Dossier · Private startup · 2 independent sources
Runlayer
Last updated: Jul 31, 2026
Runlayer is an enterprise AI control plane that gives organizations a governed path to deploy agents, connect MCP servers and other tools, enforce identity-aware policy, detect runtime threats, and audit AI activity. Its current product spans MCP gateway, shadow-AI discovery, runtime security, reusable skills, and hosted agent execution.
Visit WebsiteCompany Overview
Runlayer is building a control plane for enterprise adoption of agentic AI. The platform sits between AI clients and the tools, MCP servers, APIs, and internal systems that agents use. Its MCP Gateway can register existing servers, deploy custom MCP servers, and route requests through OAuth or session checks, identity-aware policy, security scanning, analytics, and audit logging. Runlayer also presents a catalog for approved capabilities, supports reusable skills and plugins, and offers Runlayer Agents for hosted or background work. This is a more expansive proposition than a simple MCP reverse proxy: the company is trying to make approved agent access discoverable and usable for employees while retaining centralized control for platform, IT, and security teams.
The customer problem is the gap between rapid AI experimentation and enterprise-grade control. Employees can accumulate unsanctioned MCP servers, client configurations, plugins, and agent workflows faster than security teams can review them. Runlayer's Watch product is positioned for shadow-AI discovery and response; its policy layer scopes access by identities, groups, roles, agent accounts, clients, connectors, tools, resources, network conditions, and runtime context; and its activity records are intended to show who or what invoked a tool, what policy and security checks occurred, and the outcome. Those controls address practical governance needs in engineering, IT, operations, security, and business teams, including least privilege, approval workflows, migration of unmanaged usage, and evidence for incident or compliance review.
Public company materials indicate early commercial validation but do not establish revenue, retention, deployment scale, or the effectiveness of security detections. The official platform page displays customer logos including Gusto, Instacart, Lemonade, Opendoor, PagerDuty, dbt Labs, and Jane, while the company describes support for more than 300 AI clients. Runlayer also says it collaborated with Anthropic on MCP Tunnels, a connection pattern for reaching systems behind a firewall. In June 2026, Runlayer announced a $30 million Series A from Felicis and Khosla Ventures, bringing stated total funding to $42 million. These are meaningful signals of financing and customer interest, but diligence should distinguish logo-based or self-reported adoption from contracted recurring revenue and independently referenceable production usage.
The competitive field is broad and increasingly well funded. Runlayer competes with purpose-built MCP gateways and agent-security vendors, but also with cloud platforms, identity and privileged-access products, AI gateways, observability tools, and internal platform teams. Its potential edge is the combination of enablement and control: a catalog, gateway, identity-aware policy, runtime threat checks, shadow-AI discovery, auditability, and hosted agents in one workflow, while allowing employees to keep using clients such as Claude Code, Cursor, ChatGPT, Codex, and GitHub Copilot. That breadth may improve adoption, but it also creates product-scope, integration, and positioning risk. The company must show that a unified control plane is materially easier and safer than assembling native cloud controls, an identity provider, an AI gateway, and security monitoring.
Runlayer has credible dual-use adjacency because the core control problem is not industry-specific: autonomous software that can read data or take actions needs scoped identity, policy enforcement, runtime monitoring, and forensic records. Those capabilities could support defense contractors, government technology teams, and critical-infrastructure operators that adopt commercial agents. The public evidence reviewed here does not establish defense contracts, classified deployments, or operational military use, so the defense case remains a strategic applicability assessment rather than a traction claim. The most important diligence questions are detection precision and latency, handling of sensitive prompts and tool outputs, tenant isolation, private or controlled deployment options, coverage beyond MCP, resilience under adversarial activity, and the durability of the company's position as agent protocols and platform-native controls evolve.
Dual-Use Assessment
Runlayer's central capabilities—identity-scoped agent access, policy enforcement, runtime threat checks, shadow-AI discovery, and auditable tool execution—have substantive applicability to defense, government, and critical-infrastructure environments that use commercial AI agents. Public sources do not verify defense customers, classified work, or military deployments, so the dual-use case is based on capability transfer rather than claimed defense traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Runlayer has credible strategic fit with an AI-infrastructure and cybersecurity thesis: it addresses a concrete control gap created by enterprise agent adoption, has a product surface broader than a basic MCP proxy, lists recognizable enterprise users, and announced a $30M Series A from Felicis and Khosla Ventures in June 2026. The evidence supports priority attention, not an investment recommendation. Diligence should focus on recurring revenue and retention, customer production depth, security outcomes, gross margins for hosted capabilities, competitive displacement, and whether the platform remains relevant if MCP or cloud-native agent controls change.
Strategic Value to U.S.-Israel Alliance
Runlayer is strategically relevant as a potential control point between autonomous software and enterprise systems. A neutral, cross-client layer that binds identity, authorization, runtime security, and audit evidence to tool calls could help organizations adopt agents without granting unmanaged standing access. That architecture has resilience and national-security relevance when applied to sensitive operational environments, but the public record currently supports capability adjacency rather than verified defense deployment.
Key Technologies
- MCP gateway with server registration and managed custom MCP hosting
- Identity- and context-aware policy for users, agents, clients, tools, and resources
- Runtime threat detection and security scanning for agent tool calls
- Shadow-AI discovery for MCP servers, skills, plugins, and client configurations
- OAuth, session validation, and machine or agent account controls
- Activity tracing, audit logging, analytics, and usage or ROI visibility
- Hosted background agents with governed skills, plugins, and credentials
Use Cases & Applications
- Centralizing approved MCP access for engineering and business AI clients
- Discovering and remediating unsanctioned MCP servers, plugins, and agent configurations
- Applying least-privilege policies to agent access at tool, resource, identity, and runtime levels
- Scanning agent inputs and outputs for prompt injection, tool poisoning, and data-exfiltration patterns
- Auditing AI-assisted access to internal APIs, databases, telemetry, and enterprise content
- Running recurring background agents with controlled identities and approved capabilities
- Providing governed agent access for regulated, government, defense, and critical-infrastructure workflows
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 9 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Runlayer Series A announcement Official June 2026 announcement of a $30M Series A from Felicis and Khosla Ventures, stated total funding of $42M, and the company's broader AI control-plane positioning.
- Runlayer platform overview Official overview of the control plane, MCP gateway, hosted agents, shadow-AI discovery, observability, runtime security, policy, catalog, and displayed customer logos.
- Runlayer MCP Gateway Official product detail covering identity-aware policy, OAuth and session checks, security scans, audit logging, analytics, custom MCP hosting, and support for many AI clients.
- About Runlayer Official company and team page identifying founders Andy Berman, Tal Peretz, and Vitor Balocco and describing the company's enterprise agent-control mission.
- Runlayer and Anthropic MCP Tunnels Official account of collaboration around MCP Tunnels for connecting Anthropic clients to systems behind a firewall.
- Runlayer LinkedIn company profile Public company profile listing New York headquarters, 11-50 employees, and a New York and San Francisco footprint.
- MCP AI agent security startup Runlayer launches with 8 unicorns, $11M from Khosla's Keith Rabois and Felicis Official TechCrunch launch announcement with funding details, customer confirmations (Instacart, Gusto, dbt Labs, Opendoor), founding team background, and Keith Rabois quote.
- Runlayer Emerges from Stealth With $11M to Secure the MCP Era Detailed technical overview of MCP vulnerabilities (prompt injection, unauthorized access), Runlayer's threat detection architecture, founding team expertise (Tal Peretz's Air Force background, Vitor Balocco's Zapier role), and advisor David Soria Parra.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.