root-level access to MCP servers, skills, and plugins; detects and blocks agent-specific attack vectors including prompt injection, credential exfiltration, and tool poisoning at the agent execution layer.
- Runlayer Agents Enterprise AI agent framework supporting LLM-powered agents from Anthropic, OpenAI, and Google, with subagents that inherit parent connectors and tools, persistent agent memory (SQLite), human-in-the-loop Notify-Only approvals, scheduled and webhook-triggered runs, Slack triggers, and shareable artifact publishing.
- Runlayer MCP (Platform API) Model Context Protocol server and Platform API from Runlayer exposing audit log tools (including bulk export_audit_logs to JSON/CSV), governance tools for creating/updating/deleting policies, and management of connectors and agents, accessible from any MCP-compatible AI client and via the runlayer CLI (uvx runlayer logs).
Quantifiable outcome
- Signed over 12 unicorn customers by Series A (June 2026), up from 8 unicorns in the first four months of operation
- +5 more outcomes
Companies that use Runlayer
Customer profileNamed customers11 records
Segments4 records
Ideal customer profiles2 records
Runlayer technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration92 records
AI capability10 records
Feature7 records
Runlayer partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered flagship and core.
- AnthropicflagshipRunlayer and Anthropic collaborated on MCP Tunnels, which invert the connection direction so the customer's network reaches out to Anthropic instead of exposing inbound ports, removing the security wall that blocks Claude from accessing internal systems like Jira, databases, and telemetry. Anthropic co-creator of MCP, David Soria Parra, is also a Runlayer advisor.
- AARM (Agentic AI Risk Mitigation)coreRunlayer achieves AARM Extended Conformance (R1-R9), partnering with the Vanta-backed open specification to define how enterprises secure AI agents at runtime.
- 1PasswordcoreRunlayer + 1Password integration brings secure, auditable credential access to autonomous AI agents. The integration lets enterprises inject secrets from 1Password vaults into agent sessions managed by Runlayer, replacing plaintext .env files with centralized governance, real-time retrieval, and full audit logging across human and non-human identities.
- BoxflagshipBi-directional partnership. The official Box MCP server is available in the Runlayer marketplace, and Runlayer is listed as an official integration in the Box Integrations Center. Box customers can connect AI agents (Claude, ChatGPT, Cursor, any MCP client) to Box content with identity enforcement, audit logging, and threat detection while preserving existing Box access controls. Targeted at regulated industries (financial services, healthcare, life sciences, legal).
- CursorflagshipRunlayer is an official launch partner for Cursor Hooks. The integration allows security teams to observe, control, and extend MCP tool calls inside Cursor through Runlayer. Any MCP server not managed by Runlayer is blocked, while approved servers run with one-click install. Combined with MDM (Intune, Jamf, Rippling, Kandji), enterprise-wide enforcement is achieved via a single deployment script.
- Linux Foundation (Agentic AI Foundation / AAIF)flagshipRunlayer is a Gold-tier founding member of the Linux Foundation's Agentic AI Foundation (AAIF) alongside Anthropic, OpenAI, Google, AWS, Bloomberg, and Microsoft. AAIF now oversees the Model Context Protocol (MCP), Block's goose framework, and OpenAI's AGENTS.md, positioning Runlayer to curate and steer the future of MCP-based enterprise AI.
- OktacoreOkta is shown as a supported MCP server in the Runlayer homepage logo list and is integrated as an identity provider for SSO, SCIM, and group sync in Runlayer's permissioning model.
- Microsoft SentinelcoreMicrosoft Sentinel is listed as a native integration in the Runlayer enterprise stack section of the homepage, enabling Runlayer audit logs to feed enterprise SIEM workflows.
- DatadogcoreDatadog is shown as a native integration in the Runlayer enterprise stack section of the homepage for observability of MCP tool calls and security events.
- SplunkcoreSplunk is shown as a native integration in the Runlayer enterprise stack section of the homepage; Runlayer SIEM export supports Splunk via S3 ingestion pattern.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Runlayer competitors and assessment
Company assessmentEmerging players
- Reco: Reco is a SaaS security posture management platform with growing capabilities in AI-app governance. It is comparable to Runlayer in addressing enterprise AI governance and shadow-discovery use cases, though from a broader SaaS-security angle.
- HiddenLayer: HiddenLayer provides AI-application security including model and AI-agent protection. It competes with Runlayer's ToolGuard and AgentGuard modules in the AI threat-detection category, with a slightly different go-to-market focus on model security.
- Grip Security: Grip Security focuses on SaaS security posture management and shadow SaaS/AI discovery. It addresses similar shadow-AI governance pain points as Runlayer but at the SaaS-app layer rather than the MCP protocol layer.
- Prompt Armor: Prompt Armor is an emerging AI security startup specializing in prompt-injection protection and data-loss prevention for LLM applications. It competes with Runlayer's Prompt Guard and ToolGuard threat-detection modules on a narrower threat-surface.
Direct peers
- Pillar Security: Pillar Security is an AI security platform focused on securing AI applications and agents throughout the SDLC. It is the closest direct peer to Runlayer in the AI-agent security and governance category, with overlapping positioning around agent risk management, prompt-injection protection, and enterprise AI controls.
- Lakera: Lakera provides LLM and AI-agent security guardrails (Gandalf), including prompt-injection detection and AI red-teaming. It is a direct competitor to Runlayer's ToolGuard on the threat-detection side of the MCP/agent security stack.
- Lasso Security: Lasso Security focuses on securing AI usage across the enterprise, including shadow AI discovery and AI data governance. It overlaps with Runlayer's MCP Watch and shadow-AI discovery capabilities.
- Astrix Security: Astrix Security specializes in securing third-party AI agents and non-human identities, addressing agent sprawl and over-provisioned access in enterprise environments. It competes directly with Runlayer's identity-forward MCP proxying and shadow MCP enforcement capabilities.
Broad incumbents
- Palo Alto Networks: Palo Alto Networks (Prisma AIRS / Cortex) is a broad cloud-security incumbent actively building AI and agent governance into its existing enterprise-security platform. It represents the most significant incumbent threat to Runlayer's standalone positioning due to its installed base and bundled pricing.
- Zscaler: Zscaler is a cloud-security incumbent expanding into AI workload protection and shadow-AI governance. Its SSE platform overlaps with Runlayer's positioning for enterprise buyers and represents a comparable broad-incumbent threat if it bundles agent governance into existing contracts.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat8 records
Key risks5 records
Key highlights6 records
Customer concentration
Runlayer social profiles
Digital presenceRunlayer compliance and trust
Trust signalCompliance4 records
Runlayer financial estimates
Financial estimateRevenue estimate
Valuation estimate
Runlayer leadership team
Management profileNumber of profiles
Profiles3 records
Runlayer funding detail
Funding detailFunding overview
Funding rounds2 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Runlayer M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Runlayer
What does Runlayer do?
Runlayer (Anysource, Inc.) sells an enterprise AI control plane that sits between AI clients (Cursor, Claude Code, ChatGPT, VS Code, GitHub Copilot, Codex, Windsurf, etc.) and Model Context Protocol (MCP) servers. The platform provides custom MCP-aware threat detection, fine-grained permissions integrated with enterprise identity providers, full audit logging with SIEM export, shadow-MCP discovery and blocking, and a curated private MCP catalog. It is sold as a SaaS subscription (with a self-hosted VPC deployment option) to enterprise security, IT, and engineering teams.
Is Runlayer a public or private company?
Runlayer is a private company. It is classified as venture growth investor backed and is currently operating.
When was Runlayer founded?
Runlayer was founded in 2025. It employs 11 to 50 people.
Where is Runlayer based?
Runlayer is headquartered in New York, United States, in the North America region.
How does Runlayer make money?
One revenue line is on record: enterprise SaaS Subscription (inferred).
Who are Runlayer's main competitors?
Emerging players on record are Reco, HiddenLayer, Grip Security and Prompt Armor. Direct peers are Pillar Security, Lakera, Lasso Security and Astrix Security. Broad incumbents are Palo Alto Networks and Zscaler.
Does Runlayer have an API?
Yes. Runlayer offers a Runlayer MCP server, a Platform API, and CLI tools (uvx runlayer logs). The Runlayer MCP exposes audit log tools including export_audit_logs for JSON/CSV exports, plus governance tools for creating/updating/deleting policies and managing connectors and agents. The CLI supports authentication, audit log querying, and AI Watch scanning. API keys can be scoped with the Deploy role for CI/CD pipelines. Webhook authorization supports API-key authentication for agent webhooks. Developer documentation is at docs.runlayer.com/platform-api.
What industry is Runlayer in?
Runlayer's product category is AI Security & Governance Software. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAAACAB, Model Hosting, Serving & Inference Platforms. Its NAICS code is 541512.