Zendoric
← Back to the day · July 29, 2026

Runlayer sues Rippling for cloning its MCP gateway: the risk of selling AI infrastructure to a customer-competitor

🕒 Published on Zendoric: July 29, 2026 · 00:34

Runlayer accuses Rippling of cloning its MCP security gateway after nearly a year of trials with access to its code and roadmap. Rippling confirms it is launching its own product and denies any theft. The case exposes the risk of selling AI infrastructure to a customer with its own engineering team.

🎧 Listen to the analysis (in Spanish)

By Zendoric · July 29, 2026.

Runlayer, a startup that sells a security gateway for the Model Context Protocol (MCP) —the open standard that lets AI models and agents access external data and tools in a controlled way—, has sued Rippling, the human resources and payroll software provider. According to the lawsuit, seen by TechCrunch, Rippling evaluated Runlayer's product for nearly a year, with access to its roadmap and its source code, and ended up launching what a purported Rippling employee described to Runlayer founder Andrew Berman as "almost a 1-to-1 copy" of the original product.

The process, according to Runlayer's own account, followed the usual script of a complex enterprise sale: a mutual non-disclosure agreement (NDA) and a product trial contract that —a standard clause in this kind of deal— barred Rippling from copying Runlayer's intellectual property or creating derivative works. The trial, described in the lawsuit as "nearly a year of intensive engineering collaboration", ended without a pricing agreement. Shortly afterwards, Runlayer claims, a Rippling employee warned Berman that the company had an internal project under way to build a clone of its product. In the lawsuit, Runlayer alleges trade secret misappropriation, unfair competition and breach of contract.

Rippling does not deny the launch: it confirms to TechCrunch that it is indeed rolling out its own MCP gateway, but rejects having used anyone else's information. A spokesperson called the lawsuit a "desperate effort to avoid competition by fabricating accusations" in the face of what it called Runlayer's "business failures", and stated that its product is being built "only with our own information". It is worth stressing clearly: for now these are one side's accusations and the other side's denial; no court has determined what actually happened inside Rippling's engineering team.

Two details frame the case. Runlayer has hired the law firm Sullivan & Cromwell to represent it, a heavyweight name that —as TechCrunch notes— adds optical credibility to the lawsuit without prejudging its outcome. And Runlayer is no marginal startup: it launched its product in mid-2025 and has raised $42 million in total, with Khosla Ventures and Felicis among its investors, which places the litigation in a market —infrastructure for AI agents— that is already attracting serious capital.

Our read: the case matters less as litigation than as an X-ray of a structural risk for any startup selling AI infrastructure to other tech companies. Placing complex software inside a large company almost always requires a deep "trial": months of technical integration in which the vendor shows how its product works under the hood to justify the price. That same process is, for a customer with strong in-house engineering, a crash course in how to build the replacement. The NDA and the anti-copying clause protect on paper, but in court it is very hard to prove that a team that already knew the problem —and saw up close how someone else solved it— did not independently arrive at a similar solution. That ambiguity, more than anyone's bad faith, is what makes the relationship between a startup and a "customer-competitor" so asymmetric.

The case also explains why the MCP gateway layer is especially fragile in the face of this risk. Anthropic released MCP as an open protocol in November 2024 and, in a year and a half, it has become a basic piece of interoperability between AI models and tools. Precisely because the protocol is public and free, the value of startups like Runlayer lies not in the standard but in the control, authentication and agent governance layer they build on top of it. That layer is thinner, and therefore faster to replicate by a competent engineering team that already knows which problem needs solving, than compute infrastructure or a proprietary model. The thinner a product's competitive edge, the more exposed it is to a customer with its own technical muscle.

It also fits a dynamic we have been observing in agent infrastructure: the real fight over value is waged less at the model level than over who controls the substrate on which agents operate —authentication, data access, permission management—. Large horizontal platforms (HR, productivity, cloud) have a structural incentive to internalize that layer rather than depend on an external vendor, because that is where the trust relationship with the end customer accumulates. That does not make copying inevitable —Rippling insists it built its product independently—, but it does explain why so many tech companies, after evaluating a small vendor, end up choosing to build in-house.

In the long run, the fact that an open protocol like MCP has generated such a contested gateway ecosystem in a year and a half is good news: more competition and probably lower prices for managing agents securely, in line with increasingly accessible AI infrastructure. But in the short term, that same dynamism leaves the pioneers —those who risked capital and time building first— in a fragile position if their advantage rests only on having arrived earlier and not on a moat that is harder to cross: security certifications, deep integrations or sustained customer relationships.

Whether Runlayer wins or loses in court, the market lesson is already written for the rest of the sector: anyone selling AI infrastructure to a customer with its own engineering team must assume, from the very design of the sales process, that the customer may become a competitor. That forces a rethink of how much code and how much roadmap to show in a product trial, and of building defensibility somewhere else: not in the idea, but in everything around it that a clone cannot copy overnight.

🔗 Related on Zendoric

Sources & references