Least privilege for agents and humans
The network stack built from the ground up for the agentic era. Reverse and forward proxies that keep credentials out of agents’ and humans’ hands, enforce fine-grained policies, and audit every action.
Deploy a single stateless binary in your VPC via Terraform, Kubernetes, or Docker. Point connection strings through Formal instead of directly to your datastores. Every identity — engineer, BI tool, CI/CD pipeline, AI agent — hits the proxy, where policies evaluate in real time. No app changes, no SDK.
See the quickstart guide →Authenticate / Authorize Mask / Filter / Rewrite Log / Monitor / Alert +------------------+ +------------------+ +------------------+ | Identities | ---> | Formal Proxy | ---> | Resources | +------------------+ +------------------+ +------------------+ Response path: identities <--- formal proxy <--- resources Examples: idp users, CI/CD, BI tools, AI agents | postgres, mysql, mongodb, snowflake, k8s, http, mcp
One stateless binary in your VPC via Terraform, Kubernetes, or Docker. Most teams route first traffic in under an hour — Notion secured hundreds of datastores in days.
Read how →Use the no-code editor or write Rego policies. Set masking rules, access controls, and approval workflows. Test with dry-run before going live.
Every query, every protocol, evaluated in real time. Full visibility, automatic compliance, least privilege on autopilot.
Security as Code
API-first. Choose your IaC, pick your VPC, deploy a single distroless image to protect your entire stack.
See docs →# Connect a resource resource "formal_resource" "production_pg" { name = "production-postgres" technology = "postgresql" hostname = "db.internal.company.com" port = 5432 } # Mask PII for non-privileged users (Rego) resource "formal_policy" "mask_pii" { name = "mask-pii-data" description = "Mask PII fields for non-privileged users" status = "active" module = <<-EOT package formal.v2 import future.keywords.if import future.keywords.in response := { "action": "mask", "type": "nullify", "columns": pii_columns } if { not "pii_access" in input.user.groups pii_columns := [col | col := input.columns[_] col.data_label in ["email", "ssn", "phone"] ] count(pii_columns) > 0 } EOT }
One policy engine, both directions
The forward and reverse proxies share the same OPA policy engine and protocol parsers. Write a policy once and it governs both what leaves your machines and what reaches your infrastructure.
Protocol-native at every hop
Formal parses Postgres, MySQL, SSH, Kubernetes, HTTP, MCP, and more on the wire, so every decision is made per query, command, and tool call — not per IP and port.
Identity on every request
Every action is tied to who made it: the engineer, the agent, and the person the agent is acting for. Permissions are checked against the human behind the task.
Runs in your infrastructure
The reverse proxy runs in your VPC and the forward proxy on the machines your agents run on. Your data stays in your infrastructure, with single-digit-millisecond overhead at p50.
Ready to trust your agents?
One network security layer for every agent and human, from the laptop to production.