The short version
Pipelock is an open-source agent firewall. It scans HTTP, MCP, and WebSocket traffic routed through it for credential leaks, injection, SSRF, and tool poisoning, can emit signed action receipts for mediated decisions when a signing key is configured, and runs locally as a single binary.
Runlayer is a managed AI control plane. Its site describes a governed MCP gateway backed by a catalog of more than 18,000 MCPs, support for more than 300 AI clients, identity-based access and permissions, shadow AI discovery across unmanaged agents and client configs, and audit of agent sessions. The company advertises SOC 2, HIPAA, and GDPR compliance.
Pipelock enforces on the network path. Runlayer governs at the access layer.
Feature comparison
| Feature | Pipelock | Runlayer |
|---|---|---|
| Architecture | Network proxy, single self-hosted binary | Managed control plane with a governed MCP gateway |
| Primary scope | Content scanning on HTTP, HTTPS CONNECT (payloads only with TLS interception on), WebSocket, and MCP | MCP access governance, catalog, identity, discovery |
| Credential scanning (DLP) | 65 built-in patterns, encoding-aware, environment leak detection | Input and output filtering on tool traffic, per its materials |
| Prompt injection detection | Deterministic patterns with multi-pass normalization | Security models on tool calls, outputs, and intent, per its materials |
| Tool poisoning | Description scanning and rug-pull drift detection | Curated catalog plus runtime filtering |
| SSRF protection | Private IP, metadata, and DNS rebinding checks | Not documented |
| Identity-based access | Not in scope at the proxy | Yes |
| MCP catalog | No | Yes, 18,000+ per the site |
| Shadow AI discovery | No | Yes |
| Signed receipts | Yes, Ed25519, verifiable offline | Session audit; no signed-receipt format documented |
| Compliance | OWASP, NIST 800-53, and EU AI Act mappings | SOC 2, HIPAA, GDPR advertised |
| Source availability | Apache-2.0 core; Enterprise under ELv2 | Closed source |
| Pricing | Free core; paid tiers published | No public price list found |
Where Runlayer is stronger
Access governance at company scale. Which users and teams may reach which MCP servers, with permissions and approval built in. Pipelock doesn’t manage identity.
The catalog. A curated registry of approved servers that teams can browse and request. Pipelock has no catalog.
Shadow AI discovery. Visibility into unmanaged agents, MCPs, skills, and client configs across an organization. Pipelock sees only the traffic routed through it.
Compliance posture for procurement. SOC 2, HIPAA, and GDPR badges and named enterprise customers matter to buyers who purchase through procurement.
Where Pipelock is stronger
Network-layer coverage. HTTP, HTTPS via CONNECT, and WebSocket traffic are inspected alongside MCP. Agent activity outside the MCP tool layer is visible because the proxy is in the path.
Inspection depth. Encoding-aware DLP, injection normalization passes, tool fingerprinting and drift detection, entropy and environment-leak checks.
Open, readable rules. Every pattern is in the public repository. Runlayer’s security models are proprietary.
Evidence. With a signing key configured, Pipelock can emit signed receipts for mediated decisions that the shipped verifier checks offline against your key.
Published pricing. The free core and the paid tiers are on the pricing page. Runlayer asks you to talk to sales.
Different enforcement points
Runlayer answers: who may access which tools, under what policy, with what approval? Pipelock answers: what is in the traffic, is a credential leaking, is the response injecting instructions, is the tool description poisoned, and can I prove what I decided?
Agents don’t only act through governed tool calls. They fetch URLs and call APIs. A proxy on the network path sees that traffic whatever layer initiated it.
Further reading
- What is an agent firewall?: definition and evaluation checklist
- Agent firewall vs guardrails: where enforcement happens
- Pipelock vs Backslash Security: another governance-platform comparison
- Agent firewall vs AI security platform: the shape question, across the platform vendors
- MCP security: the full scope of MCP threats
- Pipelock on GitHub
Sources checked
Third-party descriptions on this page come from the public materials below, read on the dates shown. Features and pricing change; check the current documentation before you decide.
Third-party product names and marks belong to their owners. PipeLab is not affiliated with, sponsored by, or endorsed by the makers of any product compared on this page. Descriptions of other products come from their own public materials on the dates listed above and reflect PipeLab's reading of them. If something here is wrong or out of date, tell us and it will be corrected.