Skip to main content
Hybrid data planes open outbound connections to NeuralTrust for configuration sync and DataBridge. Your firewall or security-group rules must allow the destinations below from cluster worker nodes (and from any egress NAT or proxy in front of them). Prefer hostname rules when your firewall supports DNS-based allowlists. The IPs below are for static ACLs. If DNS resolves differently in your region, trust DNS and contact NeuralTrust support to refresh the IP list.

Outbound (egress)

Allow TCP 443 from your cluster egress to: Also allow outbound HTTPS to your container registry (or mirror), LLM upstreams, and managed PostgreSQL / Redis. Product metadata OTLP uses a local collector that forwards to the hosted telemetry endpoint — include that host if your policy lists every external destination.

Inbound (ingress)

Allow traffic from this NeuralTrust source IP into your cluster or edge (typically to your published TrustGate LLM and MCP entry points): Config-sync and DataBridge are outbound-only from your cluster. You do not open inbound ports for those services.