Skip to main content

Formatho Engineering Services

Make your internal systems agent-ready

We turn internal APIs and workflows into secure, MCP-accessible tools — deployed inside your infrastructure, permissioned per agent, audit-logged without recording payloads. Built on the open-source Formatho Runtime; verified, not trusted.

Zero data egress by design Your infra, your keys Open-source foundation

What we do

Internal API → MCP tool development

We wrap your internal services as permissioned MCP tools: typed schemas, capability declarations, and error contracts your agents can act on — built on the same registry that powers Formatho Runtime.

  • Zod-validated input/output schemas
  • Deny-by-default capability declarations
  • Error shapes agents can self-correct from

Self-hosted runtime deployment

We deploy and harden the runtime in your environment — Docker or Kubernetes, inside your VPC — with API-key issuance, policy files, and rate limits per agent and per team.

  • Docker / Kubernetes / VPC deployment
  • Per-agent keys and policy engine
  • Rate limits that stop runaway loops

Governance & audit alignment

Metadata-only audit trails designed for security review: what was called, by which key, when — never what was sent. We map the trail to your compliance vocabulary (SOC 2 evidence, internal review boards).

  • JSONL audit streams, payload-free by construction
  • SOC 2 / internal-review evidence mapping
  • Egress verification: the firewall test documented

Agent-readiness assessment

A two-week audit of which internal systems can safely become agent tools — and which cannot yet. You get a ranked roadmap with the capability gaps and data-classification boundaries made explicit.

  • Data classification per candidate system
  • Ranked tool roadmap with effort estimates
  • Buy/build/hosted recommendation per service

How an engagement runs

Fixed-scope start, verifiable checkpoints, and a handover that leaves everything in your repository — the same no-lock-in discipline the runtime is built on.

Weeks 1–2

01

Assessment

Inventory candidate systems, classify data boundaries, produce the ranked agent-readiness roadmap.

Weeks 3–6

02

Pilot

One or two high-value tools built and deployed in your environment, with policies and audit wired for review.

Weeks 7–10

03

Production

Expanded toolset, per-team keys and quotas, runbooks, and a security-review package your engineers can verify line by line.

Ongoing

04

Handover

Everything is yours: open-source runtime, tool code, policy files. Optional support retainers; no lock-in by construction.

Why teams pick us

  • The reference implementation is public. The runtime your tools run on is open source with a three-dependency supply chain, an MCP Registry listing, and a security model written to be audited. Your security team reads the same code that runs in production.
  • Zero egress is structural, not contractual. The registry refuses tools that declare network, filesystem, or secret access — so "could a compromised tool exfiltrate?" has a testable answer: there is no channel.
  • Audit designed for review boards. Metadata-only logs (tool, key, duration, sizes) give compliance a trail while ensuring the log itself can never become the incident.
  • Tool engineering at catalog scale. The free Formatho tool suite is the same discipline — 160+ deterministic, client-side tools — applied to the browser; engagements apply it to your systems.

Frequently asked questions

What does "agent-ready" actually mean?

An internal system is agent-ready when an AI agent can call it through a governed interface: typed schemas so the agent constructs valid requests, a permission model that says which agent may call what, rate limits that bound blast radius, and an audit trail that records every invocation without recording payloads. It is the difference between letting an agent loose on your API and giving it tools.

Where does our data go during the engagement?

Nowhere. The runtime we deploy runs inside your infrastructure and makes zero outbound requests — that is verifiable in the open-source code, not a contractual promise. Tool development happens against your staging systems; production access is issued by your team, to your team, and revocable by you.

Do you host anything for us?

The default engagement is fully self-hosted: your containers, your network, your keys. A hosted trial tier exists for evaluation, but production deployments in these engagements are self-hosted by design — that is the product thesis, and it is also what security teams sign off on fastest.

How is this different from hiring an MCP consultant?

The reference implementation is a maintained, open-source runtime with a published tool registry, MCP Registry listing, and a security model designed for review — not a one-off server somebody leaves behind. Engagements extend that foundation instead of starting from a blank file, so your team inherits an upgrade path, not an artifact.

What does an engagement cost?

Assessments are fixed-scope; pilots and production rollouts are sized by tool count and system complexity after the assessment. Every engagement ends with handover of all code and configuration — the open-source runtime guarantees there is no lock-in to price against.

Which teams typically start?

Platform and developer-experience teams bringing internal tooling to agents, security teams that need governed tool access before broader agent adoption, and payments/fintech engineering groups that already operate under data-residency constraints and recognize the zero-egress pattern.

Start with the two-week assessment

You get a ranked agent-readiness roadmap for your internal systems — whether or not the engagement continues past it.