Overview
At the heart of Formal are two proxies: the Formal Connector, an easily deployed, cloud-native reverse proxy, and the Formal Endpoint, an egress proxy that intercepts and inspects TLS traffic on the host (macOS, Linux, and Windows). Organizations can use the Formal Connector to understand and control their data. The Connector is deployed as a container in your infrastructure. Formal’s architecture relies on two main parts: the Control Plane and the data plane (the Connector and Endpoint). The Control Plane cannot interact with your data; only the Connector and Endpoint can.Minimal Architecture Diagram
At a minimum, Formal consists of a Connector deployed in your own infrastructure: The Connector needs to have network access tohttps://api.joinformal.com (the Control Plane), which is hosted in Formal’s infrastructure. This enables you to manage your Connectors via the API, Terraform provider, and the Control Plane (https://app.formal.ai).
Satellites
Formal has three Satellite types: AI, Policy Data Loader, and Data Discovery Satellites. These satellites are also deployed in your infrastructure. You may add these satellites if you want to leverage additional functionality in your Connector. You can deploy any mix of these three satellites, and each one operates without the others. However, the Data Discovery Satellite can use a linked AI Satellite to classify columns with prompt labels. Satellites also require direct network access to the Control Plane.Within the Connector
The Formal Connector interprets network traffic, identifies the user, and evaluates policies against requests and responses. It can call the Policy Data Loader and AI Satellites to make policy decisions. The Connector also logs and records sessions that are viewable via the Control Plane.