Surfil
// on-device control plane for AI coding agents

One install. Cheaper, safer, and remembered.

Surfil runs beside Claude Code, Cursor, Codex & Copilot. The tools that route through it get cheaper and safer; editors like Cursor connect through MCP - every claim proven with a signature, and your source never leaves the machine.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Works with
Claude CodeCursorCodexCopilotMCP agents
byte-exact
never busts your prompt cache
0
lines of source leave device
100%
offline-verifiable receipts
1
interception point
Proof you can verify yourself

Don't trust our numbers. Check the signature.

Every Surfil claim ships as an Ed25519-signed receipt. Verification runs offline, with no account - on your machine, against a public key. This is what it looks like:

~/acme/api - surfil
$ surfil consolidate
# scanning 6 MCP servers across Claude Code + Cursor…
consolidated 6 → 1 endpoint saved ~48k tokens/op
$ surfil audit
recoverable spend this week: $96.40 (signed: rcpt_8f2a)
$ surfil verify rcpt_8f2a
✓ VALID (offline · epoch 7 · no account)
The numbers above are illustrative. Yours are measured on your own repos. We publish no fixed savings percentage, because the honest answer depends on your traffic: what Surfil guarantees is that every figure is measured and signed, and that interception is byte-exact, so the provider prompt cache that already removes most of your input cost keeps hitting.
The problem

Agents are expensive, risky, and forgetful

Not because they're bad - because nothing sits beside them watching cost, safety and memory across all of them at once.

Expensive

Agents re-send the same context and re-read the same files. Token spend creeps up and nobody can point to why - or prove what's recoverable.

Risky

Agents run shell commands, hit the network, and paste payloads. One leaked key or injected tool-call is discovered after it already happened.

Forgetful

Every session starts from zero. Agents re-derive your architecture, re-ask settled questions, and forget the decisions you already made.

What Surfil does

Cheaper, safer, remembered - on one spine

Three products carry the consumer story. All of them are stages on the same pipeline, writing to the same signed knowledge network.

How it works

Install. Intercept once. Verify the receipt.

Three steps between your current agent bill and a signed number you can hand to anyone.

1 · Install

One install beside Claude Code, Cursor, Codex and Copilot. Core consolidates your scattered agent configs and bootstraps Weave.

2 · Intercept once

A single on-device interception point, byte-exact passthrough. Every product is a stage on the same pipeline; no second proxy, ever.

3 · Verify the receipt

Savings and outputs are measured, then Ed25519-signed. Run surfil verify on any receipt - offline, no account. The signature is the proof.

The catalog

Eleven products, one interception point

Each product produces exactly one metric type on the shared spine - so every number has a source and a signature.

Why you can trust it

Four rules we can't break

These aren't policies - they're architecture. Breaking any of them would require rebuilding the product.

Zero-trace

Source never leaves the device. Telemetry is metadata only; memory syncs as ciphertext.

Signed outputs

Every paid output is Ed25519-signed and verifiable offline - no trust-us dashboards.

Honest claims

Measured facts, never “certified”. Savings reported in tokens, at the conservative floor.

One layer

A single interception point, by rule. We never chain a second proxy to sell you more.

Pricing

Execution is unmetered. Signed output is metered.

You're never charged for running your agents - only for the server-signed value-outputs Surfil produces. One signed output = one Credit.

Starter

$5/mo

Core install, Guard monitor and the Cap cost ledger

Choose Starter
recommended

Pro

$25/mo

Guard enforce, Cap full, Mind, Radar · Bench · Pilot

Start with Pro

Team

$20/seat

Everything in Pro, plus team dashboards and pooled credits

Talk to sales

Enterprise

custom

Proof · Fleet Control · Charter · Policy + SSO/SLA

Contact sales
FAQ

Questions developers ask first

Does my source code leave my machine?

No. Zero-trace is architectural, not a setting. The heavy work runs in the on-device runtime; telemetry is metadata only and memory syncs as ciphertext.

How much will I actually save?

That depends on whether your agents already use prompt caching, and Surfil measures which case you are in. If they do, the provider cache is already removing most of your input cost, and byte-exact interception means Surfil never busts it. If they do not, Surfil can safely prune context an agent already superseded. We publish no fixed percentage: you get the measured figure on your own traffic, in tokens, never an invented dollar amount.

Which agents does it work with?

Claude Code, Cursor, Codex, Copilot and 30+ more, from one install. It connects each the way it can - full traffic interception for CLIs and MCP, MCP for editors like Cursor. Run surfil doctor to see how each connects.

What is a Credit?

Execution is unmetered. One server-signed value-output equals one Credit. You're metered on signed output, never on running the agent.

Can I verify the savings myself?

Yes. Run surfil verify on any receipt - offline, no account. The signature (Ed25519) is the proof, not a dashboard.

What happens if I uninstall?

A clean uninstall restores every agent config byte-for-byte and leaves zero residue. Export your Weave anytime with surfil export.

Install once. Verify everything after.

Core installs beside your agents. Cap, Guard and Mind light up for the tools that route through Surfil - nothing leaves your device, and uninstalling restores every config byte-for-byte.