Introduction
Formal is a modern network security and privileged access management platform built from the ground up to enforce least privilege for both humans and AI agents. At the heart of Formal are two proxies. The first is the , a protocol-aware reverse proxy that you deploy within your own network. You can think of it as a super powerful bastion host. With the Connector, security teams can control access to . The second is the Endpoint, a protocol-aware egress proxy that runs on the host (macOS, Linux, and Windows). It transparently intercepts TCP and UDP flows and terminates TLS. This gives security teams visibility and control over the traffic of their AI agents. Using the , you gain visibility into the requests, responses, and going through the Connector and the Endpoint. You can then write that are evaluated against the traffic going through the Connector to perform actions (, blocking, filtering) against requests, responses, and sessions.Examples
You can use Formal to restrict the kinds of SQL queries your engineers can make to your databases while masking and redacting the data as it leaves the DB: You can allow local GitHub MCP servers to make some HTTP requests to the GitHub API but not others: You can monitor SSH sessions to your bastions for anomalous behavior and have Formal automatically classify the risk level:Get started
Get started in 10 minutes
Deploy production-ready access controls in minutes
Use our API for full control
Automate everything with Terraform, Pulumi, or direct API access
Add a Resource
Connect your first database to Formal in less than five minutes