Runlayer
Sources: Homepage · Funding announcement (Runlayer blog) · TechCrunch launch coverage
What
San Francisco-based MCP-security startup founded by third-time founder Andrew Berman (previously Nanit baby-monitor and Vowel AI video conferencing — Vowel sold to Zapier in 2024). Sells an all-in-one MCP gateway with threat detection, observability, custom-automation enablement, and Okta/Entra-integrated permissions. David Soria Parra (lead creator of MCP) is an angel and advisor.
Funding
$11M seed round, November 17, 2025 — led by Khosla Ventures (Keith Rabois) and Felicis. Customer roster cited at launch included eight unicorns or public companies: Gusto, dbt Labs, Instacart, Opendoor, and four undisclosed (Source: TechCrunch).
Relevance
Maps cleanly to the RA Egress plane (gateway is the canonical primitive) with strong overlap into Observability (full MCP request analytics) and Identity (permission system integrates with Okta + Entra).
Functional analog of AgentGateway (open-source, Linux Foundation) but commercial and MCP-specialized. Closest commercial peers: Helmet Security (discovery-and-monitoring side), Operant MCP Gateway, Natoma, and Cloudflare AI Gateway.
CMM evidence supports D5 L3-L4 (egress / MCP), partial D7 L3 (observability), partial D2 L3 (identity integration).
Product
Four advertised pillars (Source: TechCrunch):
- Gateway — inline MCP traffic mediation
- Threat detection — analyzes every MCP request (mitigation surface for the MCP CVE wave — 30+ CVEs, 82% path-traversal)
- Observability — visibility across all agentic activity over MCP servers
- Enterprise development — custom AI automation building blocks for IT
- Detailed permissions — works with existing identity providers (Okta, Microsoft Entra)
The “MCP creator as advisor” signal is meaningful: protocol-level guidance for the gateway approach.
Notable Statements
- Eight-unicorn customer signal at four months post-launch is unusually high for a seed-stage security company; suggests the MCP gateway market is demand-led, not supply-led.
See Also
- Synthesis: Agentic AI Security Seed Funding May 2025–May 2026
- Inline Gateway vs Runtime Instrumentation
- MCP Security
- Helmet Security — discovery + monitoring counterpart