Runlayer Sues Rippling Over MCP Claims
A legal dispute over Model Context Protocol technology highlights the risks startups face when piloting tools with tech giants.
When an enterprise-focused startup opens its codebase to a prospective corporate partner, the potential for a sale usually outweighs the risks of exposure. However, for Runlayer, a firm specializing in secure Model Context Protocol gateways, a year-long integration trial has culminated in a formal lawsuit accusing Rippling of misappropriating proprietary intellectual property.
The Anatomy of a Failed Pilot
The conflict centers on a period of collaboration between the two companies. According to the complaint, Runlayer engaged with Rippling under a mutual non-disclosure agreement and a product trial contract that explicitly restricted the ability to duplicate or build derivative works based on Runlayer’s technology. The partnership involved nearly a year of intensive engineering work, but the relationship soured when the parties failed to reach a pricing agreement, leading to the formal conclusion of the trial.
Runlayer claims that shortly after the partnership ended, a Rippling insider reached out to CEO Andrew Berman to warn him of an internal effort to develop a near-identical clone of the startup’s platform. This prompted legal action citing trade secret misappropriation, unfair competition, and breach of contract.
Corporate Defense and Disputed Claims
Rippling has acknowledged it is bringing its own MCP gateway to market but has firmly rejected the allegations of intellectual property theft. The company maintains that its development efforts were entirely independent and focused on creating a superior solution for AI integration.
Runlayer’s panicked effort to avoid competition by fabricating claims is not an effective way to deal with its business failures. Rippling is launching a superior product for connecting AI tools to business data using only our proprietary information – we have every reason to win in this market.
— Rippling spokesperson
Infrastructure Competition and Risk
The litigation highlights the precarious position of startups navigating the modern enterprise software landscape. As AI interoperability becomes a critical requirement, the market for MCP gateways has intensified. Since Anthropic introduced the protocol in 2024, the demand for security-hardened gateways has surged, making the space increasingly crowded.
- $42 million in total capital raised by Runlayer to date.
- Approximately one year of engineering collaboration occurred during the pilot.
- The lawsuit is currently being handled by the law firm Sullivan & Cromwell.
Implications for Enterprise Sales
For founders and enterprise leaders, this dispute illustrates the inherent tension in deep-dive product trials. While hands-on integration is often necessary to secure high-value contracts, it forces startups to expose their core value propositions to companies that may possess the engineering resources to replicate them. This could mean that future enterprise agreements require even more stringent legal safeguards or that startups may increasingly limit transparency during the pilot process to protect their underlying IP from becoming a casualty of a failed sales negotiation.
Sources
- TechCrunch Original source
Continue Reading
Critical SQL Injection in @hypequery/clickhouse
A severe SQL injection vulnerability in @hypequery/clickhouse allows attackers to execute arbitrary SQL commands by manipulating input parameters.
Critical Command Injection Hits IBM Aspera
A critical shell command injection flaw in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code with high-level privileges.
Critical RCE Flaw Found in IBM Aspera Faspex
A critical vulnerability in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code via unquoted shell interpolation.