Runtime security for AI agents is decided at the moment the agent acts, not by the tests it passed before it shipped or the network it sits behind. Agents do not just answer, they execute. They call tools, trigger workflows, and take real actions, and the attacks that matter arrive inside the action itself. The question is whether your security enforces inline on the agent's execution path, or whether it tests that agent, catalogs it, watches the logs, and filters the traffic at the network edge. Those are different jobs, and only one of them stops an unsafe tool call in flight.
TrustGuard is NeuralTrust's AI runtime security, and it is the first runtime security built to extend across every AI agent, without a custom integration rebuilt for each tool or framework. Zscaler comes to AI security from network security. It is a cloud-delivered platform that entered the category by acquiring SPLX, a red-teaming and testing startup, and folding it into the Zero Trust Exchange. The result pairs SPLX's testing, discovery, and governance with app-level guardrails and log scanning at runtime, all delivered from Zscaler's cloud. This comparison covers both on the terms that decide AI runtime security: whether protection enforces on the agent's execution path, where it can run, and whether the agent is treated as an identity and an action rather than an asset to test and monitor.
TL;DR
- NeuralTrust enforces inline on the agent execution path. TrustGuard blocks unsafe tool calls in-flight before they execute. Zscaler's AI runtime is SPLX's input and output guardrails plus threat inspection that scans logs after the fact.
- NeuralTrust runs anywhere, including on-premises and air-gapped. Zscaler's AI security is cloud-delivered, so the most sensitive environments are the ones it does not fit.
- NeuralTrust ships a native AI gateway with enforcement inline. Zscaler is a network security proxy, not an AI gateway, and SPLX has no gateway of its own.
- NeuralTrust protects every agent surface with one policy model and authenticates the agent to the tool at runtime. Zscaler discovers agents, red-teams them, and scans them statically, but does not enforce across the agent execution path or authenticate the agent to the tool.
NeuralTrust vs Zscaler: AI Runtime Security at a Glance
| Capability | NeuralTrust | Zscaler |
|---|---|---|
| Private and air-gapped deployment | ✅ | ❌ |
| Secures every AI agent | ✅ | ❌ |
| Native AI gateway integrated | ✅ | ❌ |
| First-party inline enforcement | ✅ | ❌ |
| Agent-to-tool authentication | ✅ | ❌ |
| Real-time threat detection | ✅ | ✅ |
NeuralTrust vs. Zscaler: Platform Overview
What is NeuralTrust TrustGuard?
)
TrustGuard is NeuralTrust's AI runtime security. It inspects every interaction and stops attacks at the moment of execution, on every surface where your agents run: gateways, SDKs, browsers, and platforms. It was built for that job, and it enforces the way agents actually behave.
The design rests on one policy model that covers every threat class at once: injections, sensitive data, unsafe actions, and behavioral attacks. Collectors pull agent traffic from gateways, SDKs, browsers, sidecars, and log streams, protocol-typed policies run detection on every request and response, and the decision is enforced in-flight. Allow, block, or transform, before the action reaches your system. TrustGuard reads the session, the identity, and the protocol together, so it catches the indirect prompt injection hidden in a poisoned tool result, the agent reaching for a tool it should never touch, the automated loop burning through tool calls, and the exfiltration buried in a tool input, and it acts before any of it executes.
Because enforcement is first-party and inline across the agent's execution path, TrustGuard protects the tool call itself, not just the model output or the log record. It integrates natively with TrustGate, NeuralTrust's own AI gateway, and it extends across SDKs, browsers, and platforms with the same policy model. It runs where you need it, from cloud to fully air-gapped. That is what makes it the first runtime security built to reach every AI agent without a new integration for each one.
)
What is Zscaler?
)
Zscaler is a cloud-delivered network security company, known for its Zero Trust Exchange, a proxy platform for secure access and data protection. It entered AI security by acquisition rather than by building runtime security for agents, and that shapes what it offers.
The AI capabilities come largely from SPLX, a startup founded in 2023 that Zscaler acquired in late 2025 and folded into the Zero Trust Exchange. SPLX centers on automated red teaming, running large batches of attack simulations against AI systems, alongside asset discovery and an AI-BOM, prompt hardening, and governance. Its runtime piece is a set of input and output guardrails during live deployments, plus threat inspection that works by scanning LLM logs in near real time. Its agentic security ships as Agentic Radar, an open-source static scanner that inspects agent workflows before they run. Layered onto Zscaler's proxy, this is a stack built to test, discover, monitor, and filter, delivered from Zscaler's cloud, rather than to enforce inline on the agent's execution path.
Private and Air-Gapped Deployment: Runs Anywhere vs Cloud-Delivered
The environments that carry the most sensitive agents are often the ones that cannot send traffic to an outside cloud. Regulated, sovereign, and air-gapped deployments need security that runs inside the perimeter, not security that routes through someone else's platform.
TrustGuard runs where you need it. Cloud, hybrid, on-premises, and fully air-gapped are all deployment options, so runtime enforcement can live inside your perimeter with sensitive data never leaving it. The agents that matter most in banking, defense, and government are exactly the ones TrustGuard is built to protect in place.
Zscaler is cloud-delivered by design. Its platform is a global cloud that traffic is routed through, and its AI security, inherited from a cloud-based startup, follows the same model. That makes the most sensitive environments, the disconnected and air-gapped ones, the environments Zscaler's AI protection does not reach. An enterprise that needs runtime security inside an isolated network cannot get it from a platform whose whole design is to send traffic out to a cloud. TrustGuard removes that constraint by running anywhere the agents do.
Secures Every AI Agent: Runtime Enforcement Everywhere vs Static Scanning and Testing
Agents run behind gateways, inside SDKs, in browsers, and on agent platforms, and new ones arrive constantly. Runtime security has to enforce wherever the agent acts, not just test it in advance or map that it exists.
TrustGuard reaches every surface with a single policy model. The same rules on injections, sensitive data, unsafe actions, and behavioral attacks apply whether the agent calls a tool through a gateway, an SDK, or a browser. This is the core of NeuralTrust's position. It is the first runtime security built to extend across every AI agent, without a custom integration rebuilt for each tool. You write policy once and it protects every agent, including the ones your teams have not deployed yet.
Zscaler relates to agents mainly as things to test, scan, and discover. Its agentic security ships as a static scanner that inspects agent workflows before they run, its red teaming probes those agents with attack simulations ahead of deployment, and its discovery records them in an inventory. That is useful knowledge about your agents, but static scanning and pre-deployment testing do not stop the unsafe tool call an agent makes in production. Knowing an agent exists and having probed it in advance is not the same as enforcing on it while it acts. TrustGuard enforces on that action, on every surface, from one policy model.
Native AI Gateway Integration: Enforcement Inline vs a Network Proxy
Where runtime enforcement runs decides what it can stop. On the agent's own traffic path, it blocks a tool call before it executes. At the network edge, it sees packets and sessions, not the semantics of an agent calling a tool.
TrustGuard integrates natively with TrustGate, NeuralTrust's own AI gateway, so runtime enforcement runs inline on the actual path that LLM and MCP traffic already travels. The decision to block, transform, or allow a tool call is made in-flight, with routing, failover, and tool governance living in the same place as the enforcement decision. Enforcement is built into the road the agent's traffic drives on.
Zscaler is a network security proxy, not an AI gateway. Its platform is built to broker access and inspect traffic at the network layer, and SPLX adds guardrails and testing on top, but there is no first-party AI gateway underneath carrying agent traffic with routing, failover, and MCP tool governance where the enforcement decision is made. A secure web proxy is not the same thing as an AI gateway that understands and controls an agent's tool calls. TrustGuard owns that gateway and the enforcement in one product, so control over the agent's traffic is built in rather than approximated at the network edge.
First-Party Inline Enforcement: The Agent Execution Path vs Guardrails and Log Scanning
The scope of enforcement decides which attacks it can reach. If protection filters app input and output and scans logs after the fact, the agent's tool calls happen outside its control.
TrustGuard enforces first-party and inline across the agent's execution path. Its collectors, policy engine, and enforcement point are all NeuralTrust's, and they act on the tool call, the tool response, the tool input, and the identity behind the request, in-flight, before execution. The dangerous moments in an agent workflow live in those tool interactions, and that is exactly where TrustGuard sits.
Zscaler's AI runtime works differently. SPLX's runtime protection is a set of input and output guardrails on the application, and its threat inspection detects attacks by scanning LLM logs in near real time, which is analysis after the interaction has already happened. Guardrails on app input and output and detection from logs do not enforce on the agent's tool calls as they execute. An indirect injection arriving through a tool response, an agent authenticating to a tool it should not use, a loop of tool calls, or data leaving through a tool input all happen on the execution path that app guardrails and log scanning do not sit on. Filtering the edges and reading the logs is not the same as controlling the actions in between. TrustGuard controls those actions where they happen.
Agent-to-Tool Authentication: Identity at Runtime vs Discovery and Red Teaming
Least-privilege for agents starts with a question a scanner cannot answer: is this really the agent it claims to be, and is it entitled to use this tool right now? Finding an agent's tools and testing them is not the same as verifying who is calling one.
TrustGuard controls how an agent authenticates to MCP tools at runtime. It ties the tool call to the agent's identity and enforces authentication and authorization together at the moment of execution, so an agent reaches only the tools it is entitled to, as the identity it actually is. Identity and permission are verified inline, in the same step as the action.
Zscaler discovers MCP servers, maps the tools an agent can reach, and red-teams for tool-level weaknesses before deployment. That is discovery and testing of the tool relationship, not authentication of the agent to the tool at runtime. An inventory entry and a pre-deployment finding do not establish who the agent is when it reaches for a tool in production. TrustGuard closes that gap by making authentication part of the runtime decision, not a result in a scan report.
Final Verdict
AI runtime security is decided inside the action, and inside the identity behind it. Security built to enforce on the agent's execution path behaves differently from a network platform that acquired a testing tool and filters traffic at the edge.
NeuralTrust built TrustGuard as runtime security from the start. It is the first runtime security built to extend across every AI agent, without a custom integration for each one. It enforces first-party and inline across the agent's execution path, it ships a native AI gateway with enforcement inline, it authenticates the agent to the tool at runtime, and it runs anywhere the agents do, from cloud to fully air-gapped. NeuralTrust is an independent company focused on AI runtime security, and TrustGuard is the product, not a startup absorbed into a much larger platform.
Zscaler comes to AI security from network security, and its AI capabilities are largely SPLX, a small testing and red-teaming startup it acquired and folded into the Zero Trust Exchange. That stack tests, discovers, governs, scans logs, and filters app input and output, delivered from Zscaler's cloud. It has no AI gateway of its own, its runtime does not enforce on the agent's tool calls, it does not authenticate the agent to the tool, and it does not reach the air-gapped environments that carry the most sensitive agents. Inside a sprawling network security portfolio, agent runtime security is one recent acquisition among many.
Both detect threats in real time, so detection alone is not the deciding factor. The decision is whether you want runtime security that enforces on the agent's actions and runs wherever those agents live, or a network platform that tests and monitors them from its cloud. If you are building on agents and you want protection that spans every one of them, enforces first-party and inline on the tool call, verifies the identity behind it, and runs even in your most isolated environments, NeuralTrust is built for exactly that.
Frequently Asked Questions about NeuralTrust vs. Zscaler
1. What is the main difference between NeuralTrust and Zscaler?
NeuralTrust TrustGuard is AI runtime security that enforces inline on the agent's execution path and extends across every agent surface with one policy model. Zscaler is a cloud-delivered network security platform whose AI capabilities come largely from SPLX, a testing and red-teaming startup it acquired, focused on discovery, red teaming, governance, app guardrails, and log scanning. One enforces on the agent's actions, the other tests and monitors them.
2. Does Zscaler have its own AI gateway?
No. Zscaler is a network security proxy, and SPLX adds guardrails and testing on top, but there is no first-party AI gateway carrying agent traffic with routing, failover, and MCP tool governance where the enforcement decision is made. NeuralTrust ships TrustGate, its own AI gateway, and TrustGuard enforces inline on that traffic path.
3. Can Zscaler's AI security run in an air-gapped environment?
Zscaler is cloud-delivered by design, and its AI security is inherited from a cloud-based startup, so the most sensitive disconnected and air-gapped environments are the ones it does not fit. NeuralTrust runs across cloud, hybrid, on-premises, and fully air-gapped deployments, so runtime enforcement can live inside your perimeter with sensitive data never leaving it.
4. Does Zscaler provide runtime protection on agent tool calls?
Zscaler's AI runtime is SPLX's input and output guardrails on the application, plus threat inspection that scans LLM logs in near real time, which is detection after the interaction. That does not enforce on the agent's tool calls, tool responses, or tool inputs as they execute. NeuralTrust enforces first-party and inline across that execution path, which is where indirect injection, unsafe tool use, and exfiltration actually happen.
5. Does Zscaler authenticate agents to tools the way NeuralTrust does?
No. Zscaler discovers MCP servers, maps an agent's tools, and red-teams for tool-level weaknesses before deployment, which is discovery and testing. NeuralTrust authenticates the agent to the tool at runtime, tying the tool call to the agent's identity and enforcing authentication and authorization together, so an agent reaches only the tools it is entitled to as the identity it actually is.
About the Author
Alessandro Pignati is Lead AI Security Researcher at NeuralTrust, where he leads research on AI and agentic security, advancing techniques to evaluate and secure large language models and autonomous AI systems. He specializes in adversarial machine learning, AI red teaming, LLM security, and AI safety, contributing to the development of secure and trustworthy AI.
NeuralTrust is an AI agent security platform, recognized in the Gartner 2025 Market Guide for AI Gateways and Guardian Agents, and the KuppingerCole 2025 Leadership Compass for Generative AI Defense. Headquartered in Barcelona with ISO 27001 certification.
)
)
)
)