NeuralTrust
by NeuralTrust
Discover, secure and govern every AI agent in the enterprise from one gateway
NeuralTrust is an AI agent security platform that discovers every agent running in an enterprise, enforces policy on their traffic in real time, and red-teams them before deployment. It is built for security teams facing agents spread across homegrown apps, ChatGPT, Copilot, Gemini and developer tools such as Cursor, where per-tool security controls do not compose into a single policy.
NeuralTrust sells a four-module platform for securing autonomous AI agents: TrustGate, an agent gateway that connects agents to models and tools and enforces traffic policy; TrustGuard, a runtime security engine that protects agent interactions live; TrustLens, an agent posture management layer that discovers and governs every agent deployed across the company; and TrustTest, an AI red-teaming module that stress-tests models and agents with adversarial attacks before they ship. On 6 August 2026 the company launched its AI Agent Runtime Security Gateway, which centralises enforcement across agent ecosystems without a bespoke integration per agent, inspecting six stages of the agent workflow: incoming prompts for injection attempts, leaked credentials and harmful content; tool requests before execution; responses returned by external tools; authentication and authorisation policy; the agent's reasoning patterns across sessions; and the final response for policy violations and data exposure. The company states sub-100ms enforcement latency, throughput above 20,000 requests per second per node, and 99% multilingual detection using behavioural and contextual analysis rather than prompt-only heuristics, and reports that roughly 1.2% of the millions of agent interactions it inspects daily are malicious. Deployment options span on-premise inside a customer VPC or data centre, SaaS, and a hybrid split-plane architecture separating control and data planes. Founded in Barcelona by Joan Vendrell (CEO, formerly CDO at Mango and previously Amazon and McKinsey), Victor Garcia (CTO) and Alejandro Domingo (COO), with offices in London and New York, NeuralTrust raised a $20M seed on 17 June 2026 led by Alstin Capital — reported as the largest cybersecurity seed round by an EU company to date. Named customers include Banc Sabadell, Iberia, ABANCA, Air Europa, ISDIN, Capgemini, NTT Data and Devoteam.
The CISO or head of security architecture at a large European enterprise where business units have already deployed agents across Copilot, ChatGPT, homegrown RAG apps and developer tools, with no single place to see or govern them
One inventory and one enforcement point covering every agent in the estate, including the ones configured outside your own codebase, instead of a different security control per AI vendor
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Open source
- Target Market
- CISOs, Security Architects, CIOs, CTOs, AI Governance Leads, Enterprise Developers
- Deployment
- Hybrid, Self-hosted, Cloud-first, Open-source
- Headquarters
- Barcelona, Spain
Key Features
- ✓TrustGate agent gateway
Apache-2.0 licensed Go gateway that connects agents to models and tools while enforcing traffic policy centrally
- ✓TrustGuard runtime security
Inspects six stages of the agent workflow live, from incoming prompt through tool calls to the final response
- ✓TrustLens posture management
Discovers every agent deployed company-wide along with its connected tools and execution workflows, producing an inventory security can act on
- ✓TrustTest AI red teaming
Runs adversarial attacks against models and agents pre-deployment so weaknesses are found before an attacker finds them
- ✓Enforcement on externally configured agents
Applies policy to ChatGPT, Google Gemini, Microsoft Copilot, Cursor and Claude Code, not just applications you built
- ✓Sub-100ms enforcement at scale
Vendor states under 100ms added latency and over 20,000 requests per second per node, so enforcement does not become the bottleneck
- ✓Flexible deployment topology
On-premise in your own VPC, SaaS, or a hybrid split-plane model separating the control plane from the data plane
Capabilities
Use Cases
- •Shadow AI agent discovery
Build a complete inventory of agents, their connected tools and their execution workflows across business units that deployed independently
- •Blocking prompt injection and data exfiltration
Inspect prompts and tool responses inline and stop attempts to extract data or hijack a tool before execution
- •Pre-deployment red teaming
Adversarially test a new agent against jailbreak and injection techniques so failures surface in staging rather than production
- •Governing developer AI tooling
Apply enterprise policy to Cursor and Claude Code sessions that would otherwise sit entirely outside the security perimeter
- •Sovereign deployment for regulated industries
Run the platform inside a bank's own data centre so agent prompts and responses never leave the regulated perimeter
Ideal For
Best For
- ✓Discovering shadow AI agents and their connected tools across an enterprise estate that has grown faster than security review
- ✓Enforcing a single prompt-injection, data-exfiltration and tool-use policy across agents from multiple vendors and frameworks
- ✓Red-teaming models and agents with adversarial attacks before they reach production, rather than after an incident
- ✓Regulated European enterprises needing on-premise or VPC deployment so agent traffic never leaves their own perimeter
- ✓Security teams that need enforcement on agents configured outside their codebase, such as Copilot, Gemini, Cursor and Claude Code
Not Ideal For
- ✗Small teams with one or two agents from a single provider — the platform's value is consolidating enforcement across a heterogeneous estate, and that consolidation is the whole cost justification
- ✗Organisations unwilling to put a seed-stage vendor in the critical path of production agent traffic, since the gateway is an inline enforcement point and therefore a availability dependency
- ✗North America-first buyers wanting local reference customers: the disclosed customer base is roughly 80% European and the named logos are almost entirely Spanish and EU enterprises
- ✗Teams hoping to adopt the open-source route seriously — TrustGate is Apache-2.0 but sits at only a handful of GitHub stars, so there is effectively no community, contribution flow or third-party support behind it
Integrations
Deployment
Market Analysis
Pros
- ✓Covers discovery, runtime enforcement, gateway and red teaming in one platform, which is the specific gap in a market of single-purpose AI security tools
- ✓Named, verifiable enterprise customers unusual for a seed-stage vendor: Banc Sabadell, Iberia, ABANCA, Air Europa, Capgemini, NTT Data and Devoteam
- ✓Genuine deployment flexibility including on-premise in a customer VPC and a split control/data plane hybrid, which matters for banks and airlines
- ✓Publishes original adversarial research such as the Echo Chamber jailbreak and contributes to the OWASP AI Testing Guide, rather than only marketing content
- ✓Backed by the largest cybersecurity seed round raised by an EU company to date at $20M, alongside European Innovation Council and Spanish state research funding
Cons
- ✗Seed-stage vendor sitting inline in production agent traffic — the gateway is an availability and latency dependency as well as a security control
- ✗No published pricing at all; the pricing URL returns a 404, so cost discovery requires a full sales engagement
- ✗The open-source story is thin in practice: TrustGate is Apache-2.0 but carries only a handful of GitHub stars, so there is no meaningful community or third-party contribution
- ✗Performance and detection figures — sub-100ms latency, 20K requests per second per node, 99% multilingual detection, 1.2% malicious traffic — are all vendor-published and not independently benchmarked
- ✗Customer base is roughly 80% European and heavily Spanish, so North American buyers will find few local references
- ✗No G2, Capterra or TrustRadius listing and no Hacker News discussion of the product, so there is no independent practitioner feedback available yet
Pricing
TrustGate (open source)
$0
- ✓Apache-2.0 licensed agent gateway
- ✓Self-hosted
- ✓Written in Go
Enterprise platform
Contact for pricing
- ✓TrustGuard runtime security
- ✓TrustLens posture management
- ✓TrustTest red teaming
- ✓On-premise, SaaS or hybrid deployment
- ✓Sub-100ms enforcement
There is no pricing page — the site returns a 404 for it — so the commercial platform is entirely sales-led with no published rates or self-serve tier. The only free entry point is TrustGate, the Apache-2.0 licensed gateway on GitHub, which you can self-host at no cost; TrustGuard, TrustLens and TrustTest are all commercial. Given a customer base where 92% exceed $1B in revenue, expect enterprise contract sizing.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 4 on domains other than neuraltrust.ai.
- 1.neuraltrust.ai — neuraltrust.aivendor
- 2.neuraltrust.ai — neuraltrust raises 20mvendor
- 3.techedgeai.com — neuraltrust launches ai agent runtime security gateway
- 4.thesaasnews.com — neuraltrust raises 20m seed
- 5.github.com — TrustGate
- 6.eu-startups.com — barcelona based neuraltrust raises e17 2 million to secure a
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Stairwell Backstory
Agentic malware investigation that maps blast radius from every executable you have ever run
Drata AI Agent Governance
Discover every AI agent, block policy violations inline, and prove it to an auditor
Hush Security
Kill standing credentials — discover every AI agent and broker just-in-time access at runtime
Astelia
AI-native exposure management that proves which vulnerabilities an attacker can actually reach, then drives the fix