Skip to main content
Adopt AI securely.

Introduction

Formal is a modern network security and privileged access management platform built from the ground up to enforce least privilege for both humans and AI agents. At the heart of Formal are two proxies. The first is the , a protocol-aware reverse proxy that you deploy within your own network. You can think of it as a super powerful bastion host. With the Connector, security teams can control access to . The second is the Endpoint, a protocol-aware egress proxy that runs on the host (macOS, Linux, and Windows). It transparently intercepts TCP and UDP flows and terminates TLS. This gives security teams visibility and control over the traffic of their AI agents. Using the , you gain visibility into the requests, responses, and going through the Connector and the Endpoint. You can then write that are evaluated against the traffic going through the Connector to perform actions (, blocking, filtering) against requests, responses, and sessions.

Examples

You can use Formal to restrict the kinds of SQL queries your engineers can make to your databases while masking and redacting the data as it leaves the DB: You can allow local GitHub MCP servers to make some HTTP requests to the GitHub API but not others: You can monitor SSH sessions to your bastions for anomalous behavior and have Formal automatically classify the risk level:

Get started

Get started in 10 minutes

Deploy production-ready access controls in minutes

Use our API for full control

Automate everything with Terraform, Pulumi, or direct API access

Add a Resource

Connect your first database to Formal in less than five minutes