top of page

Runlayer Accuses Rippling of Misusing Confidential Information to Build an MCP Gateway

Runlayer sued Rippling after an evaluation lasting nearly one year, turning a prospective sale into a disputed fight now circulating through Google News.

The startup alleges that Rippling used confidential material from the trial to develop a competing Model Context Protocol gateway. Rippling confirms that it is launching its own gateway but denies using Runlayer’s intellectual property.

The dispute matters beyond these two companies. Enterprise software trials often require vendors to expose product architecture, roadmaps, and implementation details before a customer signs a contract. A technically capable customer can then decide that building an internal alternative looks more attractive than buying the product.

That risk becomes sharper for AI infrastructure startups. Their products often sit close to open protocols and familiar software patterns. Yet the operational knowledge required to secure and manage those protocols can represent much of the vendor’s actual advantage.

The lawsuit does not establish that Rippling copied anything. It places two conflicting accounts before a court and leaves important technical evidence undisclosed. However, it exposes a structural problem for every startup selling infrastructure to sophisticated technology companies.

A Product Trial Became a Trade Secret Lawsuit

Runlayer says a protected evaluation crossed the line from product testing into unauthorized product development.

Runlayer offers an enterprise gateway for Model Context Protocol, or MCP. The protocol gives AI applications a common method for connecting with external tools and business data.

A gateway sits between those applications and their MCP servers. It can enforce permissions, inspect tool calls, record activity, and limit which systems an AI agent can reach.

According to the lawsuit account, Rippling evaluated Runlayer as a prospective customer. The companies reportedly signed a mutual nondisclosure agreement, while Rippling also signed a product trial agreement.

Runlayer alleges that the second agreement prohibited copying its intellectual property or creating derivative works. Such language can distinguish a commercial evaluation from unrestricted access to a vendor’s technology.

The startup claims that the evaluation involved nearly one year of close engineering collaboration. Runlayer says it shared its source code, product roadmap, and other technical information during that period.

Those allegations make the dispute more specific than a complaint about a competitor launching a similar feature. The central question is whether Rippling used protected information obtained through the trial, not whether it independently recognized demand for MCP governance.

The parties eventually failed to agree on commercial terms, according to the complaint as described by TechCrunch. Runlayer then ended the evaluation.

Runlayer alleges that an insider later contacted founder and CEO Andrew Berman. The reported message described an internal Rippling project as essentially a clone and nearly a one-to-one copy of Runlayer.

That reported message is an allegation cited in the complaint. Its author, context, and supporting evidence have not been independently established in public reporting.

Runlayer accuses Rippling of trade secret misappropriation, unfair competition, and breach of contract. It has retained Sullivan & Cromwell to handle the litigation.

Rippling rejects the allegations. A spokesperson told TechCrunch that the claims were fabricated and intended to restrict competition. The company says its gateway relies only on proprietary Rippling information.

That denial creates the case’s central factual divide. Runlayer describes a protected trial followed by a copy, while Rippling describes independent product development followed by an attempt to block a competitor.

A court will need more than product similarities to resolve that divide. It will likely examine what Runlayer disclosed, who received it, how Rippling developed its product, and whether confidential elements appear in Rippling’s implementation.

Until that evidence emerges, the most consequential confirmed fact is narrower. Rippling evaluated Runlayer and is now launching a competing MCP gateway, while denying that the two events involved misuse of confidential information.

Why Google News Attention Raises the Stakes

Google News is amplifying a lawsuit that challenges how enterprise AI startups conduct high-touch sales trials.

The dispute arrived when MCP gateways were becoming a recognizable enterprise software category. That timing gives the allegations importance beyond an ordinary contract disagreement.

Anthropic introduced MCP as an open standard in November 2024. Its MCP announcement described a common way for AI assistants to connect with content repositories, business tools, and development environments.

An open protocol reduces the need to create a separate integration method for every data source. It does not automatically solve authorization, monitoring, security, or compliance requirements.

Those remaining problems create room for gateways. Enterprises want agents to reach useful systems without giving every model unrestricted access to payroll records, internal documents, customer data, or production tools.

Runlayer entered that layer of the market with a managed gateway and governance product. The company has raised a reported total of $42 million from investors that include Khosla Ventures and Felicis.

The startup’s position depends on a distinction that will shape the litigation. MCP itself is open, but Runlayer says its implementation, source code, roadmap, and operational techniques include protected intellectual property.

That is not an unusual distinction in enterprise software. A database protocol can be public while a vendor’s management system remains proprietary. The same applies to security controls built around an open networking standard.

However, the boundary can become difficult to prove when competing products use comparable architecture. Gateways commonly authenticate users, route traffic, apply policies, create logs, and present administrative controls.

Runlayer must therefore identify confidential elements with enough precision to separate them from general concepts, public protocol requirements, and ordinary engineering practices. Broad ownership claims over the idea of an MCP gateway would face obvious scrutiny.

Google News distribution increases public attention, but it does not validate either party’s account. Aggregation can make a dispute appear settled before a defendant has filed a detailed response or technical evidence becomes available.

Readers should treat the Google News headline as an entry point, not a verdict. The wording summarizes Runlayer’s accusation, while Rippling’s denial remains essential to understanding the story.

The attention still creates practical pressure. Prospective Runlayer customers may ask whether extended trials expose its core technology. Rippling customers may ask whether the forthcoming gateway faces legal or product continuity risks.

Other AI infrastructure vendors will watch how Runlayer documented its disclosures. A favorable outcome could strengthen the value of trial restrictions, access logs, code controls, and narrowly defined trade secrets.

A weak complaint or an early dismissal would send a different signal. It would suggest that contractual protection cannot compensate for disclosing information that a court considers general knowledge or readily reproducible engineering.

Rippling also faces a reputational tension because of its earlier conflict with Deel. Rippling accused the rival HR platform of corporate espionage in 2025, including allegations involving an insider and confidential company information.

The separate espionage dispute does not prove anything about Runlayer’s claims. It does create an uncomfortable contrast as Rippling now defends itself against allegations involving confidential information.

That contrast will attract coverage. It should not replace the technical and contractual evidence that the new case requires.

Runlayer Versus Rippling Is Really Build Versus Buy

The primary conflict is between a specialist vendor protecting its product and a large customer asserting its right to build competing infrastructure.

Enterprise buyers rarely evaluate infrastructure through a short demonstration. Their security teams request architecture reviews, integration tests, deployment details, and direct access to engineers.

Those requests often serve legitimate purposes. A company cannot safely place an untested gateway between AI agents and sensitive business systems.

A meaningful trial can reveal whether the gateway handles real workloads, identity systems, failure cases, and access policies. A superficial demonstration may conceal problems that appear only inside the customer’s environment.

The vendor must therefore disclose enough information to complete the sale. Each disclosure also helps the buyer understand how the product works and how difficult it would be to reproduce.

Runlayer publicly argues that companies should purchase this capability. Its gateway case says internal teams can underestimate the security, performance, and maintenance demands surrounding MCP.

That argument is a vendor’s position, not independent proof. Some companies have enough engineering capacity and internal context to build a gateway that meets their requirements.

Rippling is a particularly difficult prospect for a startup making the buy argument. Its broader product connects HR, payroll, identity, device management, and other business functions.

A company operating those systems already controls valuable data, permission structures, and integration infrastructure. It also has incentives to make that information available to AI applications without adding another vendor to the path.

Building internally can provide tighter product integration and direct control over development priorities. It can also avoid dependencies on an outside gateway for a strategically important interface.

Buying offers different advantages. A specialist can spread security research, protocol updates, and operational development across multiple customers. It can also provide a neutral control layer across competing applications.

The lawsuit tests where lawful internal development ends. A customer does not normally lose its right to enter a market simply because it evaluated a vendor.

However, a signed agreement can limit what the customer does with confidential information received during that evaluation. Trade secret law can add protection when the information has economic value, remains nonpublic, and receives reasonable safeguards.

Runlayer’s case therefore cannot rest on the sequence alone. Evaluation followed by internal development can look suspicious, but timing does not establish misuse.

The startup needs evidence connecting its confidential material to Rippling’s work. That evidence might include access records, internal communications, design documents, code history, or unusually specific technical similarities.

Rippling can counter with evidence of independent development. Earlier design work, separate engineering teams, clean documentation, and reliance on public materials would support its denial.

This creates a warning for both sides of enterprise trials. Vendors need controlled disclosure and clear records. Buyers need separation between evaluation material and teams developing an alternative.

A mutual nondisclosure agreement offers useful protection, but it does not prevent a dispute. The parties still need to define confidential information, permitted use, retention, and access.

Source code raises the stakes further. Sharing a repository can reveal implementation choices that ordinary product documentation would never expose.

A startup should be able to show exactly who accessed that code and why. A buyer contemplating an internal build should restrict access before its engineers begin competing work.

Those practices cannot determine whether wrongdoing occurred here. They can reduce ambiguity and make later claims easier to test.

The Runlayer versus Rippling conflict ultimately reflects opposing business needs. Startups need close collaboration to win complex customers, while capable buyers want freedom to build technology that becomes strategically important.

The Evidence Has Not Yet Caught Up With the Accusation

Runlayer has described a troubling sequence, but the public record does not yet prove that Rippling copied protected technology.

The strongest narrative element is the alleged insider message. A person supposedly familiar with Rippling’s project characterized it as nearly a one-to-one copy.

That description sounds decisive in a headline. Legally and technically, it raises more questions than it answers.

It remains unclear what the person saw, what “copy” meant, and whether the comparison concerned source code, architecture, features, or product positioning. Similar interfaces alone would carry different weight from matching nonpublic code.

The message also needs authentication and context. Courts routinely examine whether quoted communications are complete, accurate, and based on firsthand knowledge.

Runlayer’s disclosure of source code may become more important. If Rippling personnel accessed distinctive code and substantially similar elements later appeared in its gateway, that connection would support the startup’s theory.

The opposite result is also possible. Rippling might show that its gateway uses an independently created architecture shaped by its existing systems and the public MCP specification.

Many gateway functions are predictable. Authentication, policy enforcement, audit logs, routing, rate limits, and observability appear across API management and security products.

A company cannot convert every familiar feature into a trade secret by placing it inside an MCP product. Runlayer must identify information that was genuinely confidential and not readily derived from public knowledge.

It must also show reasonable protection. The reported agreements help, but courts can examine how widely Runlayer distributed the information and what controls surrounded access.

Rippling’s public response is equally unverified. The company says it used only proprietary information, but no independent technical review has confirmed that assertion.

Its claim that the product is superior is a competitive statement with no public benchmark behind it. Product quality also would not resolve whether protected information influenced its development.

The lawsuit presents another uncertainty because its remedies could take several forms. Runlayer might seek damages, restrictions on using specific information, contractual relief, or changes to Rippling’s launch.

The practical outcome may also arrive before a final judgment. Litigation can delay a rollout, increase review requirements, discourage customers, or produce a confidential settlement.

None of those outcomes would necessarily establish which narrative was correct. Companies often settle to control cost and uncertainty.

Industry competition further complicates Runlayer’s argument that its knowledge was unique. Citrix announced MCP Gateway capabilities for NetScaler in July 2026.

Other security, identity, and API management vendors have also moved toward agent governance. Their presence shows that several companies independently see demand for a control point between agents and enterprise systems.

That crowded market does not disprove copying. Multiple competitors can reach the same category while one still misuses a specific vendor’s confidential implementation.

It does narrow the valid claim. Runlayer is not entitled to exclusive ownership of the market category merely because it entered early.

The skeptical reading is straightforward: a failed sale became a lawsuit when the prospect turned into a competitor. Under that reading, Runlayer is trying to extend contractual restrictions into a barrier against lawful competition.

The opposing reading is equally coherent: Rippling used a protected trial to shorten its development process and obtain details unavailable through public research.

Only discovery can separate those accounts. Internal records, repository histories, evaluation logs, and testimony will matter more than either company’s public rhetoric.

Readers arriving through Google News should preserve that distinction. The allegation is credible enough to investigate, but not established enough to repeat as fact.

MCP Gateway Competition Is Expanding Fast

The lawsuit lands in a category where open standards encourage competition while enterprise security creates demand for proprietary control layers.

Anthropic designed MCP to replace fragmented integrations with a shared method for connecting AI systems and data sources. Wider adoption makes it easier for application developers to support many tools.

Standardization also lowers one barrier to entry. A company does not need to invent the underlying communication protocol before building management software around it.

That helps startups reach the market quickly. It also allows established infrastructure vendors to add MCP controls to products customers already use.

Identity providers can connect agent permissions with existing access policies. API gateway vendors can adapt routing and monitoring systems. Security companies can inspect tool calls for suspicious behavior.

Cloud platforms can place MCP governance inside broader deployment environments. Business software companies can expose their own applications through controlled gateways.

Runlayer competes against all of those routes, not only Rippling. Its long-term case depends on delivering specialized capabilities faster than internal teams and larger vendors can reproduce them.

The company says MCP gateways require protocol-specific threat detection and continuous maintenance. That argument gains force when agents can act on data rather than merely retrieve it.

An agent connected to email, payroll, code repositories, and customer systems can create substantial operational risk. Incorrect permissions or manipulated instructions can turn an ordinary model error into a business action.

Gateways offer one place to apply restrictions, but they are not complete security systems. Their effectiveness depends on identity controls, server behavior, application design, and the policies an enterprise configures.

A gateway can log a dangerous tool call without preventing it. It can enforce a weak policy exactly as written. It can also become a valuable target because many agent connections pass through it.

These limitations make implementation knowledge commercially valuable. They also make feature overlap likely, because every serious vendor must address similar security requirements.

The market’s growth explains why Rippling would want its own product. It also explains why Runlayer would defend information gathered through a long evaluation.

For enterprise buyers, the dispute should encourage more disciplined evaluation processes. A proof of concept should begin with a written purpose, defined data boundaries, and a limited set of participants.

The customer should record whether it is evaluating, integrating, or conducting security review. Those purposes can require different levels of access.

Vendors should stage disclosure. Product behavior can be tested before a prospect receives source code or detailed roadmap information.

When deeper access becomes necessary, access records and expiration rules can preserve evidence. They can also reduce accidental reuse by people working across evaluation and development teams.

Buyers that might build should establish clean boundaries early. Waiting until after a failed negotiation creates a sequence that invites suspicion, even when development is independent.

The case also offers a knowledge-management lesson. Engineers need reliable records separating public research, customer evaluation material, and original design decisions.

Teams can use a searchable knowledge base to preserve design provenance, meeting notes, and technical sources. The record matters when similar ideas emerge from multiple channels.

Documentation is not merely defensive. It helps teams explain why a feature exists, which constraints shaped it, and whether protected information influenced a decision.

For startups, those records can support a trade secret claim. For customers, they can support an independent-development defense.

The Google News cycle will move faster than this evidence. Public attention rewards a simple story about an idea being stolen, while the legal dispute requires a detailed reconstruction of access and development.

That mismatch is why the case deserves careful coverage. Its value lies less in the accusation itself than in what the evidence may reveal about enterprise AI sales.

What Google News Readers Should Watch Next

Three signals will show whether this dispute becomes an important trade secret case or fades into a private commercial settlement.

The first signal is Rippling’s formal response. A detailed filing should indicate whether the company challenges the existence of protectable secrets, denies access, or argues that its product was independently developed.

Those defenses carry different implications. A dispute over secrecy would test Runlayer’s disclosure practices, while an independent-development defense would focus attention on Rippling’s engineering records.

The filing may also clarify the forum, requested remedies, and immediate launch risk. A request for early injunctive relief would raise the stakes because it could affect Rippling’s ability to release or sell its gateway.

If a court grants restrictions after reviewing evidence, Runlayer’s account gains strength. If the court rejects urgent relief, that would weaken the startup’s immediate leverage without necessarily deciding the full case.

The second signal is product-level evidence. Rippling’s gateway launch should reveal its positioning, integrations, security model, and relationship with the company’s existing business data.

Public features will not expose source code. They can still show whether the product appears designed primarily for Rippling’s environment or competes broadly with Runlayer across enterprise systems.

A narrowly integrated product would support Rippling’s argument that it built from proprietary assets and customer needs. A broader product matching unusual Runlayer capabilities would invite closer scrutiny, though similarity alone would remain inconclusive.

Independent testing will matter more than competitive claims. Security researchers and enterprise users can assess whether either gateway delivers the governance, isolation, and monitoring it advertises.

The third signal is how other enterprise vendors change their trials. New contract language, restricted code access, shorter evaluations, or clean-room development policies would show that the dispute has influenced industry behavior.

A clean-room process separates engineers exposed to confidential material from those building a competing product. It is not required for every evaluation, but it can provide valuable evidence of independent work.

If major buyers adopt such safeguards, the lawsuit will have consequences regardless of its final result. It will have exposed a weakness in how enterprise AI products move from evaluation to procurement.

If practices remain unchanged, companies may view the conflict as an unusual breakdown between two parties. A confidential settlement would make that interpretation more likely because little technical evidence would become public.

For developers, the immediate lesson is not to assume that an open protocol makes every implementation interchangeable. The architecture around access, policy, monitoring, and threat detection can contain valuable nonpublic work.

For enterprise buyers, the lesson is not that internal development has become off-limits. It is that evaluation access and competing development require deliberate boundaries.

For startup founders, the case challenges the standard enterprise sales motion. Deep collaboration can win trust, but it can also reveal enough information for a capable prospect to reassess the build decision.

The next one to three months should clarify whether Runlayer has evidence connecting its disclosures to Rippling’s code or design. Until then, both the accusation and denial deserve explicit attribution.

Google News has given the conflict a wide audience. The court record will determine whether it becomes a precedent, a warning about trial management, or another unresolved fight between enterprise software companies.

The question for every team evaluating AI infrastructure is now concrete: can you prove where your design came from after a vendor demonstration becomes an internal build?

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page