Skip to main content
Leave trustlens.enabled and watchdog.enabled off unless NeuralTrust asks you to enable them.
Product telemetry export is mandatory in Hybrid and always on — there is no global.clickstack.enabled: false opt-out. TrustGate and TrustGuard send OTLP to a co-located, enrollment-backed egress collector, so the tokens you collect when creating each product are required. For a deployment with no NeuralTrust SaaS dependency, use External mode instead.
Configuration sync is pull-based. TrustGate and TrustGuard dial the SaaS control-plane endpoint from the customer environment; no inbound control-plane connection into the customer network is required. Choose Kubernetes in the private TrustGate wizard to obtain setup and credential input. Review and map that input into the current maintained neuraltrust-platform chart or manifests; do not apply the generated values or local-chart command unchanged. Choose Manual for custom manifests; it provides CONTROL_PLANE_JWT and DATA_AGENT_JWT.

Managed stores (required)

Sizes: Configuration.

Platform and routing

global.platform: aws · gcp · azure · openshift · kubernetes.
global.domain combines with the default gateway and mcp prefixes to create separate LLM/proxy and MCP ingress hosts. Enter the corresponding full URLs in Settings → Agent Gateway → General. Ingress class and annotations are provider-specific. global.imageRegistry rewrites the registry prefix for mirrors.
See Configuration and Secrets.