Skip to main content
TrustGuard is the NeuralTrust detection engine for AI agents. It evaluates prompts, responses, and tool calls against your policies and returns findings, backed by ML classifiers. Your applications or gateway call it synchronously and decide how to enforce. TrustGuard is NeuralTrust’s commercial offering and is licensed to enterprise customers. This page installs TrustGuard on its own as a Hybrid data plane, with the control plane on NeuralTrust SaaS. The Hybrid page covers the architecture, prerequisites, and network rules that apply here too.
The TrustGuard image is published to the NeuralTrust container registry. Pulling it requires a registry key, which NeuralTrust issues with an enterprise offer — contact NeuralTrust to get one. See Container images for pulling directly or mirroring into your own registry.
This install runs trustguard-data-plane (port 8081) and dataagent-trustguard.
1

Prepare the namespace and chart sources

Do step 1 of the Hybrid install to create the namespace and the image pull Secret, then get the chart sources so values-trustguard.yaml.example is on disk.
2

Create the TrustGuard in the console

Create a private TrustGuard in TrustGuard → Agent Security. Take the CONFIG_SYNC_TOKEN and the DataAgent enrollment JWT from the wizard output — see Console setup.
3

Create the two Secrets

4

Install

Put the cluster-specific values in their own file:
values-cluster.yaml
Then install with the TrustGuard slice, which turns on global.products.trustguard and wires the two Secrets:
Then verify. TrustGuard is published at trustguard.<domain>; it needs no inbound rule from NeuralTrust, and only trustguard-configsync.neuraltrust.ai, databridge.neuraltrust.ai, and the telemetry host for your region need egress.