nonoAlways Further
|
||||||
Related Products
|
||||||
About
Formal is a protocol-aware reverse proxy that secures access to databases, APIs, infrastructure, and AI tools by enforcing least privilege at the wire-protocol level. Deployed as a single stateless binary in a VPC through Terraform, Kubernetes, or Docker, it sits between identities and resources without application changes, SDKs, or agents. Formal parses more than 15 protocols, including PostgreSQL, MySQL, MongoDB, Snowflake, SSH, Kubernetes, HTTP, MCP, S3, Redis, RDP, BigQuery, ClickHouse, and DynamoDB, allowing query-level decisions instead of generic network filtering. Policies can authenticate and authorize users, mask or filter fields, rewrite requests, block actions, require MFA, quarantine sessions, suspend access, or support impersonation across session, request, and response stages. Teams can secure AI agents and MCP servers by stripping PII before it reaches a model, blocking unauthorized tool calls, and auditing every action.
|
About
nono is an open source, kernel-enforced sandbox for AI coding agents and LLM workloads. Unlike policy-based guardrails that intercept and filter operations, nono uses OS security primitives — Landlock on Linux and Seatbelt on macOS — to make unauthorised operations structurally impossible at the syscall level.
Wrap any AI agent — Claude Code, OpenCode, OpenClaw, or any CLI process — with a single command. nono applies default-deny filesystem access, blocks destructive commands (rm, dd, chmod, sudo), isolates credentials and API keys, and cascades all restrictions to child processes. No escape mechanism exists once restrictions are applied.
Built-in profiles get you running in seconds. Secrets inject securely from the system keystore and are zeroised on exit. Audit logging, atomic rollbacks, and Sigstore-attested policy signing are on the roadmap.
Apache 2.0. From the creator of Sigstore.
|
|||||
Platforms Supported
Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook
|
Platforms Supported
Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook
|
|||||
Audience
Security engineering teams at AI-native enterprises that need granular access control and auditing across data, infrastructure, and autonomous agents
|
Audience
Developers & AI power users — Anyone running Claude Code, Cursor, OpenCode, or other CLI-based AI coding agents on their local machine who wants to prevent agents from accessing credentials, deleting files, or touching paths outside the project directory. CISO, Security engineers & DevSecOps teams — Teams responsible for establishing safe agent usage policies across engineering organisations. nono provides kernel-enforced, auditable enforcement without requiring infrastructure changes. Platform & ML engineers — Engineering teams building or evaluating agentic AI workflows who need runtime isolation as part of their agent stack. Software companies adopting AI tooling — Organisations in software development, fintech, healthcare, and any regulated industry where developer workstations hold sensitive credentials, proprietary code, or compliance-relevant data that must not be accessible to autonomous agents. Open source contributors & researchers — Security researchers and OSS contributors working with or studying AI agent threat models, kernel sandboxing, and runtime security primitives.
|
|||||
Support
Phone Support
24/7 Live Support
Online
|
Support
Phone Support
24/7 Live Support
Online
|
|||||
API
Offers API
|
API
Offers API
|
|||||
Screenshots and Videos |
Screenshots and VideosNo images available
|
|||||
Pricing
No information available.
Free Version
Free Trial
|
Pricing
No information available.
Free Version
Free Trial
|
|||||
Reviews/
|
Reviews/
|
|||||
Training
Documentation
Webinars
Live Online
In Person
|
Training
Documentation
Webinars
Live Online
In Person
|
|||||
Company InformationFormal
United States
formal.ai/
|
Company InformationAlways Further
Founded: 2025
United Kingdom
alwaysfurther.ai/
|
|||||
Alternatives |
Alternatives |
|||||
|
|
||||||
|
|
||||||
|
|
|
|||||
Categories |
Categories |
|||||
Integrations
Amazon DynamoDB
Amazon S3
Claude Code
ClickHouse
Datadog
Docker
Google Cloud BigQuery
Kubernetes
Model Context Protocol (MCP)
MongoDB
|
Integrations
Amazon DynamoDB
Amazon S3
Claude Code
ClickHouse
Datadog
Docker
Google Cloud BigQuery
Kubernetes
Model Context Protocol (MCP)
MongoDB
|
|||||
|
|
|