Forum Systems is a privately held engineering company founded in 2001 in Needham, Massachusetts, focused on mission-critical, large-scale API security with a “security by design” philosophy. Its flagship platform, Forum Sentry API Security Gateway, unifies security, access control, and performance capabilities into a single integrated offering used by US federal agencies, governments, and large enterprises, with a stated 100% deployment success rate. The text argues that digital transformation has made APIs central to business relationships and revenue growth across mobile, cloud, B2B, and IoT, but that the rapid expansion of APIs has outpaced the security maturity of many API management tools, which often treat security as an add-on and overlook legacy modernization and non-HTTP protocols.
Forum Sentry is positioned as an API security gateway rather than a developer-centric API management gateway, emphasizing deep, protocol-specific inspection, payload validation, threat detection, and embedded antimalware scanning. It supports a wide range of standards and protocols, including legacy messaging and real-time AMQP via an inline proxy, and can translate protocols (e.g., AMQP to JMS) to simplify legacy integration. A highlighted capability is scanning and decoding embedded BASE64 content (including nested formats such as ZIP) in very large documents (up to 100 GB) for malware detection and policy-driven external checks.
Deployment prioritizes reliability via hardened physical appliances with cryptographic acceleration, a locked-down OS, and certifications including FIPS 140-2 Level II and NIAP NDPP; virtual appliances and software packages are also available, with network HSM support for strong cryptography in cloud environments. Centralized management is achieved through Global Device Management for secure policy propagation and automation, typically relying on Syslog/SNMP rather than a single central console. The product also integrates broad identity standards (SAML, OAuth, WS-Trust, OpenID Connect, JWT) and supports hybrid access control (RBAC/CBAC, XACML integration), extensive reporting, SIEM and big-data analytics exports, and high-availability deployment patterns—while accepting tradeoffs such as limited extensibility, a smaller partner network, and higher cost.
See All Locations
See All Locations