Home
Loading

aVenture is in Alpha: During this preview period, you should expect the research data to be limited and may not yet meet our exacting standards. We've made the decision to provide early access to our data to showcase the product as we build, but you should not yet rely upon it alone for your investment decisions.

aVenture is in Alpha: During this preview period, you should expect the research data to be limited and may not yet meet our exacting standards. We've made the decision to provide early access to our data to showcase the product as we build, but you should not yet rely upon it alone for your investment decisions.

Get in touch

  • Contact

  • Request a demo

  • Request data updates

  • Add a company

Research

  • Companies

  • Investors

  • People

aVenture

  • Sitemap

  • Feature requests

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
YC-backed Formal brings a clever security reverse-proxy out of stealth

From TechCrunch

By Romain Dillet

November 19, 2024

YC-backed Formal brings a clever security reverse-proxy out of stealth

YC-backed Formal brings a clever security reverse-proxy out of stealth

Formal is a security startup coming out of stealth on Tuesday with a nice list of investors and an interesting product positioning. The company has designed a reverse-proxy for data stores and APIs so that security teams can more easily secure access to sensitive data.

In more practical terms, Formal is a proxy that you deploy in your virtual private cloud (VPC) where it logs every request made to your data stores — say a database with customer information for instance — and enforces access policies.

Formal is the brainchild of founder Mokhtar Bacha, a 24-year-old who began his tech career at ConsenSys while still a teen, before getting the bug to turn solo entrepreneur.

“At the age of 17, I was lucky enough to connect with one of the co-founders of Ethereum — a guy named Joseph Lubin — and to be recruited as a software engineer [for ConsenSys], which is behind Metamask and other wallets and more,” Bacha told TechCrunch.

“Technically, it was incredibly interesting. But I didn’t feel like I was working on something that was very useful,” he added, explaining that this led him to applying to Y Combinator as a solo founder when he was still just 19 (with Maytana, a cash management platform for multinational startups).

A pivot later, his initial startup idea became Formal, a security product that chief information security officers (CISOs) and CTOs may find useful.

In late 2023, Formal raised a $5.8 million seed round with Thrive Capital leading the round and participation from Y Combinator. Abstract Ventures, Kima Ventures and a bunch of business angels, including Alexis Lê-Quôc, Charles Gorintin, Mathilde Collin, Aaron Katz, Jean-Denis Greze and Matt MacInnis, also joined the round.

Access and control

While data access management isn’t new, what makes Formal special is that you can add or remove data stores and applications without having to manually configure each new component in your stack with a new security policy.

“With the growth of the modern data stack and the transition to the cloud and to AI, basically there were too many different types of tools, too many different types of applications and users that were consuming data,” Bacha suggested.

Formal acts as an abstraction layer for visibility on and control of data flows. After deploying the Formal Connector in your infrastructure, and updating every application to tell them to use the proxy, each query is checked against Formal’s policy engine to dynamically mask or filter data.

“If I am a software engineer based in the U.S., I shouldn’t see data of European customers. And therefore the proxy will automatically mask and redact the data of the European customers,” Bacha explained.

For instance, for a Postgres database, instead of directly “talking” to the Postgres database when you query the database, employees interact with the Formal Postgres proxy. This new step is what makes it easier to enforce access policies — and potentially help customers stay on the right side of laws such as the E.U’s General Data Protection Regulation.

“For the engineering teams that are creating data, let’s say from their laptops, we have an agent that customers can deploy that will automatically redirect the traffic to the proxy without, actually, the engineering teams even noticing,” Bacha added.

Formal’s customers include Gusto, Notion and Ramp. While it’s still a relatively new startup, these are companies that tend to handle sensitive data, such as HR records and financial statements. So having such early adopters is an encouraging sign for Formal’s security model.

View original article on techcrunch.com

Most Recent

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

As Chinese AI models grow in capability and popularity among U.S. companies, the arguing over what should be done about them has reached a fever pitch.

Jul 22, 2026

Cascade raises $3.5M to help construction firms find and win projects

Cascade raises $3.5M to help construction firms find and win projects

a16z Speedrun, Ada Ventures, and Snowball VC have invested in Cascade's $3.5 million seed round.

Jul 22, 2026

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.

Jul 22, 2026

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.

Jul 22, 2026

Similar Posts

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig traces data flows in the security stack and then alerts security teams when changes at any point affect detection or response capabilities.

Mar 3, 2026

Relyance lands $32M to help companies comply with data regulations

Relyance lands $32M to help companies comply with data regulations

As the demand for AI surges, AI vendors are devoting greater bandwidth to data security issues. Not only are they being compelled to comply with emerging data privacy regulations (e.g. the EU Data Act), but they’re finding themselves under the microscope of clients skeptical about how their data is being used and processed. The trouble is, where it concerns tightening data security practices around AI, many orgs aren’t in a position to execute well. According to a survey from BigID, a data cont

Oct 10, 2024

Another customer of troubled startup Delve suffered a big security incident

Another customer of troubled startup Delve suffered a big security incident

TechCrunch has confirmed that Delve was the compliance company that performed the security certifications for Context AI, the AI agent training startup that last week disclosed a security incident.

Apr 23, 2026

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, a platform that helps companies manage and secure third-party app integrations, today announced that it closed a $25 million Series A funding round led by CRV with participation from Bessemer Venture Partners and F2 Venture Capital. Co-founder and CEO Alon Jackson says that the round, which brings Astrix’s total raised to $40 million, […]

Jun 28, 2023

Most Recent

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

As Chinese AI models grow in capability and popularity among U.S. companies, the arguing over what should be done about them has reached a fever pitch.

Jul 22, 2026

Cascade raises $3.5M to help construction firms find and win projects

Cascade raises $3.5M to help construction firms find and win projects

a16z Speedrun, Ada Ventures, and Snowball VC have invested in Cascade's $3.5 million seed round.

Jul 22, 2026

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.

Jul 22, 2026

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.

Jul 22, 2026

Similar Posts

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig traces data flows in the security stack and then alerts security teams when changes at any point affect detection or response capabilities.

Mar 3, 2026

Relyance lands $32M to help companies comply with data regulations

Relyance lands $32M to help companies comply with data regulations

As the demand for AI surges, AI vendors are devoting greater bandwidth to data security issues. Not only are they being compelled to comply with emerging data privacy regulations (e.g. the EU Data Act), but they’re finding themselves under the microscope of clients skeptical about how their data is being used and processed. The trouble is, where it concerns tightening data security practices around AI, many orgs aren’t in a position to execute well. According to a survey from BigID, a data cont

Oct 10, 2024

Another customer of troubled startup Delve suffered a big security incident

Another customer of troubled startup Delve suffered a big security incident

TechCrunch has confirmed that Delve was the compliance company that performed the security certifications for Context AI, the AI agent training startup that last week disclosed a security incident.

Apr 23, 2026

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, a platform that helps companies manage and secure third-party app integrations, today announced that it closed a $25 million Series A funding round led by CRV with participation from Bessemer Venture Partners and F2 Venture Capital. Co-founder and CEO Alon Jackson says that the round, which brings Astrix’s total raised to $40 million, […]

Jun 28, 2023