All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
NeuralTrust puts one gateway in the path of every AI-agent request, so a regulated bank or airline that routes its agent traffic through it faces real work to move off it. TrustGate's core is open source, offered to seed adoption, but a larger vendor can study the open code and rebuild the same control point. NeuralTrust names customers such as Iberia, Abanca, and Banc Sabadell and holds Gartner recognition as an AI-gateway vendor. It is most defensible where a European buyer has already wired agent traffic through the gateway, and weakest if Palo Alto Networks or a cloud provider ships an agent gateway buyers find good enough.
| Description | NeuralTrust helps enterprises discover and secure the AI agents running across their teams, with products for runtime protection, a gateway that connects agents to models and tools, agent posture management, and adversarial red teaming. | [f1] |
|---|---|---|
| HQ | Barcelona, Spain | [f2] |
| Funding | $20M total | [f3] |
| Latest funding | Seed, $20M (June 2026, led by Alstin Capital) | [f3] |
| Deployment | Hybrid, SaaS, Self-hosted | [f4] |
| Product | What it does |
|---|---|
| NeuralTrust | NeuralTrust: AI gateway and runtime firewall that screens LLM and agent traffic for injection attacks and data leaks, plus automated red teaming. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
NeuralTrust is an AI gateway and runtime firewall that screens LLM and agent traffic for injection attacks and data leaks, plus automated red teaming. It is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer is clear (enterprise teams deploying GenAI chatbots and agents), but the Echo Chamber pain rests on NeuralTrust's own jailbreak research echoed by The Hacker News rather than independent quantification, qualitative pain from a single originating source placing this at 3. [s1, s8, s3] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The open-source TrustGate gateway with a public self-hosted install, the TrustTest red-teaming engine, and the Generative Application Firewall give detailed, externally checkable capability, and the Echo Chamber research written up as an arXiv preprint with an ICREA and Universitat Pompeu Fabra co-author is an externally checkable validation point. The open-source gateway plus the published research justify the high score. [s2, s7, s8, s16] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Gartner named NeuralTrust in its 2025 to 2026 AI Gateways and Guardian Agents market guides, multiple analyst-category signals that buyers are sourcing this control, but as an emerging-category guide placement shared with rival vendors it sits at 4 rather than the demand-established 5. [s6, s8, s5, s14] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | CEO Joan Vendrell was previously chief data officer at Mango and worked at Amazon and McKinsey per TechFundingNews, and the public record shows no prior security exit, so the commercial pedigree is real but not in-domain. Echo Chamber is written up as an arXiv preprint and the later GPT-5 jailbreak drew Dark Reading coverage, a genuine signal that supports the score without lifting it further. Placed at 3. [s11, s8, s5, s16, s17, s22] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Independent funding coverage names several enterprise customers, including Iberia, AirEuropa, Abanca, and Banc Sabadell, but customer-side references stay thin, with only ABANCA speaking on the record and no published deployment detail. Gartner recognition, a 4YFN award, and ISO 27001 support real interest, holding the score at 3 rather than the 4 that multiple referenceable customers would support. [s1, s5, s12, s13, s14, s15, s18, s21] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | NeuralTrust raised a $20 million seed led by Alstin Capital, broadly proportional to its enterprise go-to-market motion, with shipping across TrustGate, TrustGuard, TrustLens, and TrustTest plus ISO 27001 certification. It reports doubling its 2025 recurring revenue but discloses no dollar figures, so output per dollar stays unconfirmed, the honest default at 3. [s21, s2, s4, s5] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Gartner names AI gateway and guardian-agent slots in its market guides, a Gartner Peer Insights vendor page places NeuralTrust in the AI Gateways market based on public information, and the EU-Startups directory places it there, but the category carries several competing labels and remains at the Gartner market-guide (forming) stage, which holds it at 3. [s6, s10, s5, s14, s20] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | An open-source gateway plus runtime firewall and red teaming is absorbable by platform vendors and cloud providers moving into AI traffic management, and the open-source choice lowers switching cost. The research brand raises replication cost but is not a structural moat. [s2, s10, s8] |
NeuralTrust treats the live traffic flowing into an enterprise's GenAI applications and agents as something security teams cannot inspect or control with conventional tools. The company frames the buyer as the security team standing up LLM chatbots and agents inside regulated processes, where a prompt injection or a data leak reaches production systems. Its documentation positions the product as the runtime and red-team layer for that traffic.
The risk NeuralTrust points to is demonstrated, not hypothetical. Its own researchers built the Echo Chamber jailbreak, a multi-turn context-poisoning attack that The Hacker News reported bypassed GPT-4o and Gemini guardrails, which establishes that the safety filters enterprises rely on can be steered into producing disallowed output. A bank deploying a customer-facing chatbot is the concrete buyer this work speaks to. [s3, s8, s1]
The NeuralTrust platform spans a runtime layer, an agent-security layer, and an offensive testing layer rather than a single control. TrustGate is an open-source AI gateway that routes and screens LLM traffic and installs through a public self-hosted install command, and the company announced a Generative Application Firewall, while the cited pages ground runtime inspection and prompt-injection blocking in TrustGuard. Around the gateway sit prompt moderation, sensitive-data masking, bot detection, and agent-monitoring modules.
TrustTest is the offensive half, an automated red-teaming engine the company says carries tens of thousands of real-world adversarial attacks drawn from its own research. NeuralTrust folded the Echo Chamber jailbreak into both TrustGate and TrustTest so customers can simulate the multi-turn attack before it reaches production.
The research output demonstrates the capability the product sells. NeuralTrust researchers wrote Echo Chamber up as an arXiv preprint with a co-author from Universitat Pompeu Fabra in Barcelona and disclosed a further jailbreak against GPT-5 that Dark Reading reported, work that shows the team finds the attacks its firewall is built to stop. [s2, s7, s11, s16, s23]
NeuralTrust competes in AI gateway and runtime security against both independents and the platform vendors moving into the same slot. Lakera, which Check Point acquired, and Prompt Security cover overlapping runtime guarding and red teaming, while larger API and platform vendors move toward AI gateway offerings of their own. The category NeuralTrust sells into is one larger vendors are building toward.
The open-source gateway is NeuralTrust's adoption entry point and its structural weakness at once. Giving TrustGate away wins installs and a place in customer traffic, but a gateway is the layer a platform vendor can bundle into a deal an enterprise already signs, and an open-source one is straightforward for a larger player to match. Its durable separation is the research brand, which a bundled competitor cannot quickly reproduce. [s2, s8, s10]
Research is NeuralTrust's clearest go-to-market engine, and it generates attention rather than named revenue. The Echo Chamber and GPT-5 jailbreak findings drew coverage in The Hacker News and other outlets, and Gartner named NeuralTrust in guides for AI gateways and guardian agents, which builds inbound awareness and analyst validation. This is demand generation through research and analyst recognition rather than proof of paid deployments.
Verifiable customer proof is thinner than the recognition. A named testimonial from the Spanish bank ABANCA describes stress-testing a customer chatbot for a safe go-live, and the homepage logo wall shows ISDIN, Iberia, Sabadell, and Air Europa, but these appear as vendor-displayed logos and testimonials rather than independently reported references. A Gartner Peer Insights vendor page lists NeuralTrust in its AI Gateways market based on public information, a Gartner surface distinct from the company's own announcements of its Gartner recognition. NeuralTrust also won best cybersecurity startup at 4YFN during MWC 2026 and earned ISO 27001 certification.
The motion is early and direct. NeuralTrust routes prospects to a demo request and a free gateway download, leaning on its research and analyst profile to open enterprise conversations. A publicly referenceable paying enterprise would be the signal that this attention has converted into deployments. [s8, s6, s5, s12, s13, s15, s18, s20]
NeuralTrust's founders pair business-scaling experience with a strong research bench rather than prior security exits. Co-founder and CEO Joan Vendrell previously held roles at Mango, Amazon, and McKinsey, and co-founders Victor Garcia (engineering) and Alejandro Domingo (GTM) appear on the company team page, but the public record shows no prior security company built and sold. The leadership signal is commercial and operational, not a track record of shipping security products.
The research record is the team's strongest public asset. NeuralTrust researcher Ahmad Alobaid and colleagues wrote the Echo Chamber jailbreak up as an arXiv preprint, co-authored with Carlos Castillo of ICREA and Universitat Pompeu Fabra in Barcelona and with CEO Joan Vendrell among the authors, and the team disclosed a follow-on GPT-5 jailbreak reported by Dark Reading. A preprint is published research, not peer-reviewed work, but it is a sustained, externally checkable stream of in-domain adversarial output for a company this young.
The recognition gives that work outside validation. Independent outlets covered the Echo Chamber disclosure and Gartner cited NeuralTrust across multiple AI security guides, which separates a sustained research program from a single covered finding. [s8, s11, s5, s16, s17, s22, s23]
NeuralTrust's trust posture centers on a published certification and a flexible deployment model. The company states it is ISO 27001 certified, the recognized information-security management standard that a procurement team can ask to see, which is a stronger starting artifact than the same-asset peers that show no attestation. The announcement names Insight Assurance as the issuer, following an independent audit, and states that the certificate runs through 2029 with annual surveillance audits, so a buyer can check the issuer and the certificate's currency from the public page. For a vendor whose product inspects proprietary AI traffic, that certification addresses an early security-review question.
The company's trust portal at trust.neuraltrust.ai renders only a sign-in form, so the public verification path is the announcement rather than a browsable document set. A buyer who wants the certificate or supporting documents requests portal access rather than downloading them from a public page.
Deployment choice supports buyers who cannot send traffic to a vendor cloud. NeuralTrust documents SaaS, hybrid, and self-hosted modes built on a control-plane and data-plane split, and the open-source gateway can run inside the customer's own environment. A bank or healthcare buyer that needs sensitive prompts to stay in-house can run the data plane locally, which lowers the exposure objection that a runtime inspection product raises. [s5, s3, s12, s19]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Lakera | competes with | Shipped automated AI red teaming and runtime guardrails before Check Point acquired it, contesting NeuralTrust's testing and runtime layers. | |
| Prompt Security | competes with | Covers AI gateway, runtime protection, and the same enterprise GenAI buyer, the closest same-asset independent to NeuralTrust's gateway plus firewall. | |
| Aim Security | competes with | Guards runtime LLM traffic and models for the enterprise AI buyer, overlapping NeuralTrust's runtime firewall on shared assets. | |
| Lasso Security | competes with | Runs discovery, red teaming, and runtime guardrails for the enterprise AI stack, overlapping NeuralTrust's testing and runtime motion. | |
| Cloudflare | adjacent | Ships its own AI gateway in front of LLM traffic and could fold gateway-level screening into platform deals enterprises already sign. | |
| OpenAI | adjacent | Model provider that could ship native guardrails for the models NeuralTrust screens, narrowing the third-party budget line. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with NeuralTrust.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
NeuralTrust's gateway brokers each model, tool, and protocol request, so a customer routing all agent traffic through it faces real re-integration work to leave, and its named European banks and airlines do not swap security controls casually. Working against that, the open-source core lets a larger vendor study and bundle the same control point, the gateway routes to models NeuralTrust does not own, and its flagship jailbreak techniques sit in the OWASP taxonomy, published work available to rivals. NeuralTrust is most defensible where a regulated European buyer has already wired its agent traffic through the gateway, and weakest if Palo Alto Networks or a cloud provider ships a competing agent gateway buyers find good enough.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | TrustGate, TrustGuard, and TrustLens are product software sold in SaaS, hybrid, and customer-hosted modes, with no analyst-staffed managed service or accountability-for-outcomes layer in fetched sources. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Routing every model, tool, and protocol call through TrustGate makes the gateway a central enforcement point a customer must re-integrate to leave, real friction short of data residency lock or a network effect, and the open-source core lowers the lock further. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | NeuralTrust holds its own ISO/IEC 27001:2022 certification, table-stakes assurance that eases procurement without blocking a substitute, and the cited record identifies no regulation mandating this product class. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building a distributed gateway that brokers LLM, MCP, and tool calls, a runtime engine that tracks multi-turn attacks across surfaces, and a red-teaming engine, while running original jailbreak research that entered the OWASP taxonomy, is applied adversarial security at depth. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Independent reporting names multiple regulated enterprise customers, Iberia, AirEuropa, Abanca, and Banc Sabadell, mostly billion-dollar enterprises, so procurement and legal gate the replacement path for the platform. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Agent calls a customer routes through TrustGate depend on the gateway while it is deployed, but the customer can swap it for another gateway, and the platform still ingests from the models and tools it does not own. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The team's flagship jailbreak techniques are incorporated into the OWASP AI Security Project taxonomy and the TrustTest attack taxonomy spans the public prompt-injection and data-leakage classes, so the published side of the adversarial work is available to rivals, the gateway routes to models NeuralTrust does not own, and no named non-public corpus is quoted. |
NeuralTrust sells to the large, regulated enterprise standing up AI agents across many teams. The company describes a buyer where one team builds a customer-service agent on one model provider while another automates back-office work on a different one, leaving security teams unable to say how many agents run or what each may do. That fragmentation is the problem it scopes, and its named customers are global banks and airlines, with government customers reported but unnamed, rather than small teams.
The customer base is concentrated at the top of the market and tilted toward Europe. NeuralTrust reports that most of its customers are billion-dollar enterprises, the bulk of them based in Europe, and names Iberia, AirEuropa, Abanca, and Banc Sabadell among them. That profile fits a product whose self-hosted and air-gapped modes target defence, government, and the financial sector.
The European concentration is a deliberate foothold as much as a starting point. TechFundingNews reports that several of NeuralTrust's government and banking customers seek providers headquartered outside the United States as EU AI Act compliance requirements tighten, which gives a Barcelona vendor a procurement opening tied to where it is headquartered rather than to product features. The company states a goal of leading the European market by the end of 2026 before expanding internationally.
NeuralTrust's claimed advantage is owning the single point every agent call passes through. TrustGate is an agent gateway that brokers each model, tool, and protocol request, which the company frames as turning thousands of individual security decisions into one a customer controls and meters. It routes calls to any model, OpenAI, Anthropic, or self-hosted, and adds inline prompt inspection, PII redaction, and semantic caching at that chokepoint.
The runtime and offensive layers extend the gateway rather than wrap a single model. TrustGuard inspects every interaction and tracks conversation context across turns, catching a multi-turn attack where a jailbreak fails once and lands on a later attempt. Tech.eu describes the core platform as three products, TrustGate, TrustGuard, and TrustLens, while NeuralTrust separately markets TrustTest, a red-teaming engine that runs algorithmic adversarial probes against a customer's LLMs and agents across a taxonomy spanning prompt injection, indirect injection, and data leakage. TrustLens maps every agent in the enterprise and tracks its behaviour.
The research record is the externally checkable proof of the team's adversarial depth. NeuralTrust documented the Echo Chamber multi-turn jailbreak, reported by The Hacker News, and the Semantic Chaining multimodal attack, and Tech.eu reports both have been incorporated into the OWASP AI Security Project taxonomy. The durable engineering asset is real, though TrustGate routes to commercial or self-hosted models rather than a model NeuralTrust owns, and the flagship attacks are now published.
Research and analyst recognition are NeuralTrust's most visible demand surfaces. The Echo Chamber and follow-on jailbreak findings drew security-press coverage, and Gartner named the company a Representative Vendor in two AI-security Market Guides, third-party surfaces that build inbound awareness, though the company's lead sources and sales mix are not disclosed. A Gartner Peer Insights vendor page lists NeuralTrust in its AI Gateways market based on public information, a Gartner surface distinct from the company's own recognition announcements. The company pairs that with an open-source gateway download meant to seed adoption ahead of a paid upgrade.
The named-customer record is corroborated twice over. TechFundingNews independently names Iberia, AirEuropa, Abanca, and Banc Sabadell as customers, and NeuralTrust's own funding announcement corroborates the same four, and the company reports doubling its full-year 2025 annual recurring revenue in Q1 2026, though it disclosed no dollar figures. A strategic partnership with KPMG, plus collaborators including Capgemini and Sopra Steria, gives it a channel into large enterprise accounts.
The capital now matches the enterprise ambition more closely than before. NeuralTrust raised a $20 million seed led by Alstin Capital, with VentureFriends, Seaya, Kibo Ventures, and Banc Sabadell participating, a sizable round for a European cybersecurity startup. The plan is to deepen product integration, grow engineering, and expand across Europe while growing its international presence.
NeuralTrust does not publish list prices, but states enterprise pricing is based on the number of protected apps and agents, traffic volume, and deployment model, per its homepage FAQ. The rate card and contract mechanics remain undisclosed. A vendor that names the charged dimensions without a public rate card usually targets large negotiated enterprise deals, which fits a customer base of mostly billion-dollar enterprises.
The open-core model implies a land-and-expand meter rather than a single list price. NeuralTrust offers TrustGate as an open-source download a team can run locally, then frames the upgrade around governance, compliance, and depth of control across many teams, which reads as a scale-based enterprise tier layered over a free entry point. The paid platform charges on the number of protected apps and agents, traffic volume, and deployment model, while only the exact rate card and contract terms remain undisclosed.
The inferable belief is that buyers pay for centralized control over agent traffic rather than for any single feature. Confirming the unit and whether consumption is capped would require a sales conversation, which the hidden-price posture and demo-request flow signal is the intended route.
NeuralTrust delivers its platform in deployment modes chosen to match compliance needs. It offers a SaaS option, a hybrid cloud model that keeps a SaaS control plane while the data plane stays privately hosted so data never leaves the customer boundary, and an on-premises or air-gapped mode for defence, government, and financial-sector buyers. That range lets a bank or agency run inspection of sensitive prompts inside its own perimeter.
The architecture centers the gateway as the enforcement point. TrustGate brokers every model, tool, and protocol call, TrustGuard ingests agent traffic from gateways, SDKs, browsers, sidecars, and log streams and applies allow, block, transform, or alert decisions depending on the integration, and TrustLens tracks agent posture. NeuralTrust states that it inspects a large daily volume of agent interactions and intervenes on the small share it flags as malicious, a self-reported operating figure rather than an independently audited one.
The delivery is product rather than managed service in fetched sources. No analyst-staffed operations layer or accountability-for-outcomes offering appears, so the customer configures and runs the controls itself. The deployment pages do publish operational performance figures, including sub-100 ms p95 added latency and 20k+ requests per second per node. Published uptime and support SLAs do not surface in fetched pages.
NeuralTrust holds its own information-security certification, a meaningful starting artifact for a product that inspects privileged AI traffic. The company states it achieved ISO/IEC 27001:2022 certification, the recognized information-security management standard a procurement team can ask to see. For a vendor whose gateway and runtime engine sit in the path of a customer's sensitive prompts, that attestation addresses an early security-review question.
Deployment choice carries much of the trust case. Because the hybrid mode keeps the data plane inside the customer's boundary and the open-source gateway can run in the customer's own cloud, a regulated buyer can avoid sending proprietary prompts to a vendor cloud at all. The air-gapped mode extends that to defence and government buyers who cannot use a SaaS control plane.
The attestation is enterprise-grade but table-stakes rather than a moat. ISO 27001 eases procurement without blocking a substitute, the cited record identifies no regulation mandating this product class, and a buyer whose traffic the platform inspects should still resolve data-handling, model-provider, and retention terms in a formal review beyond the certification.
NeuralTrust positions itself as the control layer that all enterprise agent traffic flows through rather than a point tool. By brokering every model, tool, and protocol call at the gateway and enforcing at runtime across every surface agents run on, it aims to be, in its own words, the layer enterprise AI runs on, a claim that rests on becoming the single chokepoint for agent activity.
The open-source core is the adoption strategy and the structural weakness at once. Offering the open-source core is meant to win installs and a place in customer traffic, and the gateway brokers calls to any model so a customer is not locked to one provider, but an open gateway is also the layer a platform vendor could study and bundle into a deal an enterprise already signs. The durable separation is occupying the enforcement point first, not the code.
The ecosystem play leans on systems integrators rather than a marketplace. NeuralTrust names KPMG as a strategic partner and Capgemini and Sopra Steria as collaborators, relationships that can route it into large enterprise accounts, while the platform does not own the underlying models or tools it routes and governs.
NeuralTrust pairs commercial and operational pedigree with a research bench, and the reviewed sources document no prior security-sector exit, though the funding release notes COO Alejandro Domingo previously scaled a startup to an exit. CEO Joan Vendrell led AI deployment and security as Chief Data Officer at Mango after roles at Amazon and McKinsey, a leadership signal that is commercial and operational more than a track record of shipping security products. The co-founders join him from consulting and regulated-industry security roles, with CTO Victor Garcia having led security architecture in regulated telecom and banking and COO Alejandro Domingo having led AI transformation as an Associate Partner at McKinsey.
The research output is the team's strongest public asset. NeuralTrust documented the Echo Chamber multi-turn jailbreak and the Semantic Chaining multimodal attack, both reported as incorporated into the OWASP AI Security Project taxonomy, a sustained and externally checkable stream of in-domain adversarial work for a company this young.
The backer bench reinforces the signal. The $20 million seed drew Alstin Capital as lead, with VentureFriends, Seaya, Kibo Ventures, and Banc Sabadell participating. That volume of venture backing in a single seed round is itself a signal about how investors read the team.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | NeuralTrust: The Platform for AI and Agent Security | official | 2026-07-09 |
| f2 | About us | NeuralTrust | official | 2026-06-14 |
| f3 | Tech.eu: NeuralTrust closes 20M to expand AI agent security platform | press | 2026-06-17 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | NeuralTrust homepage with product line and customer testimonials | official | 2026-06-13 |
| s2 | NeuralTrust AI gateway (TrustGate) product page “Code: docker compose -f docker-compose.prod.yaml up -d” | official | 2026-06-13 |
| s3 | NeuralTrust documentation with deployment modes | official | 2026-06-13 |
| s4 | NeuralTrust automated red teaming (TrustTest) page | official | 2026-06-13 |
| s5 | NeuralTrust news index with Gartner, ISO 27001, and 4YFN award | official | 2026-07-08 |
| s6 | NeuralTrust recognized by Gartner Market Guide for Guardian Agents | official | 2026-06-13 |
| s7 | NeuralTrust Echo Chamber attack announcement “NeuralTrust has already integrated the Echo Chamber Attack into its AI Gateway (TrustGate) and Red Teaming (TrustTest) solutions” | official | 2026-06-13 |
| s8 | The Hacker News on NeuralTrust's Echo Chamber jailbreak “Early planted prompts influence the model's responses, which are then leveraged in later turns to reinforce the original objective.” | press | 2026-06-13 |
| s9 | BankInfoSecurity on the Echo Chamber attack detailed by NeuralTrust “A proof-of-concept attack detailed by Neural Trust shows how bad actors can steer LLMs into producing prohibited content, without issuing an explicitly harmful request.” | press | 2026-06-13 |
| s10 | EU-Startups directory entry for NeuralTrust (Spain) “TrustGate: The fastest open-source AI gateway, enabling enterprises to scale LLMs and agents with zero-trust security” | other | 2026-06-13 |
| s11 | NeuralTrust research blog (GPT-5 and OpenAI Atlas jailbreaks) | official | 2026-06-13 |
| s12 | NeuralTrust ISO 27001 certification announcement “NeuralTrust has achieved ISO/IEC 27001:2022 certification, the international standard for information security management. The certification was issued by Insight Assurance following an independent audit” | official | 2026-07-08 |
| s13 | NeuralTrust wins Best Cybersecurity Startup at 4YFN during MWC 2026 “NeuralTrust was named Best Cybersecurity Startup at 4YFN during MWC 2026, receiving the Digital Horizons Award in recognition of its work securing AI agents operating inside enterprise environments.” | official | 2026-06-13 |
| s14 | NeuralTrust recognized as Representative Vendor by Gartner Market Guide for AI Gateways “NeuralTrust has been recognized as a Representative Vendor in Gartner's Market Guide for AI Gateways.” | official | 2026-06-13 |
| s15 | ABANCA customer testimonial on the NeuralTrust homepage “With NeuralTrust we stress-tested our chatbot with GenAI 'SOFia,' validating a safe go-live that meets financial-sector security and regulatory standards.” | official | 2026-06-13 |
| s16 | arXiv preprint: The Echo Chamber Multi-Turn LLM Jailbreak “Authors: Ahmad Alobaid (NeuralTrust), Marti Jorda Roca (NeuralTrust), Carlos Castillo (ICREA and UPF), Joan Vendrell (NeuralTrust)” | research | 2026-06-16 |
| s17 | About us | NeuralTrust team page “Meet our team Joan Vendrell GTM Victor Garcia Engineering Alejandro Domingo Salvador GTM” | official | 2026-06-16 |
| s18 | NeuralTrust homepage customer logo wall “Trusted by the world's leading companies (logos: sabadell-logo.png, iberia-logo.png, abanca-logo.png, isdin-logo.png, air-europa.png)” | official | 2026-06-16 |
| s19 | NeuralTrust Trust Center (login-gated portal, rendered check) “Sign in Use your email and password to sign in” | official | 2026-07-08 |
| s20 | Gartner Peer Insights: NeuralTrust in the AI Gateways market, based on public information “NeuralTrust focuses on addressing security and compliance challenges related to AI agents and large language model (LLM) applications. The company identifies vulnerabilities in AI systems, implements measures to prevent attacks, and monitors system performance” | other | 2026-06-29 |
| s21 | TechFundingNews: NeuralTrust raises 20M, Europe's largest cybersecurity seed “The $20 million will be used to hire more engineers, improve integration across the three product layers, and expand throughout Europe.” | press | 2026-06-29 |
| s22 | TechFundingNews: NeuralTrust founder backgrounds “Vendrell was previously chief data officer at Mango and also worked at Amazon and McKinsey. Domingo led AI transformation projects as an associate partner at McKinsey before co-founding NeuralTrust. Garcia designed security systems for telecoms and banks.” | press | 2026-06-29 |
| s23 | Dark Reading: NeuralTrust's Echo Chamber technique used to jailbreak GPT-5 “The successful hybrid approach of the Echo Chamber and Storytelling technique to jailbreaking GPT-5, released Aug. 7, demonstrates how these techniques continue to evolve.” | press | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | NeuralTrust homepage: platform for AI and agent security “Agent Runtime Security Protect agent interactions in real time TrustGuard. Agent Gateway Connect agents to models and tools securely TrustGate. Agent Posture Management Discover and govern every agent.” | official | 2026-06-17 |
| s2 | NeuralTrust TrustGate agent gateway (open source, LLM/MCP/A2A) “Point your agents at any model, OpenAI, Anthropic, or self-hosted. Every call routes through one place you control and meter. OPEN SOURCE Run TrustGate locally or self-hosted in your own cloud in minutes. Start from the open core.” | official | 2026-06-18 |
| s3 | NeuralTrust TrustGuard runtime security and deployment modes “TrustGuard inspects every interaction and stops attacks at the moment of execution. SaaS. Hybrid cloud SaaS control plane, privately hosted data plane. Data never leaves your boundary. On-premises / air-gapped Full isolation. For defence, government, and financial sector.” | official | 2026-06-17 |
| s4 | NeuralTrust TrustTest AI red teaming and evaluation “TrustTest is a red-teaming and evaluation framework that attacks your LLMs and agents with state-of-the-art adversarial techniques, then grades how they hold up. One taxonomy of attacks Prompt injection Indirect injection PII and data leakage.” | official | 2026-06-17 |
| s5 | NeuralTrust raises 20M to secure AI agents (seed round, investors, products, customers, partners) “today announced a $20 million seed round. The round was led by Alstin Capital, with participation from VentureFriends, Seaya, Kibo Ventures, Banc Sabadell. NeuralTrust's customers include AirEuropa, Abanca, Iberia, and Banc Sabadell, alongside other global banks, airlines, energy companies.” | official | 2026-06-18 |
| s6 | Tech.eu: NeuralTrust closes 20M to expand AI agent security platform “Echo Chamber and the multimodal attack vector Semantic Chaining, both incorporated into the OWASP AI Security Project taxonomy. NeuralTrust's platform combines three products: TrustGate, which manages agent traffic across models and tools, TrustGuard, runtime security for AI agents, and TrustLens.” | press | 2026-06-18 |
| s7 | TechFundingNews: NeuralTrust seed (founders, customers, ARR, competition) “Its customers include Iberia, AirEuropa, Abanca, and Banc Sabadell. Palo Alto Networks bought Protect AI for about $500 million. With EU AI Act compliance requirements tightening, several of its government and banking customers are actively seeking providers headquartered outside the US.” | press | 2026-06-17 |
| s8 | NeuralTrust ISO 27001 certification announcement “NeuralTrust has achieved ISO/IEC 27001:2022 certification, the international standard for information security management.” | official | 2026-06-17 |
| s9 | The Hacker News: Echo Chamber jailbreak tricks LLMs “Early planted prompts influence the model's responses, which are then leveraged in later turns to reinforce the original objective.” | press | 2026-06-13 |
| s10 | NeuralTrust named Representative Vendor in Gartner Market Guide for AI Gateways “NeuralTrust has been recognized as a Representative Vendor in Gartner's Market Guide for AI Gateways.” | official | 2026-06-13 |
| s11 | Gartner Peer Insights: NeuralTrust in the AI Gateways market, based on public information “NeuralTrust focuses on addressing security and compliance challenges related to AI agents and large language model (LLM) applications. The company identifies vulnerabilities in AI systems, implements measures to prevent attacks, and monitors system performance” | other | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.