See what your AI coding tools actually cost you - and stop them leaking secrets.
One command, running next to the agents you already use. Everything stays on your machine, and your source code never leaves it.
Surfil installs with one command in a terminal. You will need a Mac, Linux or Windows computer to run it. On a phone, take the link with you instead.
Email me the trial linkPoint it at your own agents and see what they actually cost, measured before and after, on your traffic rather than ours. Includes 250 signed outputs.
The screen above is an example. The numbers you see are measured from your own machine.
We'll send the trial link
One email, and the $1 trial is one tap away when you're back at a terminal.
Email me the trial link
14 days of Pro for $1, then $25/mo unless you cancel. We'll send the checkout link - no CLI needed to receive it.
One click to confirm, one click to leave, any time. No sharing, no selling.
Your agents cost more than you think, and you cannot see it
Not because the tools are bad. Because nothing sits beside them keeping track, so the bill, the leaks and the forgotten context are all invisible until they are not.
Expensive
Agents re-send the same context and re-read the same files. Token spend creeps up and nobody can point to why - or prove what's recoverable.
Risky
Agents run shell commands, hit the network, and paste payloads. One leaked key or injected tool-call is discovered after it already happened.
Forgetful
Every session starts from zero. Agents re-derive your architecture, re-ask settled questions, and forget the decisions you already made.
It answers all three, from one place
You install one thing. It watches every agent you route through it, so cost, safety and memory stop being three separate problems you have no view of.
You can see the bill
Where your money actually goes, request by request, taken from the provider’s own token counts rather than our guess. Most of an agent bill is re-sent context, and this is the first time you get to look at it.
Details →Nothing leaks by accident
It reads every request before it leaves your machine and stops the ones carrying an API key, a token, or an instruction hidden in a tool response. You can watch it decide before you let it block anything.
Details →It stops forgetting
Facts your agents work out stay available to all of them, with a note of where each came from. When the code they describe changes, they are flagged as out of date instead of quietly lying to you.
Details →One command, then it runs by itself
You install it once, keep using your agents exactly as you do now, and read the numbers it collects.
1 · Run one command
It installs next to Claude Code, Cursor, Codex and Copilot and tidies up the config files they each keep separately. Nothing else changes.
2 · Keep working normally
Your agents carry on exactly as before. Surfil sits in the middle counting what they spend and checking what they send, without slowing anything down or changing a single request.
3 · Read your own numbers
What your agents cost, what almost leaked, what they learned. Measured from your traffic - and signed, so you can prove any figure to somebody else without an account.
Don't trust our numbers. Check the signature.
Every Surfil claim ships as an Ed25519-signed receipt. Verification runs offline, with no account - on your machine, against a public key. This is what it looks like:
The first run we published is the one where we saved nothing
Every tool in this category quotes a percentage. Here is a real run from our own machine, including the figure that does us no favours.
removed from 533 intercepted requests. Nothing redundant was there, so nothing was taken out and nothing is claimed. A number you can check beats a percentage you cannot.
of 533 requests, 0 blocked. Two kinds of credential were seen in outbound traffic before it left the machine: anthropic-keygithub-token
Eleven products, one interception point
Each product produces exactly one metric type on the shared spine - so every number has a source and a signature.
Core
ConsumerThe install that bootstraps everything else.
Cap
ConsumerSee what your context really costs, signed.
Guard
ConsumerSandbox and block risky tool calls before they run.
Mind
ConsumerLocal, encrypted memory your agents can reuse.
Radar
ConsumerObservability and rewind - metadata only.
Bench
ConsumerLeaderboard and a signed savings receipt.
Four rules we can't break
These aren't policies - they're architecture. Breaking any of them would require rebuilding the product.
Zero-trace
Source never leaves the device. Telemetry is metadata only; memory syncs as ciphertext.
Signed outputs
Every paid output is Ed25519-signed and verifiable offline - no trust-us dashboards.
Honest claims
Measured facts, never “certified”. Savings reported in tokens, at the conservative floor.
One layer
A single interception point, by rule. We never chain a second proxy to sell you more.
The first two are checkable rather than promised: the code that reads your traffic is public and Apache-2.0. Build it, run its tests, and see whether you agree before you install anything.
Execution is unmetered. Signed output is metered.
You're never charged for running your agents - only for the server-signed value-outputs Surfil produces. One signed output = one Credit.
Pro
Guard enforce, Cap full, Mind, Radar · Bench · Pilot
Start Pro for $1Questions developers ask first
Does my source code leave my machine?
No. Zero-trace is architectural, not a setting. The heavy work runs in the on-device runtime; telemetry is metadata only and memory syncs as ciphertext.
How much will I actually save?
That depends on whether your agents already use prompt caching, and Surfil measures which case you are in. If they do, the provider cache is already removing most of your input cost, and byte-exact interception means Surfil never busts it. If they do not, Surfil can safely prune context an agent already superseded. We publish no fixed percentage: you get the measured figure on your own traffic, in tokens, never an invented dollar amount.
Which agents does it work with?
Claude Code, Cursor, Codex, Copilot and 26 more, from one install. It connects each the way it can - full traffic interception for CLIs and MCP, MCP for editors like Cursor. Run surfil doctor to see how each connects.
What is a Credit?
Execution is unmetered. One server-signed value-output equals one Credit. You're metered on signed output, never on running the agent.
Can I verify the savings myself?
Yes. Run surfil verify on any receipt - offline, no account. The signature (Ed25519) is the proof, not a dashboard.
What happens if I uninstall?
A clean uninstall restores every agent config byte-for-byte and leaves zero residue. Export your Weave anytime with surfil export.
Then take the thing that costs nothing
No schedule, no drip, and one click to leave.
Tell me when Surfil starts cutting the bill
Cap measures what your context costs today; it does not reduce it yet. That work is next, and this is the only way to hear when it lands. One email, no schedule.
One click to confirm, one click to leave, any time. No sharing, no selling.
Install once. Verify everything after.
Core installs beside your agents. Cap, Guard and Mind light up for the tools that route through Surfil - nothing leaves your device, and uninstalling restores every config byte-for-byte.