Platforms

Pipelock vs Runlayer

Local content inspection with signed receipts next to a managed AI control plane with a governed MCP gateway.

At a glance

Pipelock source Runlayer
Job Agent firewall. Mediates HTTP, WebSocket, and MCP traffic routed through it, scans it for secret leaks, prompt injection, SSRF, and tool poisoning, and can emit signed action receipts for mediated decisions when a signing key is configured. AI control plane. A governed MCP gateway with a large MCP catalog, identity-based access, shadow AI discovery, and audit across many AI clients.
Enforcement point Network path, outside the agent process Managed gateway and control plane between users, clients, and MCP servers
Source Open source, Apache-2.0 core; Enterprise under ELv2 Closed source (Anysource Inc.)
Pricing shape Free core; paid Pro and Enterprise tiers No public price list found on its site
Runs as Single Go binary, self-hosted; container and Helm Managed service; the site advertises SOC 2, HIPAA, and GDPR
Pick Runlayer

Your problem is who may use which MCP servers across a company, with identity-based access, a catalog, and shadow AI discovery.

Pick Pipelock

Your problem is what is inside the traffic those tools produce, on HTTP and WebSocket as well as MCP, self-hosted, with a signed record.

Run both

Runlayer governs access. Pipelock inspects content and receipts decisions. Different enforcement points, no conflict.

Want the runtime boundary, not just another checklist?

The short version

Pipelock is an open-source agent firewall. It scans HTTP, MCP, and WebSocket traffic routed through it for credential leaks, injection, SSRF, and tool poisoning, can emit signed action receipts for mediated decisions when a signing key is configured, and runs locally as a single binary.

Runlayer is a managed AI control plane. Its site describes a governed MCP gateway backed by a catalog of more than 18,000 MCPs, support for more than 300 AI clients, identity-based access and permissions, shadow AI discovery across unmanaged agents and client configs, and audit of agent sessions. The company advertises SOC 2, HIPAA, and GDPR compliance.

Pipelock enforces on the network path. Runlayer governs at the access layer.

Feature comparison

FeaturePipelockRunlayer
ArchitectureNetwork proxy, single self-hosted binaryManaged control plane with a governed MCP gateway
Primary scopeContent scanning on HTTP, HTTPS CONNECT (payloads only with TLS interception on), WebSocket, and MCPMCP access governance, catalog, identity, discovery
Credential scanning (DLP)65 built-in patterns, encoding-aware, environment leak detectionInput and output filtering on tool traffic, per its materials
Prompt injection detectionDeterministic patterns with multi-pass normalizationSecurity models on tool calls, outputs, and intent, per its materials
Tool poisoningDescription scanning and rug-pull drift detectionCurated catalog plus runtime filtering
SSRF protectionPrivate IP, metadata, and DNS rebinding checksNot documented
Identity-based accessNot in scope at the proxyYes
MCP catalogNoYes, 18,000+ per the site
Shadow AI discoveryNoYes
Signed receiptsYes, Ed25519, verifiable offlineSession audit; no signed-receipt format documented
ComplianceOWASP, NIST 800-53, and EU AI Act mappingsSOC 2, HIPAA, GDPR advertised
Source availabilityApache-2.0 core; Enterprise under ELv2Closed source
PricingFree core; paid tiers publishedNo public price list found

Where Runlayer is stronger

Access governance at company scale. Which users and teams may reach which MCP servers, with permissions and approval built in. Pipelock doesn’t manage identity.

The catalog. A curated registry of approved servers that teams can browse and request. Pipelock has no catalog.

Shadow AI discovery. Visibility into unmanaged agents, MCPs, skills, and client configs across an organization. Pipelock sees only the traffic routed through it.

Compliance posture for procurement. SOC 2, HIPAA, and GDPR badges and named enterprise customers matter to buyers who purchase through procurement.

Where Pipelock is stronger

Network-layer coverage. HTTP, HTTPS via CONNECT, and WebSocket traffic are inspected alongside MCP. Agent activity outside the MCP tool layer is visible because the proxy is in the path.

Inspection depth. Encoding-aware DLP, injection normalization passes, tool fingerprinting and drift detection, entropy and environment-leak checks.

Open, readable rules. Every pattern is in the public repository. Runlayer’s security models are proprietary.

Evidence. With a signing key configured, Pipelock can emit signed receipts for mediated decisions that the shipped verifier checks offline against your key.

Published pricing. The free core and the paid tiers are on the pricing page. Runlayer asks you to talk to sales.

Different enforcement points

Runlayer answers: who may access which tools, under what policy, with what approval? Pipelock answers: what is in the traffic, is a credential leaking, is the response injecting instructions, is the tool description poisoned, and can I prove what I decided?

Agents don’t only act through governed tool calls. They fetch URLs and call APIs. A proxy on the network path sees that traffic whatever layer initiated it.

Further reading

Sources checked

Third-party descriptions on this page come from the public materials below, read on the dates shown. Features and pricing change; check the current documentation before you decide.

Third-party product names and marks belong to their owners. PipeLab is not affiliated with, sponsored by, or endorsed by the makers of any product compared on this page. Descriptions of other products come from their own public materials on the dates listed above and reflect PipeLab's reading of them. If something here is wrong or out of date, tell us and it will be corrected.

Frequently asked questions

What's the difference between Pipelock and Runlayer?
Pipelock is an open-source network proxy that scans agent traffic routed through it across HTTP, WebSocket, and MCP and can emit signed receipts when a signing key is configured. It runs locally as a single binary. Runlayer is a managed AI control plane with a governed MCP gateway, a large catalog, identity-based access, and shadow AI discovery. Pipelock scans content. Runlayer governs access.
Does Runlayer scan HTTP traffic?
Its public materials describe MCP governance through a gateway, with input and output filtering on tool traffic. A general-purpose HTTP or WebSocket forward proxy is not described. Pipelock operates at the network layer and scans HTTP, WebSocket, and MCP traffic for agents routed through it.
Can I use Pipelock and Runlayer together?
Yes. Runlayer decides who may reach which tools and records the access. Pipelock inspects routed traffic through those tools and any routed HTTP traffic outside them, and can emit signed receipts when a signing key is configured.

Want the runtime boundary, not just another checklist?

See all comparisons →