option
Home
News
Cybersecurity Startup Runlayer Launches with $11M from Khosla, Felicis and Backing from 8 Unicorns

Cybersecurity Startup Runlayer Launches with $11M from Khosla, Felicis and Backing from 8 Unicorns

January 3, 2026
77

Cybersecurity Startup Runlayer Launches with $11M from Khosla, Felicis and Backing from 8 Unicorns

On Monday, a new Model Context Protocol security startup named Runlayer emerged from stealth mode, securing $11 million in seed funding from Keith Rabois of Khosla Ventures and Felicis.

The company was founded by Andrew Berman, a three-time founder whose previous ventures include baby-monitor creator Nanit and the AI video conferencing tool Vowel, which was acquired by Zapier in 2024.

Since launching its product in stealth four months ago, Runlayer has reportedly onboarded dozens of customers, including eight unicorn or public companies such as Gusto, dbt Labs, Instacart, and Opendoor. CEO Andrew Berman also informed TechCrunch that David Soria Parra, a key creator of MCP, has joined as an angel investor and advisor. (Parra did not respond to our request for comment.)

Parra's team at Anthropic introduced the Model Context Protocol as an open-source project in November 2024. MCP has rapidly become the default standard for enabling AI agents to connect with the data and systems they need to operate autonomously, allowing them to access, transfer, modify data, and execute business processes without human intervention.

The protocol now enjoys support from all major model providers, including OpenAI, Microsoft, AWS, and Google, alongside thousands of technology and enterprise firms. Notable adopters range from Atlassian, Asana, Stripe, and Block to various banks and consumer goods manufacturers.

"Everyone is talking about AI," Berman told TechCrunch, "but its utility is ultimately determined by the tools and resources it can access."

The core issue is that the MCP protocol itself does not include robust built-in security, leading to numerous implementations being found vulnerable in various ways.

Techcrunch event

Join the Disrupt 2026 Waitlist

Secure your spot on the Disrupt 2026 waitlist to be first in line for Early Bird tickets. Past Disrupt stages have featured leaders from Google Cloud, Netflix, Microsoft, Box, Phia, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, and Vinod Khosla. They're part of over 250 industry experts leading 200+ sessions designed to accelerate your growth and sharpen your competitive edge. You'll also have the chance to connect with hundreds of startups driving innovation across every sector.

Join the Disrupt 2026 Waitlist

Secure your spot on the Disrupt 2026 waitlist to be first in line for Early Bird tickets. Past Disrupt stages have featured leaders from Google Cloud, Netflix, Microsoft, Box, Phia, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, and Vinod Khosla. They're part of over 250 industry experts leading 200+ sessions designed to accelerate your growth and sharpen your competitive edge. You'll also have the chance to connect with hundreds of startups driving innovation across every sector.

San Francisco | October 13-15, 2026 WAITLIST NOW

GitHub and Asana serve as prominent examples. In May, researchers at Invariant Labs uncovered a prompt injection vulnerability in MCP servers that enabled unauthorized access to data from private GitHub repositories. Separately, Asana identified and patched a vulnerability in its MCP server in June that could have led to customer data exposure. Since then, many more attack vectors have been discovered against common MCP server configurations.

Unsurprisingly, these security concerns have spurred the development of numerous MCP security solutions. Major players like Cloudflare, Docker, and Wiz have entered the space, alongside a wave of startups focusing on more specialized products.

Currently, the most prevalent type of MCP security product is the gateway, which acts as a protective layer to authenticate agents and manage their application access.

Runlayer aims to differentiate itself in this competitive market by offering a comprehensive security platform. It combines a gateway with advanced features like threat detection that scrutinizes every MCP request, observability that monitors all agent activity across approved MCP servers, enterprise development tools for building custom AI automations, and granular permissions that integrate with existing identity providers such as Okta and Entra.

Similar to competitors like the open-source Obot, Runlayer provides business users with a catalog—akin to Okta—of pre-vetted MCP servers that their IT department authorizes for agent access. The platform aligns AI agent application permissions with the individual user's existing privileges, enforcing read-only, write, or no-access policies for systems like financial databases accordingly.

Berman believes Runlayer's edge lies not only in its product's breadth but also in the team's direct experience. After selling Vowel to Zapier and becoming Zapier's AI director, he built one of the earliest MCP servers while collaborating closely with OpenAI and Anthropic. This firsthand exposure revealed the protocol's challenges.

"What problems did we identify with the protocol? First, the rapid adoption created significant security risks," he explained. There were critical "blind spots" in areas like observability and auditing, making enterprise-wide rollouts particularly risky.

"So in August, we left our jobs. We brought on David Soria Parra, the spec's creator, and within four months, we've signed eight unicorns," Berman said, referring to himself and his co-founders from Zapier, Tal Peretz and Vitor Balocco.

Berman notes that other advisors and investors in the company include Cursor's Head of Security, Travis McPeak, and Neon founder Nikita Shamgunov.

Related article
Google Adopts Anthropic Standard for AI Model Data Connectivity Google Adopts Anthropic Standard for AI Model Data Connectivity Just weeks after OpenAI announced it would adopt rival Anthropic's protocol for connecting AI models to data systems, Google is doing the same. In a Wednesday post on X, Google DeepMind CEO Demis Hassabis stated that Google will add support for Anthr
Developers distracted 1,200 times daily, MCP targets productivity fix Developers distracted 1,200 times daily, MCP targets productivity fix Software developers spend far more time not coding than they do writing actual code. Industry studies suggest direct programming may account for only around 16% of a developer's workday, with the vast majority of time eaten up by supporting tasks and
ChatGPT adds meeting recording and Google Drive, Box integration ChatGPT adds meeting recording and Google Drive, Box integration OpenAI's ChatGPT rolls out enhanced enterprise features, offering seamless cloud service integrations, meeting transcription capabilities, and MCP connectivity for in-depth research workflows.The update introduces native connectors for Dropbox, Box,
Related Special Topic Recommendations
Animation Creation Top AI Storyboard Generators: Convert Movie Scripts into Cinematic Animatics Automatically
Top AI Storyboard Generators: Convert Movie Scripts into Cinematic Animatics Automatically

Discover the 2026 best AI storyboard generators at XIX.AI. Our curated, top-rated tools automatically convert scripts into cinematic animatics, saving you time and boosting pre-production. Explore free vs paid options with real-world tests and weekly updated rankings. Find your perfect creative partner today!

10 tools
xix.ai
SEO Best AI Redirect & Broken Link Finders: Automatically Repair Crawl Errors to Save Crawl Budget
Best AI Redirect & Broken Link Finders: Automatically Repair Crawl Errors to Save Crawl Budget

Discover the 2026 best AI redirect and broken link finders on XIX.AI. Our top-rated, curated list features powerful tools that automatically repair crawl errors to save your crawl budget. Compare free vs paid options with real-world tests and weekly updated rankings. Find your perfect SEO solution now!

10 tools
xix.ai
Video creation Top AI Video Creators for Podcasters: Convert Audio Waves into Engaging Talking-Head Videos
Top AI Video Creators for Podcasters: Convert Audio Waves into Engaging Talking-Head Videos

Discover the 2026 best AI video creators for podcasters at XIX.AI. Our curated, top-rated list features powerful tools that convert your audio into engaging talking-head videos effortlessly. Compare free vs paid options with real-world tests and weekly updated rankings. Unlock your visual storytelling edge now.

10 tools
xix.ai
chatbot Create Your Own AI Love Story with These Roleplay Tools
Create Your Own AI Love Story with These Roleplay Tools

Discover the 2026 latest top-rated AI roleplay tools for crafting immersive narratives. XIX.AI's curated list features powerful, game-changing assistants to unlock creative storytelling and emotional depth. Compare free vs paid options with real-world tests. Start your unique journey today.

10 tools
xix.ai
Text-to-speech Top AI Voice Tools for Indie Game Devs: Save Time on Voice Acting for RPGs and Visual Novels
Top AI Voice Tools for Indie Game Devs: Save Time on Voice Acting for RPGs and Visual Novels

Discover the 2026 best AI voice tools for game devs! XIX.AI's curated list features top-rated, game-changing solutions to save you time and money on voice acting for RPGs and visual novels. Explore free vs paid comparisons, real-world tests, and weekly updated rankings. Find your perfect voice tool today!

10 tools
xix.ai
Education and Learning Best AI Spaced Repetition Tools: Optimize Study Schedules for Medical & Law Students
Best AI Spaced Repetition Tools: Optimize Study Schedules for Medical & Law Students

Discover the 2026 best AI spaced repetition tools, curated by XIX.AI. Our top-rated, game-changing picks help medical and law students optimize study schedules for maximum retention. Compare free vs paid options with real-world tests and weekly updated rankings. Unlock your learning edge now.

10 tools
xix.ai
Comments (1)
0/500
PaulYoung
PaulYoung January 27, 2026 at 11:00:16 AM EST

Une startup de cybersécurité qui sort de l'ombre avec 11 millions et le soutien de 8 licornes ? Intéressant. J'espère que leur protocole MCP tiendra ses promesses face aux menaces actuelles. Le financement est impressionnant, mais le vrai test sera sur le terrain. Bonne chance à eux ! 🛡️

OR