Runlayer, a startup that sells a secure gateway for the Model Context Protocol (MCP), has filed a lawsuit against HR software company Rippling, alleging the company stole its product idea after a nearly year-long product trial. The complaint, seen by TechCrunch, offers a rare inside look at the risks startups face when selling complex AI infrastructure to enterprise customers that have the engineering resources to build competing products in-house.
How a product trial turned into a legal dispute
According to the complaint, Runlayer and Rippling signed a mutual nondisclosure agreement and a product trial agreement that explicitly forbade Rippling from copying Runlayer’s intellectual property or creating derivative works — standard boilerplate in enterprise software evaluations. Runlayer says the trial involved what it describes as “nearly a year of intensive engineering collaboration,” during which the startup shared its product roadmap and even its source code.
After the two sides failed to agree on a price, Runlayer ended the trial. Shortly afterward, Runlayer founder and CEO Andrew Berman received a text from a person described in the suit as a “Rippling insider” informing him of “a project internally to build essentially a clone o[f] Runlayer … it’s almost a 1 to 1 copy of Runlayer.”
Runlayer’s suit alleges trade secret misappropriation, unfair competition, and breach of contract. The startup has retained Sullivan & Cromwell, a prominent law firm known for high-stakes corporate litigation.
Also read: Microsoft's Nadella tells enterprises: Don't trust OpenAI or Anthropic too much
Rippling denies the allegations and prepares its own launch
Rippling has confirmed to TechCrunch that it is indeed launching its own MCP gateway product, but a spokesperson denied Runlayer’s claims. “Runlayer’s panicked effort to avoid competition by fabricating claims is not an effective way to deal with its business failures,” the spokesperson said. “Rippling is launching a superior product for connecting AI tools to business data using only our proprietary information – we have every reason to win in this market.”
The case will likely hinge on whether Runlayer can prove that Rippling’s product was built using its proprietary information rather than independently developed. Hiring Sullivan & Cromwell lends the lawsuit credibility, but legal experts note that winning such claims requires clear evidence of misappropriation, which can be difficult to establish when both sides are building in a rapidly evolving technical field.
What the case reveals about selling AI infrastructure to enterprises
Beyond the legal drama, the lawsuit shines a light on a structural tension in enterprise AI sales. MCP, launched by Anthropic as an open-source protocol in November 2024, has quickly become a foundational layer for AI interoperability. It allows models and agents to securely access external data sources and services. MCP gateway products like Runlayer’s add security controls, agent management, and governance features on top of that protocol.
The market has grown crowded since Runlayer launched its product in mid-2024 and raised $42 million from investors including Khosla Ventures and Felicis. Enterprise sales cycles for such infrastructure are notoriously long, often requiring deep technical evaluations where prospective customers test the product extensively before committing.
That dynamic creates a dilemma for both sides. Startups must share sensitive information to prove their product’s value. Enterprise customers, especially other tech companies, may conclude that building their own solution is cheaper or gives them more control. The Runlayer-Rippling dispute represents an extreme outcome of that tension, but it is not an isolated case.
For startups selling AI tools to large companies, the lawsuit serves as a cautionary tale about protecting intellectual property during trials — and about the risk that a prospective customer may become a competitor instead. For enterprises, it underscores the importance of clear contractual boundaries and independent development practices when evaluating third-party AI infrastructure.