Skip to content
MoorAI
// moorai vs neuraltrust

MoorAI vs NeuralTrust

Last updated

NeuralTrust hooks coding agents and sends each event to its evaluator. MoorAI hooks the same events and decides on the machine. NeuralTrust’s Claude Code guide: “The TrustGuard plugin evaluates these actions through lifecycle hooks on the machine where Claude Code runs.” Each hook calls TrustGuard’s POST /v1/evaluate endpoint and enforces the answer. (docs.neuraltrust.ai, Claude Code) MoorAI is a PreToolUse hook inside the coding agent and an MCP stdio proxy in front of local Model Context Protocol (MCP) servers. Its detection engine runs inside the hook, so no call to a service is needed to reach a verdict.

NeuralTrust is gateway-first; the hooks are one collector among several. Its gateway is “One gateway for every call your agents make: to models, MCP servers, tools, and other agents.” (neuraltrust.ai/ai-gateway) and its runtime engine works from wherever traffic can be collected: “Collectors ingest agent traffic from gateways, SDKs, browsers, sidecars & log streams.” (neuraltrust.ai/ai-agent-security) MoorAI has no gateway. It decides against a 77-threat matrix on the device and by default sends only category · risk · keyed one-way hash.

NeuralTrust covers more ground than MoorAI does, including more coding agents. It documents hook integrations for Claude Code, Cursor, Codex, Gemini CLI, Windsurf and GitHub Copilot, an open-source AI gateway, session-aware detection, red teaming, model and MCP scanners, and agent inventory. MoorAI covers coding agents on endpoints and goes deeper into what they read, run and load. The rows where NeuralTrust covers more ground are further down.

Three things this page does not state. (1) Where a customer’s evaluator runs. NeuralTrust offers SaaS, hybrid and self-hosted deployment, and says “The data plane runs inside the customer's VPC/on-prem and enforces policies locally.” (neuraltrust.ai/llms-full.txt) The hook’s event leaves the developer’s machine either way; whether it leaves the customer’s network depends on the deployment, which this page cannot know. (2) How well NeuralTrust’s models do on coding-agent traffic. Its published performance report covers its guardrail models, not the coding-agent collectors, and we have not tested either product against the other. (3) A price. NeuralTrust’s pricing is a tailored quote. Every NeuralTrust statement below is quoted from NeuralTrust’s own site, documentation or GitHub, and the source is named.

The core difference is the trust model: the event goes to an evaluator, or the evaluator comes to the event.

01Where is the decision made?
In NeuralTrust’s design, off the machine. Its Gemini CLI plugin, for example: “Gemini CLI lifecycle hooks call trustguard-gemini-cli, which maps each event to TrustGuard POST /v1/evaluate and returns allow / ask / deny.” (github.com/NeuralTrust/trustguard-gemini-cli-plugin) NeuralTrust states the choice plainly when comparing itself with an endpoint product: “NeuralTrust needs no endpoint agent. It enforces at the agent's traffic layer.” (neuraltrust.ai blog, NeuralTrust vs CrowdStrike) That lets one policy and one set of models judge a coding agent, a chatbot and an MCP gateway alike. MoorAI’s engine runs in the hook process on the device, and the console receives which rule fired, the risk and a keyed hash. NeuralTrust’s design sends each prompt, command and tool result to the evaluator; MoorAI’s detectors are limited to what runs on a laptop.
02What does each judge?
NeuralTrust judges a conversation, not one call: “TrustGuard tracks conversation context across turns — catching multi-turn attacks where a jailbreak fails once and succeeds on the third attempt.” (neuraltrust.ai/ai-agent-security) Its Claude Code plugin evaluates the prompt, shell commands, tool calls and tool results, and its guide names the limits: “The plugin does not support redaction or evaluate tool declarations.” (docs.neuraltrust.ai, Claude Code) MoorAI’s rules are written for coding-agent specifics: a .env or key read into context, a near-miss package name at install time, an MCP server whose config changed after approval, a skill file carrying hidden instructions, an upload to a host the user’s request never named. Its multi-turn coverage is narrower: a crescendo-trajectory analyzer for persuasion-style jailbreaks.
03What happens to the developer?
Both use the agent’s own allow, ask and deny. NeuralTrust’s ask shows a generic sentence in Claude Code’s permission dialog, and its guides for Cursor, Codex and Gemini CLI turn a masking verdict into an ask by default, because those collectors cannot redact. Its plugins are built to stay installed: “System settings override user and workspace settings, so developers cannot remove the hooks or set hooksConfig.enabled to false.” (github.com/NeuralTrust/trustguard-gemini-cli-plugin) MoorAI coaches: it tells the developer and, where the agent host supports it, the agent what was flagged and the safer way to do it. A mask replaces a secret or PII span with a content-free tag and lets the call proceed. A device that is not enrolled in a MoorAI console coaches and never blocks; blocking, sign-off and session kill apply once it is enrolled.
✓ yes ◐ partial — unconfirmed ✗ no

Where MoorAI holds ground NeuralTrust does not

These rows follow from deciding inside the hook, and from rules written for what coding agents read, install and load.

MoorAI NeuralTrust
Reaches the verdict on the device, with no call to a service ✓engine runs in the hook ✗hooks call TrustGuard POST /v1/evaluate
By default only category · risk · keyed one-way hash leave the device ✓capture tiers are opt-in, admin-enabled ✗the event is sent to the evaluator
Masks a secret or PII span in a coding agent’s tool call and lets it proceed ✓mask action; not yet observed in a live Claude Code session ✗coding-agent collectors do not support redaction
Coaching with the safer alternative, shown to the developer and the agent ✓ —report-only findings can be shown; no safer-alternative text described
Coding-agent rules: secret read into context, slopsquatting, MCP rug-pull knock-back, skill-file poisoning and drift ✓ —not documented at that grain
Flags a risky action aimed at something the user’s request never named ✓intent alignment; lexical, keyed hashes —not in public material
Enforces for any host that launches a stdio MCP server, with no gateway ✓MCP stdio proxy ◐MCP governed through the TrustGate gateway
Detection engine itself open source ✓agent and engine MIT ◐gateway and plugins Apache 2.0; no published TrustGuard source found
Free to enforce, with a published limit, without talking to sales ✓console free to 200 users ◐TrustGate free; enterprise pricing by quote

Where NeuralTrust covers ground MoorAI does not

This list is longer. NeuralTrust secures agent traffic wherever it can be collected: gateways, SDKs, browsers and coding agents. MoorAI covers coding agents on endpoints.

MoorAI NeuralTrust
Coding agents covered: Windsurf, and GitHub Copilot in VS Code and as a cloud coding agent ◐Copilot CLI adapter only; no Windsurf adapter ✓documented integrations
An AI gateway for model, MCP and agent-to-agent traffic ✗ ✓TrustGate, Apache 2.0
Session-aware detection of slow escalation across turns, with user blocking ◐crescendo-trajectory analyzer; verdicts mostly per call ✓
Guardrail models with a published performance report, operating points and perturbation tests ◐held-out and benign-corpus figures in the README ✓
Protection for customer-facing chatbots, RAG apps and third-party assistants ✗ ✓
Red teaming of the customer’s own models and apps, and model-file scanning ◐moorai-redteam tests MoorAI’s own policy; no model scanning ✓TrustTest, Model Scanner
Claude organisation-wide coverage beyond Claude Code (claude.ai, Desktop) through inference hooks and connectors ◐MCP proxy for Claude Desktop; no org-level hook ✓
Bot, DDoS and spend controls for LLM applications ✗ ✓

Same capability, different mechanism

Both products do each of these, so the table describes how rather than scoring.

MoorAI does it by… NeuralTrust does it by…
Stopping a coding agent’s action before it runs A PreToolUse hook in the agent’s own process, validated end to end on Claude Code. Codex CLI, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. An MCP stdio proxy enforces for any host that launches a stdio MCP server. A plugin per agent whose local binary posts each lifecycle event to TrustGuard and returns allow, ask or deny. Deployed by MDM; “Developers do not need NeuralTrust accounts to use the TrustGuard plugin.” (docs.neuraltrust.ai, Claude Code)
Agents that run without a developer’s laptop Server mode runs the same hook in CI, containers and Agent SDK services, with the workload as the actor and a headless ask denied. Proven on one live claude -p run; an Agent SDK service and a GitHub Actions run have not been watched end to end. Hooks committed to the repository for Copilot’s cloud agent: “Local hooks run on the developer's machine; cloud coding-agent jobs use hooks committed to the repository.” (docs.neuraltrust.ai, GitHub Copilot) Gateway and SDK collectors cover servers without an endpoint agent.
When the checker is unreachable No service is needed to reach a verdict. If the hook process itself crashes or times out, the call fails open; a device under a fail-closed posture keeps enforcing without a console token. A setting: “open allows, closed denies when TrustGuard is unreachable”. (github.com/NeuralTrust/trustguard-gemini-cli-plugin) The Claude Code guide’s example config uses open.
Vetting MCP servers before use An approval lifecycle with rug-pull knock-back, an invisible-payload scanner, a 0-100 server reputation score, and moorai-scan, a content-free pre-install verdict on skills, MCP configs and packages. A free MCP Scanner: “Detect poisoned or redefined tools, insecure MCP servers, and unsafe endpoint exposures that could compromise trust boundaries.” (neuraltrust.ai/mcp-scanner)

MITRE ATLAS, as documented. In our reading of vendor material against the 76 ATLAS techniques tagged Agentic AI, NeuralTrust’s published material documents 19 of the 76 (read 1 October 2026), 9 of them with a limit the vendor states, such as scanners that run before deployment rather than at runtime, and detection rates measured on NeuralTrust’s own benchmark. That counts what the documentation says across its whole platform, not only the coding-agent plugins. The method and every quote behind the number are in What vendors actually document against MITRE ATLAS.

Where MoorAI is stronger. Nothing leaves the device to be judged, and the rules know coding agents. The file read into context, the package being installed, the MCP server that changed after approval, the skill file the agent loads and the upload to a host the user never named are judged in the hook, and the console receives no content. A secret can be masked instead of blocked, the developer is coached instead of just refused, and the engine that makes the decision is MIT code, free to enforce up to 200 users.

Where NeuralTrust is stronger. Breadth, and published measurement. One gateway and one policy across models, MCP servers, chatbots, browsers and coding agents, with more coding agents documented than MoorAI supports. Detection that follows a conversation: “TrustGuard models interaction patterns over time. Probing, slow escalation, and gradual manipulation are flagged before the attack completes.” (neuraltrust.ai/ai-agent-security) A performance report that states its own limits (“The benchmark suite was constructed to NeuralTrust's own taxonomies and industry cover-stories, a home-field advantage acknowledged explicitly in the full report.”) and stress-tests its models: “Jailbreak and toxicity are stress-tested under 10 adversarial text perturbations, totalling approximately 129,600 distinct scored inputs per model.” (neuraltrust.ai blog, AI Security Model Performance Report 2026) If the job is one control point for all agent traffic, NeuralTrust is the larger product and MoorAI is not one.

Which to run where. Run NeuralTrust where the question is all agent traffic in one place: customer-facing apps, MCP behind a gateway, browser use, and coding agents where sending each event to a self-hosted evaluator is acceptable. Run MoorAI on developer machines where prompts, files and commands should not leave the machine to be judged, and where the risk is specific to coding agents. Both hook the same coding-agent events, so running both means two hooks on every action; neither’s public material addresses that, and we have not run them together.

Questions about MoorAI and NeuralTrust

Does NeuralTrust send coding-agent events off the machine?

Yes, per its own documentation: the TrustGuard plugin’s hooks call TrustGuard’s evaluate endpoint, which can be NeuralTrust’s SaaS or a data plane the customer runs in its own VPC or on premises. MoorAI reaches its verdict inside the hook and sends a category, a risk level and a keyed one-way hash by default.

Which coding agents does NeuralTrust cover?

NeuralTrust documents integrations for Claude Code, Cursor, Codex, Gemini CLI, Windsurf and GitHub Copilot, including Copilot’s cloud coding agent through hooks committed to the repository. MoorAI is validated end to end on Claude Code; its Codex CLI, Copilot CLI, Gemini CLI and Cursor adapters are not yet validated against the live agents, and it has no Windsurf adapter.

Is NeuralTrust open source?

Partly. TrustGate, its AI gateway, is open source under Apache 2.0, and so are its coding-agent plugins on GitHub. We found no published source for TrustGuard, the engine the plugins call, and NeuralTrust prices its platform by quote. MoorAI’s agent, including its detection engine, is MIT; its console is source-available under the Elastic License 2.0 and free up to 200 users.

Does MoorAI replace NeuralTrust, or the other way round?

Not as a whole. NeuralTrust is a gateway-first platform for all agent traffic, with red teaming, scanners and agent inventory, and MoorAI does none of that. On coding agents the two overlap, and the difference is whether each event is sent to an evaluator or judged on the device.

Who backs NeuralTrust?

NeuralTrust says it raised a $20M seed round in June 2026, led by Alstin Capital. It was founded in Barcelona.

NeuralTrust capabilities are taken from NeuralTrust’s own published material, checked on 1 October 2026: docs: Claude Code, docs: GitHub Copilot, the documentation index, trustguard-claude-code-plugin, trustguard-gemini-cli-plugin, TrustGate, neuraltrust.ai, ai-gateway, ai-agent-security, mcp-scanner, NeuralTrust vs CrowdStrike, AI Security Model Performance Report 2026 and llms-full.txt. Every quoted phrase is NeuralTrust’s. ◐ = partial: present but narrower than the other column. — = unconfirmed, not necessarily absent. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. The agent is MIT and runs on macOS, Windows and Linux; the console is source-available under the Elastic License 2.0 and free up to 200 users. NeuralTrust is a trademark of its owner; this page is independent and is not affiliated with or endorsed by NeuralTrust. Both products change, so check specifics against current documentation.