Gus Trigos learned about the dark side of productivity the hard way. At his previous company, he used AI coding agents to ship four full-stack products in three months—a pace that would have been unthinkable just a few years ago. But speed, he discovered, came with a trade-off. Credentials leaked. Code reviews got skipped. Untested changes slipped into production. By the time anyone noticed, the damage was done.
It's a pattern playing out across the software industry, and it's spawned an entire subcategory of startups trying to contain the chaos. Trigos's answer is Runtime, a Y Combinator-backed security platform that launched publicly in April 2026. The San Francisco company's pitch centers on a straightforward premise: organizations shouldn't have to choose between the velocity AI coding agents provide and the control their security teams demand.
Whether that premise translates into a sustainable business remains to be seen. But Runtime's emergence—alongside a cluster of competitors that surfaced within weeks of each other earlier this year—signals something more fundamental. The tools that promised to make developers superhuman are now raising questions nobody asked when GitHub Copilot first arrived: Who's watching the AI? And what happens when things go wrong?
Building Guardrails at the Speed of Code
Runtime operates as what Trigos calls a "control plane," though the metaphor undersells the complexity. Think of it as a security layer that intercepts every action an AI coding agent tries to take, evaluates it against predefined policies, and either allows it to proceed, asks for human approval, or shuts it down entirely.
The architecture centers on sandboxed environments—isolated virtual machines that spin up in milliseconds, give the agent a clean workspace, and vanish when the session ends. No shared filesystems. No lingering artifacts. Each engineer (or product manager, or designer) using an AI agent gets their own bubble, insulated from everyone else's.
Runtime works with most of the agents teams are already using: Claude Code, GitHub Copilot, Codex, Gemini. You can trigger it from Slack or Linear or Jira, or pipe it through a CLI if you're old-fashioned that way. The system is agent-agnostic by design, which makes sense given how fast the tooling landscape is shifting.
Where Runtime gets interesting—and perhaps more invasive, depending on your tolerance for oversight—is in the policy layer. Teams can allowlist specific bash commands, restrict network access by host or IP range, and require manual sign-off before anything touches production. The system logs everything: prompts, tool calls, file operations, deployments, even cost breakdowns by user and session.
Trigos, who previously founded Mentum (another YC company, acquired by Nuvocargo in October 2025), says Runtime is already serving customers ranging from early-stage startups to unicorns. The company won't name names yet, which is typical for enterprise security vendors at this stage. The YC profile mentions usage across engineering, product, and operations teams, though how deeply those deployments run is harder to verify.
A Market That Materialized Overnight

The timing of Runtime's launch is striking, if not exactly coincidental. Between mid-March and mid-April of this year, a wave of established security vendors—Keycard, Sysdig, Miggo Security, Sonar—announced products or features aimed specifically at AI coding agents. 1Password followed shortly after with runtime-scoped credentials. Capsule Security emerged from stealth with $7 million in seed funding, also betting on runtime security for agents.
It's the kind of coordinated market movement that suggests either everyone saw the same slide deck at a conference, or the pain point is real enough that multiple investors decided to write checks around the same time.
Survey data backs up the hypothesis that this isn't just vendor hype. Sonar claimed in January that AI-generated code accounts for 42% of committed code at surveyed companies, with expectations that figure will cross 65% by 2027. TechRadar Pro reported in May that developers are increasingly trusting AI tools, while separate coverage noted near-universal intentions among UK DevSecOps teams to integrate AI into software development workflows.
The counterargument, of course, is that surveys overstate actual adoption. Developers may intend to use AI agents everywhere, but intention and implementation are different things, particularly in regulated industries or organizations with entrenched approval processes.
Carlos Volante, Runtime's co-founder and CTO, brings credibility from his time at Modern Treasury, where according to his YC bio he helped scale systems processing $350 billion in annual payments and $1 trillion in reconciliation volume. The team is still small—three people as of mid-May—which means they're either very early or very focused. Probably both.
Open Source as Strategy, Not Ideology

One choice that sets Runtime apart: the core is open source. The server runs on AGPLv3, the CLI and sandbox components on Apache 2.0, templates on MIT. That licensing split isn't accidental. It lets Runtime claim community credibility while keeping control of the commercial platform.
The company positions itself explicitly against competitors like E2B, Lovable, Modal, and Replit, framing those as either infrastructure-only plays or IDE-centric tools rather than "complete platforms." Whether that framing holds up depends on how you define completeness, but it's clear Runtime wants to own the entire control layer rather than just one piece of it.
The platform offers self-hosting options, which matters if you're a bank or a healthcare company or anyone else who can't stomach the idea of AI agents touching external infrastructure. Secrets never hit disk, according to the company's documentation. Deploy gates can force manual approval for production changes. The control plane can run entirely in your VPC if that's a hard requirement.
Pricing starts at free—one session, 500 credits, access to a few agents and a base sandbox—and scales up through Builder ($29/month), Teams ($99 per seat), and custom Enterprise deals that include SSO, SCIM, dedicated support, and SLA commitments. It's a standard SaaS ladder, nothing revolutionary.
The Uncomfortable Question Nobody's Asking

Here's what makes Runtime and its competitors interesting: they're building solutions to a problem the industry barely acknowledged six months ago. AI coding agents were supposed to make developers more productive. They did. What nobody emphasized was that productivity without control is just chaos with better throughput.
Runtime's architecture—millisecond sandboxes, policy enforcement at the tool-call level, session-level observability—addresses real risks. Exposed credentials. Bypassed reviews. Untested code in production. These aren't hypothetical concerns; they're the mistakes Trigos watched happen in real time at his last company.
But the deeper question is whether organizations are ready to instrument and monitor AI agents the way Runtime envisions. Every tool call logged. Every prompt recorded. Costs tracked by user and day. It's comprehensive. It's also a surveillance apparatus that makes traditional code review look quaint.
Maybe that's the trade-off. You get to move fast with AI agents, but someone's always watching. For security teams and CTOs losing sleep over what their developers' AI assistants might be doing, that's probably a trade worth making.
For everyone else, the calculus is murkier. Runtime and its competitors are betting that velocity wins, but only if you can prove you haven't lost control in the process. By the look of the market—competitors surfacing every week, funding rounds closing, enterprise pilots spinning up—they might be right.
Whether they're building a category or just a moment remains to be seen. But at least someone's asking the uncomfortable questions now, before the AI agents write code that's too fast to audit and too risky to ignore.
