TechCrunch News 2024年11月20日
YC-backed Formal brings a clever security reverse-proxy out of stealth
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Formal 是一款由 Mokhtar Bacha 创立的安全启动公司,旨在简化数据存储和 API 的安全访问。它通过在 VPC 中部署反向代理,记录所有对数据存储的请求,并强制执行访问策略,从而帮助安全团队更轻松地保护敏感数据。Formal 能够自动屏蔽和过滤数据,确保符合 GDPR 等法规,例如防止美国工程师访问欧洲客户数据。该工具已获得 Thrive Capital 等机构的 580 万美元种子轮融资,并获得了 Gusto、Notion 和 Ramp 等公司的青睐,展现出其在数据安全领域的潜力。

🤔Formal 是一款反向代理工具,部署在 VPC 中,记录所有对数据存储的请求并执行访问策略,简化数据访问安全。

🛡️Formal 可以动态屏蔽或过滤数据,例如防止特定地区或角色的员工访问敏感信息,确保合规性,例如符合 GDPR 要求。

⚙️Formal 提供代理连接器,可以轻松集成到现有的数据存储和应用中,无需手动配置每个组件的安全策略。

💼Formal 已获得多家知名企业的采用,如 Gusto、Notion 和 Ramp,表明其安全模型得到了认可和信任。

💰Formal 已完成 580 万美元种子轮融资,由 Thrive Capital 领投,Y Combinator 等参投,展现出其发展潜力。

Formal is a security startup coming out of stealth on Tuesday with a nice list of investors and an interesting product positioning. The company has designed a reverse-proxy for data stores and APIs so that security teams can more easily secure access to sensitive data.

In more practical terms, Formal is a proxy that you deploy in your virtual private cloud (VPC) where it logs every request made to your data stores — say a database with customer information for instance — and enforces access policies.

Formal is the brainchild of founder Mokhtar Bacha, a 24-year-old who began his tech career at ConsenSys while still a teen, before getting the bug to turn solo entrepreneur.

“At the age of 17, I was lucky enough to connect with one of the co-founders of Ethereum — a guy named Joseph Lubin — and to be recruited as a software engineer [for ConsenSys], which is behind Metamask and other wallets and more,” Bacha told TechCrunch.

“Technically, it was incredibly interesting. But I didn’t feel like I was working on something that was very useful,” he added, explaining that this led him to applying to Y Combinator as a solo founder when he was still just 19 (with Maytana, a cash management platform for multinational startups).

A pivot later, his initial startup idea became Formal, a security product that chief information security officers (CISOs) and CTOs may find useful.

In late 2023, Formal raised a $5.8 million seed round with Thrive Capital leading the round and participation from Y Combinator. Abstract Ventures, Kima Ventures and a bunch of business angels, including Alexis Lê-Quôc, Charles Gorintin, Mathilde Collin, Aaron Katz, Jean-Denis Greze and Matt MacInnis, also joined the round.

While data access management isn’t new, what makes Formal special is that you can add or remove data stores and applications without having to manually configure each new component in your stack with a new security policy.

“With the growth of the modern data stack and the transition to the cloud and to AI, basically there were too many different types of tools, too many different types of applications and users that were consuming data,” Bacha suggested.

Formal acts as an abstraction layer for visibility on and control of data flows. After deploying the Formal Connector in your infrastructure, and updating every application to tell them to use the proxy, each query is checked against Formal’s policy engine to dynamically mask or filter data.

“If I am a software engineer based in the U.S., I shouldn’t see data of European customers. And therefore the proxy will automatically mask and redact the data of the European customers,” Bacha explained.

For instance, for a Postgres database, instead of directly “talking” to the Postgres database when you query the database, employees interact with the Formal Postgres proxy. This new step is what makes it easier to enforce access policies — and potentially help customers stay on the right side of laws such as the E.U’s General Data Protection Regulation.

“For the engineering teams that are creating data, let’s say from their laptops, we have an agent that customers can deploy that will automatically redirect the traffic to the proxy without, actually, the engineering teams even noticing,” Bacha added.

Formal’s customers include Gusto, Notion and Ramp. While it’s still a relatively new startup, these are companies that tend to handle sensitive data, such as HR records and financial statements. So having such early adopters is an encouraging sign for Formal’s security model.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据安全 反向代理 访问控制 Formal 数据隐私
相关文章