Breaking Runlayer raises $30M Series A Total disclosed funding reaches $42M Gusto rollout: 3,000+ workers in four weeks
Company profile / Enterprise AI

Runlayer Wants Your AI Agents Working - Just Not Running Wild

Employees were connecting AI to company systems faster than security teams could count the connections. Runlayer turned that mess into a control plane - and persuaded Gusto, Jane, Homebase and other large companies to let the agents in.

The first thing to understand about Runlayer is that it does not want to replace your favorite AI. It wants to stand behind it with a clipboard. When an employee asks Claude to pull a customer record, tells Cursor to inspect a repository or builds an agent that can update Jira, Runlayer sits between that agent and the company system. It checks identity and policy, scans the request, records the action and, when necessary, says no.

That sounds like classic enterprise plumbing because it is. The new wrinkle is the Model Context Protocol, or MCP, the open standard that lets AI applications connect to tools and data. MCP turned integrations into something agents could discover and use. It also multiplied the number of doors into company systems. Runlayer says its catalog covers more than 18,000 MCP servers and its platform works across more than 300 AI clients. A security team can ban the doors, ignore them, or install a lobby.

Runlayer is the lobby: part app store, part badge desk, part security camera. Employees get a catalog of approved connectors, skills and agents. IT gets single sign-on, provisioning and policy. Security gets runtime inspection and audit history. AI transformation leaders get adoption and spend data. The company calls this the “golden path” - the approved route should be easier than the workaround.

3K+Gusto knowledge workers covered
4Weeks to Gusto's full integration
84MCP servers managed there

The mess appeared before the market had a name

Runlayer's founders did not encounter MCP as outside observers. Andrew Berman had co-founded the baby-monitor company Nanit and the video-meeting startup Vowel. After Zapier acquired Vowel in 2024, he became Zapier's director of AI. Tal Peretz and Vitor Balocco were also building there. Peretz led work on Zapier MCP; Balocco was a staff AI engineer with a focus on MCP security. They watched a connective standard spread and saw the institutional problem arrive alongside it.

Runlayer founders Andrew Berman, Tal Peretz and Vitor Balocco standing together in New York
The access committee, casual Friday edition. Andrew Berman, Tal Peretz and Vitor Balocco built Runlayer after working close to the agent boom at Zapier. Photo: Runlayer.

What failed first was not model intelligence. It was the ordinary machinery around access. MCP connections could bypass existing identity systems. An agent might hold a broad API key long after its human owner changed roles. A useful server found on GitHub might never receive a security review. Logs could show an API call without reconstructing the agent's intent, the user's identity or the policy decision that allowed it.

The founders' change of mind was subtle but commercially important. The answer was not another secure AI client. Employees already had preferences, and those preferences changed quickly. A model-neutral control plane could travel across Claude, ChatGPT, Cursor, Codex, GitHub Copilot and whatever came next. That position also kept Runlayer from competing directly with the tools it needed to govern.

Runlayer taught us how to fish, in a way.Mike Wittig, CISO and CIO at Gusto

What they actually installed

Gusto provides the cleanest public anatomy of a deployment. The payroll and HR company had employees experimenting with MCPs outside central security visibility. Runlayer's engineers first helped establish connectors across Gmail, Slack, Snowflake and Confluence. Coverage later spread to Workday, NetSuite and GitHub. Security could disable destructive actions, publish approved connectors to a central catalog and preserve raw request-and-response data for incident response and HIPAA audit work.

The clever operating detail was not a feature toggle. Workers requested new connectors in Slack. Security reviewed and configured each connector, then published it for anyone authorized to use it. Runlayer also held weekly training sessions. In four weeks, the system covered more than 3,000 knowledge workers and 84 MCP servers. The company did not merely put a fence around experimentation; it created a repeatable supply chain for it.

Jane App followed a stricter version of the playbook. The healthcare software company wanted Claude connected to core systems without exposing protected health information. Runlayer helped establish Google Drive, Calendar, Gmail, Atlassian and Fellow connectors on the first day. Jane later expanded to Slack, Notion, HubSpot, Jira, GitHub and Canva, with policies excluding sensitive Drive folders. Within 10 days of the proof of concept, Jane committed to an annual contract. It reported organization-wide adoption among more than 800 knowledge workers within two weeks.

Public rollout snapshots - scale is not the same as proof of ROI
Gusto
3,000+
Jane App
800+
Homebase
400+

Homebase offers a third pattern: use the gateway as the beginning, not the destination. It rolled approved connections to Datadog, Databricks, CrowdStrike, Sentry, GitHub, Slack, Figma and Google Workspace, then layered in company-built MCPs, skills and agents. Public figures say more than 400 employees generated 27,000 human connector calls. These are vendor case studies, so they tell us deployment breadth, not independently measured productivity. Still, they reveal the buyer's real job: turn scattered experiments into shared infrastructure.

The product is bigger than a gateway

Runlayer now packages four related jobs. Its gateway and catalog serve approved MCPs. Watch looks for shadow AI and unauthorized connectors on employee devices. Guard inspects tool calls at runtime for prompt injection, tool poisoning, command execution and suspicious data movement. Runlayer Agents hosts background agents with managed identities and scoped permissions. The platform also tracks who used what, what it cost and whether adoption is growing.

Partnerships make that neutral layer more useful. A Box integration preserves Box permissions while agents query company content. A 1Password integration injects governed credentials instead of leaving secrets in plain-text environment files. Cursor Hooks can deny an unmanaged MCP before it runs. Runlayer and Anthropic collaborated on MCP Tunnels, which reverse the usual network direction: an enterprise network initiates an outbound connection to Anthropic, avoiding an inbound hole in the firewall. In April 2026, Runlayer announced the highest R1-R9 conformance tier of the AARM runtime-security specification.

What a buyer gets

  • One approved catalog
  • Identity-aware access
  • Inline threat checks
  • Session-level audit trails

What remains on the buyer

  • Good policy design
  • Connector review
  • Employee training
  • Measuring useful work

The bill is private; the bet is public

Runlayer does not publish prices, plan tiers or a self-serve starting point. Contracts are custom and demo-led. That narrows the likely buyer to an enterprise that already has enough agent use, regulatory pressure or security exposure to justify procurement and implementation. The service can run in Runlayer's cloud or inside a customer's VPC using Terraform or Helm, which matters when data egress is unacceptable.

What did the company itself spend to reach this point? Investors have supplied the visible number. Runlayer emerged from stealth in November 2025 with an $11 million seed led by Khosla Ventures' Keith Rabois and Felicis. Seven months later, Felicis led a $30 million Series A with Khosla participating. Runlayer says total funding is $42 million, implying another roughly $1 million outside the two headline rounds. No valuation or revenue figure has been disclosed.

The capital bought speed in a market where standards and threats move together. The team grew from roughly 10 people in January 2026 to about 40 by midyear, according to Berman. Customers named publicly include Instacart, Opendoor, dbt Labs, Lemonade, AngelList, PagerDuty, Cursor and Decagon, alongside the case-study companies. In 2025, Runlayer said it had signed dozens of customers during four months of stealth, including eight unicorns or public companies.

The part worth copying

Founders can steal the sequence without copying the software. First, work close enough to a new behavior to see the unglamorous breakage. Second, sell visibility before promising transformation: an inventory of shadow connections gives a security team an immediate reason to care. Third, turn governance into distribution. An approved catalog, Slack request workflow and training cadence make the safe choice easier. Finally, remain neutral when customers already use several competing platforms. Runlayer's wedge is not “our agent is smartest.” It is “your agents can all pass through the same controls.”

A buyer can copy the operating model, too. Map current agent and MCP use. Select a small set of valuable connectors. Tie access to the identity provider. Remove destructive actions by default. Give employees one visible request path. Log full sessions, not just isolated API calls. Train teams on reusable workflows, then measure adoption and cost before expanding the catalog. The product helps, but the rollout is a management system.

There are conditions where the formula will not work. A 20-person startup with a handful of trusted engineers may find an enterprise control plane heavier than the risk. A company that bans external models, lacks broad agent adoption or needs a fully air-gapped system should scrutinize the fit. The larger strategic risk is consolidation: cloud providers, identity vendors and security incumbents can bundle adjacent controls. Runlayer must stay useful across them. Its market also depends on MCP remaining an important connective standard rather than one protocol among many.

The durable idea is not “security slows AI down.” It is that a well-paved road can make the approved route the fastest one.

Runlayer is young, its pricing is opaque, and most performance evidence comes from customers selected for public case studies. Those caveats belong in the frame. So does the speed of the deployments. The company found a moment when boards were demanding AI adoption, employees were already improvising, and security teams needed something more useful than a block list. It built the lobby before the building had finished filling up.