Surfil
// about

We build proof, not promises.

Surfil is an on-device control plane that runs beside your AI coding agents. One install, one signed knowledge network, zero source leaving the machine.

architecture.weave.md
--- fact: Auth uses device flow (RFC 8628) source: acme/api@a91f code_hash: a91f…3c2 ✓ fresh --- fact: Legacy webhook path /hooks/v0 code_hash: 2b7e…901 ⚠ STALE ---
Portable, signed, offline-verifiable.surfilpkg
Why it exists

The gap between the token bill and the sign-off

Surfil started from a specific, common pain - and a refusal to solve it the usual way.

The problem we had

Four figures a month across multiple agents, no shared cost view, and no report a security team would sign. Every existing fix wanted the code shipped to someone else's cloud first.

The bet we made

Do the heavy work on the device, intercept once, and make every paid claim a signature instead of a dashboard. If a number can't be verified offline by the person reading it, it isn't proof.

What we believe

Four rules we can't break

These aren't values-page decoration. Each one is enforced by the architecture - breaking any would mean rebuilding the product.

Zero-trace by construction

Source never leaves the device. Not a setting - the architecture. If a feature needs your code off-box, we don't ship it.

Prove, don't promise

Every paid output is Ed25519-signed and verifiable offline with no account. No trust-us dashboards.

Honest by policy

Never “certified”. No invented injection rates. No published savings percentage: cost is always measured on your own traffic.

One layer, forever

A single interception point. We will never chain a second competing proxy to sell you more.

How we work

Small team habits, held in writing

No headcount theater here - just the working rules that shape what ships and when.

Remote and async-first

Written decisions over meetings. The build order, the gates and the closure criteria are all documents anyone can read.

Gated, in order

Products ship in a fixed sequence. The next one is blocked until the previous one's foundation gate passes - anti-drift by design.

Measure before claiming

Nothing goes on the marketing site that isn't measured on real traffic first. If we can't measure it, we don't say it.

Small surface, hard invariants

Fewer features, held to rules that can't be broken without rebuilding the product: zero-trace, signed outputs, one layer, fail-closed.

The refusals

What we will never ship

A company is defined as much by its refusals as its roadmap. Ours are structural.

A cloud proxy

Any feature that needs your source off-box doesn't get built. Zero-trace is the architecture, so this is a permanent no.

A second layer

One interception point, by rule. We will never chain another proxy behind the first to sell an add-on.

A trust-us dashboard

If a number can't be measured and signed, it doesn't become a claim - not in the product, not on this site.

A “certified” badge

We produce evidence auditors verify themselves. We never sell the word certified, because we can't prove it.

Judge us by the receipts

The build log shows what's shipped; the roadmap shows what's gated behind what. Both are honest about the difference.