Drooid Logo
Back to story perspectives

Full Breakdown

Runlayer Launches to Address Security Gaps in Model Context Protocol

11/18/2025, 9:02:25 PM

Overview of Runlayer's Launch

Runlayer, a new security startup focused on the Model Context Protocol (MCP), has officially launched with $11 million in seed funding from Khosla Ventures’ Keith Rabois and Felicis. Founded by Andrew Berman, who previously led the AI division at Zapier, Runlayer aims to enhance security for enterprises utilizing MCP, which has rapidly become the standard for AI agents to connect with data and systems.

The Rise of Model Context Protocol

MCP emerged as a crucial framework in late 2024, enabling AI agents to interact with databases, APIs, and internal systems. While this has accelerated productivity, it has also introduced significant security vulnerabilities. Notable incidents include a prompt injection vulnerability discovered by Invariant Labs that exposed private GitHub data and a similar issue identified by Asana that risked customer data. These vulnerabilities have prompted many organizations to either block MCP entirely or seek robust security solutions.

Runlayer's Unique Approach

Runlayer differentiates itself in a crowded market by offering an all-in-one security solution that combines a gateway with features such as threat detection, observability of agent activity, and detailed permissions management. The platform allows organizations to curate a catalog of approved MCP servers, ensuring that AI agents operate within defined security parameters. Berman emphasizes that Runlayer's design addresses the "blind spots" in existing MCP implementations, providing enterprises with the oversight necessary to safely adopt AI tools.

Key Features and Functionality

Runlayer's platform includes a control layer that monitors every MCP action, blocking suspicious activities and maintaining detailed logs for security teams. It integrates with existing identity management systems like Okta and Entra, aligning agent permissions with those of human users. This ensures that if a user has limited access to certain data, the AI agent will have the same restrictions, thereby minimizing risk.

Customer Adoption and Market Response

In just four months since its stealth launch, Runlayer has secured contracts with eight unicorns and publicly traded companies, including Gusto, dbt Labs, and Instacart. This rapid adoption reflects the pressing need for comprehensive security solutions in the MCP landscape. Berman notes that the startup's connection with David Soria Parra, the creator of MCP, as an advisor enhances its credibility and insight into the protocol's intricacies.

Criticism and Industry Concerns

Despite its promising approach, the rapid adoption of MCP has raised concerns among industry leaders about security vulnerabilities. Critics argue that while Runlayer and similar startups are addressing specific gaps, the overall ecosystem remains fragmented, with many companies feeling overwhelmed by the number of tools available. This fragmentation can lead to a false sense of security, as organizations may inadvertently overlook vulnerabilities in their MCP implementations.

Conclusion: The Future of MCP Security

As the demand for AI tools continues to grow, the need for effective security solutions like Runlayer's will become increasingly critical. The startup's focus on providing a unified view of MCP activities aims to empower organizations to harness the benefits of AI while maintaining control over their data and systems. With ongoing developments in the MCP space, Runlayer is positioned to play a significant role in shaping the future of enterprise AI security.