Formal
Formal is a programmable reverse proxy that sits in front of databases and infrastructure, parsing 15+ wire protocols to enforce fine-grained, query-level access policies for humans and AI agents alike, without requiring application code changes.
Visit Website ↗ + Add to CompareOverview
Formal’s core technology is a transparent reverse proxy that intercepts and parses database and infrastructure protocol traffic to enforce least-privilege access policies at the individual query level, rather than only at the connection or network layer. As enterprises grant AI agents direct database and infrastructure access, Formal extends the same inline policy enforcement to machine identities.
Founded in 2022 by Mokhtar Bacha, a ConsenSys alum with a cryptography and distributed-systems background, Formal went through Y Combinator’s Summer 2020 batch under an earlier iteration, emerged from stealth publicly in November 2024 with TechCrunch coverage, and counts Notion, Ramp, and Gusto among its customers.
Innovation Matrix Assessment
Going from a 2022 founding to a public TechCrunch-covered stealth exit with named enterprise customers by late 2024 indicates a fast, credible early execution pace.
Query-level access enforcement without requiring application code changes meaningfully lowers the engineering cost of implementing least-privilege database access controls.
Named customers including Notion, Ramp, and Gusto, plus TechCrunch coverage of its stealth exit, are credible traction signals for an early-stage company.
Protocol-level, query-granular policy enforcement via a transparent proxy is a meaningfully different architecture than IAM-based or network-level access control, and extends naturally to AI agent access.
No independent, third-party efficacy or performance-overhead benchmark was found; effectiveness claims are vendor and customer-testimonial based rather than independently validated.
As both human and AI-agent access to sensitive infrastructure grows, query-level, protocol-aware access control is likely to remain relevant regardless of how the AI agent access-control market consolidates.
Why CISOs Should Care
As organizations grant AI agents direct access to production databases and internal systems, query-level access control that doesn't require rewriting application code gives CISOs a practical way to enforce least privilege without slowing engineering teams down.
What Makes It Different
Formal's protocol-parsing reverse-proxy architecture enforces policy at the query level across 15+ wire protocols, a deeper and more granular enforcement point than connection-level network access controls or IAM policies alone provide.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A technically differentiated data-access control layer with real enterprise customers and TechCrunch-covered public traction; scores reflect solid early execution tempered by limited disclosed funding specifics.
Editorial Note: Claims vs. Verified Findings
The Y Combinator batch, founding, and named customers (Notion, Ramp, Gusto) are independently confirmed via Formal's own YC company profile; specific funding amount is not disclosed on the pages reviewed.
Sources
Alternatives to Formal
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…