Formal
AARM CoreProtocol-aware reverse proxy for data, infrastructure, and AI agent traffic
Overview
Formal is a protocol-aware reverse proxy that enforces least privilege at the wire-protocol level across data, infrastructure, and AI agent traffic. It sits between identities and resources like databases, warehouses, SSH/Kubernetes servers, and MCP servers — parsing wire protocols natively and evaluating security policies inline on every request. For AI agent workloads, Formal proxies traffic between agents and resources, applying identity resolution, query-level authorization, PII masking, tool-call filtering, and full audit capture.
Classification
- Coverage surface
- Data/DBNetworkMCP
- Target audience
- Enterprise
- Deployment
- Self-hosted
Technical profile
Spec-grounded axes, verified by the TWG.
- Interception architecture (R1)
- Protocol Gateway
- Policy model (R3)
- Deterministic
- Authorization decisions (R4)
- ALLOWDENYMODIFYSTEP_UP
Conformance review
R1 | Pre-execution interception | Pass |
R2 | Context accumulation | Pass |
R3 | Policy evaluation with intent alignment— Deterministic; non intent-based | Pass |
R4 | Five authorization decisions | Pass |
R5 | Tamper-evident receipts | Pass |
R6 | Identity binding | Pass |
R7 | Semantic distance tracking | Not met |
R8 | Telemetry export | Pass |
R9 | Least privilege enforcement | Pass |
Platform capabilities
- Universal agent network proxy covering databases, infrastructure, and MCP servers
- Eight inline policy actions: Allow, Block, Mask, Filter, Rewrite, Quarantine, Suspend, MFA
- Identity-aware JIT access scoped to individual commands and data
- Panopticon audit layer with sub-second search across full history
- PII and PHI masking at the query level for HIPAA, SOC 2, PCI DSS, and GDPR
- Policy backtesting against 31 days of historical logs before enforcement
Architecture
Formal enforces AARM requirements through interception at two complementary layers. The first is a client-side layer that sits between AI coding tools and the model APIs they call, allowing agent tool calls to be inspected and blocked pre-execution based on policy. The second layer is a protocol-aware proxy between identities and downstream resources. It applies policies across session, request, and response stages. Because agent-originated traffic carries context from the first layer, the proxy can differentiate human-issued queries from agent-session queries and apply controls accordingly. Policy decisions, identity bindings, and tool calls are written to a tamper-evident audit trail, exportable to common SIEM and observability backends.