Portkey was acquired by Palo Alto Networks on May 29, 2026. Its roadmap, managed tier, and deepest security capabilities now belong to Palo Alto's Prisma AIRS platform. TrustGate is built by an independent AI security company with a first-party Security Engine, 200+ pre-built MCP servers, and a roadmap controlled by no one but NeuralTrust. That independence is the frame for everything that follows, starting with how the security model was built.
NeuralTrust TrustGate is an AI gateway where enforcement is the reason the product exists. Portkey is also a native AI gateway, but it was built as a control plane for routing, observability, and governance, with security delivered through configurable guardrails rather than a detection engine of its own. Both route LLM and MCP traffic and both offer an open-source gateway, so the meaningful differences sit deeper than the surface feature list.
Those differences are where the security team, the operations team, and the budget owner actually feel the product: how the gateway detects threats, how many tools it can connect without manual work, how many gateways one control plane can run, and how cleanly its data reaches the tools a SOC already uses.
This comparison covers TrustGate and Portkey for architecture leaders deciding which AI gateway fits their enterprise mandate, evaluated on security model, MCP governance, deployment flexibility, and roadmap independence.
TL;DR
- NeuralTrust has native, built-in security with session memory. It analyzes traffic across a whole conversation and enforces inline. Portkey relies on configurable guardrails and third-party integrations, with no session-level memory.
- NeuralTrust ships an integrated catalog of more than 200 MCP servers, connectable in one click. Portkey has an MCP gateway and registry, but servers are configured manually.
- NeuralTrust runs many gateways from one control plane. Portkey's control plane does not manage multiple gateways this way.
- NeuralTrust exports natively to SIEMs (Sentinel, Splunk, QRadar, Datadog, Elastic). Portkey has no native SIEM integration.
Comparison at a Glance
| Capability | NeuralTrust | Portkey |
|---|---|---|
| Open-source license | ✅ | ✅ |
| Flexible deployment (private, cloud) | ✅ | ✅ |
| Built-in security native | ✅ | ❌ |
| MCP catalog integrated (+200 MPC servers) | ✅ | ❌ |
| Multi-gateway control plane | ✅ | ❌ |
| Native SIEM integration | ✅ | ❌ |
| Enteprise readiness | ✅ | ❌ |
Platform Overview
What is NeuralTrust TrustGate?
)
TrustGate is NeuralTrust's AI gateway, built by a security company. It sits between agents and the services they call (LLM providers and MCP servers) and becomes the single place where routing, policy, security, and observability attach.
Its core abstractions are Consumers, Providers, Routes, and Policies: provider connections are configured once and reused, while routing, failover, retries, and caching live in the gateway rather than in each application's code.
Security is the organizing principle. A Security Engine attaches to every route and inspects each request inline, enforcing an allow, block, or transform decision before the request reaches its target, and it maintains session memory so it reasons about a whole conversation rather than one message at a time.
TrustGate also ships an integrated catalog of more than 200 third-party MCP servers, runs many gateways from a single control plane, and exports its events natively to the SIEMs a security team already runs.
)
What is Portkey?
)
Portkey is a native AI gateway that positions itself as a control plane for AI: routing to a large model catalog, virtual keys, guardrails, prompt management, and an observability layer. Its gateway was open-sourced under Apache 2.0 in early 2026.
Its architecture is a split between an open-source data plane (the gateway you can self-host) and a hosted control plane that Portkey runs for analytics, dashboards, and governance. This shape defines what Portkey does well and where it stops: routing and reliability live in the gateway, while the persistent observability, guardrail configuration, and analytics live in a Portkey-hosted layer, and its security is a set of configurable guardrails and third-party integrations rather than a detection engine of its own.
The Palo Alto Acquisition: What It Means for Architecture Leaders
In May 2026, Palo Alto Networks acquired Portkey. For an architecture leader evaluating an AI gateway, that fact matters in three concrete ways.
1. Roadmap control.
Portkey's product direction is now set by Palo Alto Networks, not by an independent team responding to enterprise AI security needs. Features, pricing, and integrations will reflect Palo Alto's broader platform strategy. That may align with your organization's direction (particularly if you are already a Palo Alto customer evaluating Prisma AIRS) or it may not. Either way, it is a variable that did not exist six months ago.
2. Pricing trajectory.
Portkey's open-source gateway remains Apache 2.0. Its hosted control plane and commercial features are now part of a large enterprise security vendor's portfolio. Pricing for those tiers will follow Palo Alto's commercial model, not an independent startup's.
3. Data residency.
Portkey's observability, guardrail configuration, and analytics live in a hosted control plane. That hosted layer is now infrastructure operated by Palo Alto Networks. For organizations in regulated industries with strict data residency requirements, the destination of that telemetry and configuration data is worth verifying explicitly before committing.
NeuralTrust is an independent, purpose-built AI security company. Its roadmap is driven by enterprise AI security requirements, its pricing is not embedded in a broader platform negotiation, and its data residency architecture (including full on-premises and VPC deployment) is a design choice, not a workaround. (Source: Palo Alto Networks acquires Portkey, May 2026)
Built-In Security: Session Memory and Inline Enforcement
Security is where the two products diverge most, and the divergence starts with what each was built to do.
TrustGate carries security inside the gateway. A Security Engine attaches to every route, inspects each request inline, and enforces before the request reaches the model.
Its foundation is session memory: it treats an interaction as a conversation, not a sequence of unrelated calls, so it can catch patterns that only appear across turns, such as an attack or an abuse pattern that is spread deliberately across several innocuous-looking messages. Because detection and enforcement are native, a blocked request and the reason it was blocked are part of the gateway itself.
Portkey approaches security as configurable guardrails: PII redaction, jailbreak and prompt-injection filters, and integrations with third-party guardrail services, applied to individual requests before and after the call. These are useful checks, but they operate on one request at a time, with no session-level memory, so an adversarial pattern that unfolds gradually across a conversation falls outside what they evaluate.
The result is a gateway that filters requests rather than one built, as a security product, to understand and enforce across a whole session.
MCP Catalog Integrated vs Manual Setup
Agents reach their tools over the Model Context Protocol, so the speed and cleanliness of connecting those tools is a real measure of an AI gateway.
TrustGate ships an integrated catalog of more than 200 third-party MCP servers, the tools teams use every day, connectable in one click and governed through the gateway from the moment they are enabled. Teams do not spend engineering time wiring servers up individually, and every connected tool is under policy and observation by default because it runs through the gateway.
Portkey provides an MCP gateway with OAuth support and an MCP registry to register, discover, and version MCP servers. That is real governance machinery, but it is not a ready catalog: each server is added and configured manually, one at a time. The registry organizes what you have connected; it does not remove the work of connecting it. For an organization standing up many tools across many teams, that difference is the gap between a configuration step and an ongoing project.
One Control Plane, Many Gateways
Enterprises rarely run a single gateway. They run several, across regions, environments, and teams, and how that fleet is managed determines the operational cost of scale.
TrustGate runs many gateways from one control plane. A single management layer governs the whole fleet, so policy, configuration, and visibility stay consistent across regions and environments without administering each gateway on its own.
Portkey's control plane does not manage multiple gateways this way. Its hosted control plane centralizes analytics and configuration for the service, but it is not built to operate a fleet of independent gateways from one place. As deployments spread across regions and teams, that becomes more moving parts to run separately rather than one estate governed centrally.
Native SIEM Integration
An AI gateway produces exactly the events a security operations team wants in its SIEM: who called which model or tool, what was blocked, which policies fired, where costs spiked. Whether the gateway delivers those events cleanly into that tooling is what decides if it fits into how an enterprise already runs security.
TrustGate treats this as a first-class capability. It exports and streams its events natively to the SIEMs security teams already run, with confirmed support for Microsoft Sentinel, Splunk, IBM QRadar, Datadog, and Elastic, plus OpenTelemetry as the export standard and a generic webhook for anything else. The events flow into the customer's own pipeline in standard formats, so NeuralTrust becomes one more high-quality source feeding the SOC.
Portkey has no native SIEM integration to select. Its observability lives in the Portkey-hosted control plane, billed around logged requests, and getting that data into a SIEM means working around a layer that was built to be read in Portkey's own dashboard rather than piped into yours. For a security team whose process is anchored on a SIEM, the difference is between a native destination and a workaround.
Final Verdict: Which AI Gateway should you choose?
Portkey is a capable AI gateway for teams that want routing, prompt management, and a hosted observability console, with an open-source gateway at its core. But its security is a guardrail layer rather than a native engine, its MCP servers are wired up by hand, its control plane runs one gateway rather than a fleet, and its data does not flow natively into a SIEM.
NeuralTrust is built for the enterprise that treats its AI gateway as security infrastructure. Security is native to the gateway and reasons across whole sessions; more than 200 MCP servers connect in one click and are governed on contact; one control plane runs the whole fleet of gateways; and events export natively to the SIEMs a SOC already runs.
Both are open source and both deploy privately or in the cloud, so the decision is not licensing or hosting. It is whether you want a gateway that routes and observes AI traffic, or one built to secure and operate it at enterprise scale.
Frequently Asked Questions about NeuralTrust vs. Portkey's AI Gateways
1. What is the main difference between NeuralTrust and Portkey's AI Gateways?
Both are native AI gateways with an open-source core, but NeuralTrust is built by a security company with security native to the gateway, including session memory that reasons across a whole conversation. Portkey is a control plane for routing, observability, and governance, with security delivered through configurable guardrails and third-party integrations rather than its own detection engine.
2. Does Portkey have built-in security like NeuralTrust?
Portkey offers configurable guardrails such as PII redaction, jailbreak detection, and prompt-injection filters, applied to individual requests. It does not have session memory or multi-turn analysis, so patterns that unfold across a conversation are outside what those per-request checks evaluate. NeuralTrust's security is native to the gateway and enforces inline across a whole session.
3. What is the MCP catalog and how is it different from Portkey's MCP registry?
NeuralTrust ships an integrated catalog of more than 200 third-party MCP servers that connect in one click and are governed through the gateway immediately. Portkey provides an MCP gateway and a registry to register, discover, and version servers, but each server is added and configured manually. The registry organizes connected tools; it does not remove the manual work of connecting them.
4. Can Portkey run multiple gateways from one control plane?
No. Portkey's hosted control plane centralizes analytics and configuration for the service, but it is not built to manage a fleet of independent gateways from one place. NeuralTrust runs many gateways from a single control plane, keeping policy and visibility consistent across regions and environments.
5. Does Portkey integrate with SIEM tools?
Portkey has no native SIEM integration; its observability lives in the Portkey-hosted control plane and reaching a SIEM requires working around it. NeuralTrust exports and streams events natively to Microsoft Sentinel, Splunk, IBM QRadar, Datadog, and Elastic, with OpenTelemetry and a generic webhook, so its data feeds a SOC's existing pipeline directly.
Related AI Gateway Comparisons:
- The 9 Best AI Gateways for Enterprise AI Security in 2026
- NeuralTrust vs. Kong: AI Gateway Comparison 2026
- NeuralTrust vs. HAProxy: AI Gateway Comparison 2026
- NeuralTrust vs. Apache APISIX: AI Gateway Comparison 2026
- NeuralTrust vs. MLflow: AI Gateway Comparison 2026
- NeuralTrust vs. LiteLLM: AI Gateway Comparison 2026
- NeuralTrust vs. Solo.io: AI Gateway Comparison 2026
- NeuralTrust vs. Google: AI Gateway Comparison 2026
- NeuralTrust vs. TrueFoundry: AI Gateway Comparison 2026
About the Author
Alessandro Pignati is Lead AI Security Researcher at NeuralTrust, where he leads research on AI and agentic security, advancing techniques to evaluate and secure large language models and autonomous AI systems. He specializes in adversarial machine learning, AI red teaming, LLM security, and AI safety, contributing to the development of secure and trustworthy AI.
NeuralTrust is an AI agent security platform, recognized in the Gartner 2025 Market Guide for AI Gateways and Guardian Agents, and the KuppingerCole 2025 Leadership Compass for Generative AI Defense. Headquartered in Barcelona with ISO 27001 certification.
)
)
)
)
)