Skip to main content
TrustGate is the NeuralTrust AI gateway: it routes, secures, and observes LLM and MCP traffic between your applications, agents, and model providers. TrustGate is open source under the Apache 2.0 license. This page installs TrustGate on its own as a Hybrid data plane, with the control plane on NeuralTrust SaaS. The Hybrid page covers the architecture, prerequisites, and network rules that apply here too. The TrustGate image and its chart values block are named agentgateway. That is the same product; see the naming map.
The TrustGate image is published to the NeuralTrust container registry. Pulling it requires a registry key, which NeuralTrust issues with an enterprise offer — contact NeuralTrust to get one.
This install runs agentgateway-proxy (LLM, port 8081), agentgateway-mcp (MCP, port 8082), and one dataagent.
1

Prepare the namespace and chart sources

Do step 1 of the Hybrid install to create the namespace and the image pull Secret, then get the chart sources so values-trustgate.yaml.example is on disk.
2

Create the gateway in the console

Open TrustGate → New Gateway, name it, choose Private, then Kubernetes. Take the CONFIG_SYNC_TOKEN and the DataAgent enrollment JWT from the wizard output — see Console setup.
3

Create the two Secrets

4

Install

Put the cluster-specific values in their own file:
values-cluster.yaml
Then install with the TrustGate slice, which turns on global.products.trustgate and wires the two Secrets:
Then verify and expose the LLM and MCP hostnames as described in Expose both entry points. Only the :8081 and :8082 entry points need the inbound rule, and only agentgateway-configsync.neuraltrust.ai, databridge.neuraltrust.ai, and the telemetry host for your region need egress.