About Runline

We build the guardrails thatAI agents can't talk their way past.

Our mission

Make AI agents safe to give real access to.

Engineering teams have spent a decade hardening production. Then in eighteen months we handed AI agents shells, cloud credentials, and write access to source control. The blast radius of a single bad command grew, and our controls didn't.

Runline closes that gap. We sit on the endpoint: laptops, runners, bastions. We evaluate every shell command and MCP tool call against signed policy. Modify operations require a rule that says allow. Read operations pass through fast. Audits drop out for free.

We're built for security teams who are tired of writing prompt rules, and for engineers who don't want their tools turned into another approval queue.

36

Managed CLIs shimmed on every endpoint

<10ms

Median decision latency on read-only rules

0

Prompts engineers have to memorize

How we build

Principles we ship by

Enforcement, not advice

Prompt rules and CI checks ask politely. Runline sits at the exec boundary on every endpoint. If a rule says deny, the managed command never reaches the cloud.

Engineers keep their terminal

Humans pass through. Only commands stamped as AI agent get evaluated against modify rules. No new IDE plugins. No prompt overhead.

Evidence by default

Every decision is signed, timestamped, and replayable. Auditors see a hash-chained trail; engineers see exactly why a command was blocked.

Open agent, signed policy

The agent is source-available so security teams can audit what runs on every laptop. Policy bundles are signed with Sigstore. No silent updates.

Story so far

From late-night incident to platform

  1. 1

    Q4 2025

    Origin

    Started as an internal tool after watching a Cursor agent run `terraform destroy -auto-approve` on a staging account at 2am. Approval flows in the IDE didn't matter. The agent just typed.

  2. 2

    Q1 2026

    First POVs

    Deployed to engineering laptops and CI runners at a handful of design partners. Caught real, in-flight AI agent actions that would have hit production within days of install.

  3. 3

    Q2 2026

    Public beta

    Opened the platform to teams running Cursor, Claude Code, Codex, and MCP-based agents. Shipped signed policy bundles, Okta SSO, and the console you see today.

Built for actors, not just commands

Policy follows actor identity. The same `terraform apply` is allowed when a human typed it and blocked when an AI agent did. That distinction is the whole product.

Default to allow read, deny write

Most AI agent calls are read-only and fast. We optimize for that path. Modify operations get the friction they deserve: rule match, approval, signed evidence.

Tell engineers why, not no

Every blocked command surfaces the rule ID, the matched attribute, and a deep link in the console. Engineers fix policy, not file tickets.

Security & trust

The same posture we expect on production

Tenant isolation

Multi-tenant by design. Every API call is scoped to a tenant; no cross-tenant reads, ever.

Signed policy

Bundles are signed with Sigstore. Agents verify before loading. No silent policy drift.

Auditor-ready evidence

Hash-chained decision logs. Filter, export, attest. SOC 2 evidence packs available on Enterprise.

Want to dig deeper?

We're happy to walk you through the architecture.

Bring the messiest AI-agent workflow on your team. We'll show you exactly what Runline would do with it before you install a single binary.