ProBackend
agentic data platforms
just now5 min read

When Proofs of Concept Turn Hostile: What Runlayer v. Rippling Means for Agentic Data Platforms

An analysis of Runlayer's trade secret lawsuit against Rippling following an extended product trial, examining the legal allegations, Rippling's defense, and what the clash reveals about building agentic data platforms in enterprise environments.

Enterprise software sales used to end with a signed contract or a polite rejection. Today, they end in multi-million dollar trade secret filings. When Model Context Protocol (MCP) gateway startup Runlayer filed a lawsuit against HR software enterprise Rippling, it exposed a legal and strategic hazard that early-stage founders dread: the thin line between evaluating a vendor's tool and replicating it in-house.

The dispute, detailed in a TechCrunch report, highlights the rising friction between infrastructure startups and well-funded tech platforms. As large enterprises race to build out autonomous agent capabilities, startup proofs of concept are increasingly turning into product blueprints for prospective buyers.

Inside the Lawsuit: NDA Breaches, Shared Code, and IP Allegations

Runlayer’s complaint paints a detailed picture of an enterprise trial gone wrong. The startup, which raised $42 million from high-profile backers like Khosla Ventures and Felicis, specializes in building security gateways for the Model Context Protocol (MCP). Anthropic open-sourced MCP in November 2024 to standardize how artificial intelligence models pull external context and execute action calls across enterprise tools. Runlayer built an enterprise-grade control plane around that open standard, offering fine-grained access governance and observability.

According to the lawsuit, Rippling engaged Runlayer for a product trial that lasted nearly a year. This wasn't a superficial sandbox test. Runlayer claims its team engaged in deep, hands-on engineering collaboration with Rippling's engineers. Under a mutual non-disclosure agreement and a standard product trial contract containing explicit anti-copying and anti-derivative works provisions, Runlayer shared detailed product roadmaps and granted access to its proprietary source code.

Negotiations ultimately stalled over pricing. When the parties failed to reach commercial terms, Runlayer terminated the trial. Shortly afterward, an insider at Rippling allegedly texted Runlayer founder and CEO Andrew Berman with a stark warning: Rippling had launched an internal effort to build what the insider described as almost a 1 to 1 copy of Runlayer's architecture.

Runlayer responded by filing suit, accusing Rippling of trade secret misappropriation, unfair competition, and breach of contract. To press its case, Runlayer retained law firm Sullivan & Cromwell.

Rippling flatly denies any wrongdoing. While confirming that it is releasing its own native MCP gateway, a company spokesperson rejected allegations of intellectual property theft. Rippling argued that Runlayer's suit is a panicked reaction to business hurdles, asserting that Rippling engineered its competing solution independently using proprietary internal resources.

What Is an Enterprise AI Platform in the Age of Autonomous Agents?

To understand why this legal clash matters, it helps to step back and ask: what is an enterprise AI platform?

At its core, an enterprise AI platform is an integrated framework of data pipelines, orchestration tools, security controls, and compute resources designed to build, deploy, and govern artificial intelligence systems across an organization. A decade ago, these platforms focused primarily on predictive machine learning models and data lakes. Today, they act as the connective tissue between foundation models and live operational systems.

Modern enterprise AI platforms must answer complex governance questions. How does an autonomous agent query HR databases without exposing confidential salary figures? How do engineers trace why an automated agent triggered a third-party API payment?

An effective enterprise AI platform must deliver four essential capabilities:

  • Unified Context Access: Enabling models to query structured data warehouses and unstructured document repositories without duplicating data.
  • Dynamic Authorization: Enforcing real-time permission checks before an agent reads record details or executes downstream transactions.
  • Protocol Mediation: Standardizing how tools interact with agents via structured interfaces like MCP rather than custom point-to-point scripts.
  • Audit and Observability: Retaining complete ledgers of prompt histories, tool invocations, and agent reasoning paths for compliance.

When enterprise platforms expand into internal AI tooling, control points like MCP gateways shift from optional add-ons to core infrastructure. Companies like Snowflake are already securing agentic data platforms with dual attribution and task-scoped access to prevent exactly this kind of uncontrolled replication.

Why Agentic Data Platforms Face a Proof-of-Concept Trap

The conflict between Runlayer and Rippling exposes a structural challenge for startups building agentic data platforms. These platforms exist to manage state, context, and execution privileges for autonomous agents across complex IT estates. Because they sit directly between raw corporate databases and dynamic AI models, selling them requires demonstrating deep integration capabilities.

Enterprise buyers rarely purchase agentic infrastructure off a slide deck. They demand extended pilot programs to test latency, permission enforcement, and system resilience under realistic workloads. But during a nine-month pilot, the buyer gets complete visibility into the startup's architectural decisions, schema choices, and edge-case handling.

For mature tech platforms with hundreds of software engineers, that evaluation period can double as an architectural discovery phase. Once the enterprise team understands how the startup solved hard orchestration problems, the temptation to build an internal version spikes—especially if the startup's enterprise licensing fees appear steep.

This dynamic isn't limited to Runlayer. Across the industry, teams building hosted MCP servers and contextual orchestration layers face the same risk. Open standards simplify adoption, but they also lower the barrier for enterprise platforms to build native competing features once the design patterns are proven. As the industry shifts toward stateless MCP architectures for better cloud scalability, the architectural blueprints become even more attractive targets for in-house replication.

The Runlayer suit signals a shift in how early-stage AI infrastructure companies must approach enterprise sales. Pitching control planes to large tech companies requires tighter operational safeguards than selling to non-technical enterprise clients.

Startup founders should consider several defensive measures during deep technical evaluations:

  • Isolate Proprietary Engines: Host sensitive routing logic, policy engines, and execution code in tenant-isolated SaaS environments rather than handing over source code or deployable containers for local inspection.
  • Define Stricter Trial Boundaries: Limit proofs of concept to clear, time-boxed milestones of 30 to 60 days rather than letting trials stretch into multi-quarter engineering projects.
  • Enforce Granular IP Clauses: Ensure trial agreements clearly classify architectural blueprints, benchmark results, and feature roadmaps as protected trade secrets with explicit remedies for breach.

For enterprise buyers, the takeaway is equally clear. Building internal tools to sidestep vendor fees might look cost-effective on paper, but prolonged trial collaborations create legal exposure if the internal product mirrors the vendor's design too closely.

As agentic data platforms mature, trust remains the foundation of enterprise procurement. If prospective buyers treat vendor trials as free research and development, the startup ecosystem will inevitably pull back on transparency—making enterprise AI integration harder for everyone.

Inside the Lawsuit: NDA Breaches, Shared Code, and IP Allegations

More blogs