What is Formal?
Formal operates as a sophisticated reverse proxy that understands various protocols, thereby improving security for databases, APIs, infrastructure, and AI tools through the implementation of least privilege principles at the wire-protocol layer. Deployed as a single stateless binary within a Virtual Private Cloud (VPC), it utilizes platforms like Terraform, Kubernetes, or Docker, placing itself strategically between users and resources without requiring any modifications to existing applications, SDKs, or agents. Capable of analyzing over 15 different protocols—including PostgreSQL, MySQL, MongoDB, Snowflake, SSH, Kubernetes, HTTP, MCP, S3, Redis, RDP, BigQuery, ClickHouse, and DynamoDB—Formal enables more granular decision-making based on specific queries instead of relying on broad network filtering alone. Additionally, its policies can manage user authentication and authorization, mask or filter data fields, alter requests, restrict certain actions, enforce multi-factor authentication, isolate sessions, revoke access, or allow impersonation during session, request, and response phases. Moreover, teams can safeguard AI agents and MCP servers by stripping personally identifiable information before processing by a model, preventing unauthorized tool access, and thoroughly auditing every action performed. This multifaceted strategy not only strengthens security but also assures adherence to data protection regulations, fostering a more secure operational environment for all users involved. In conclusion, Formal exemplifies an innovative approach to modern security challenges, effectively balancing functionality with compliance.