Build the layer agents run through.
Surfil is the interception point every AI coding agent passes through. The team is small, remote and async-first - and honest about everything, including what working here is like.
What you'd actually sign up for
Not a mission statement - the four product rules your work would be held to.
Zero-trace by construction
Source never leaves the device. Not a setting - the architecture. If a feature needs your code off-box, we don't ship it.
Prove, don't promise
Every paid output is Ed25519-signed and verifiable offline with no account. No trust-us dashboards.
Honest by policy
Never “certified”. No invented injection rates. No published savings percentage: cost is always measured on your own traffic.
One layer, forever
A single interception point. We will never chain a second competing proxy to sell you more.
The working rules
These are the habits that shape a week here - all of them verifiable from how the product ships.
Remote and async-first
Written decisions over meetings. The build order, the gates and the closure criteria are all documents anyone can read.
Gated, in order
Products ship in a fixed sequence. The next one is blocked until the previous one's foundation gate passes - anti-drift by design.
Measure before claiming
Nothing goes on the marketing site that isn't measured on real traffic first. If we can't measure it, we don't say it.
Small surface, hard invariants
Fewer features, held to rules that can't be broken without rebuilding the product: zero-trace, signed outputs, one layer, fail-closed.
What the job feels like
Three things that are true here and rare elsewhere.
Ship against gates, not sprints
Work lands when its closure criteria pass, in a fixed build order. No feature-factory churn, no half-shipped surfaces.
Own an invariant
Every engineer holds one of the hard rules - byte-exact passthrough, fail-closed security, honest claims - and can veto anything that breaks it.
Write things down
Decisions live in documents, not meetings. If it isn't written, it didn't happen - which is what makes async-first actually work.
Where we need help now
Every role is remote. If you're strong but off-profile, write anyway - the roles below are where the pain is, not a hard wall.
Senior Rust Engineer - Runtime
Engineering · Remote (GMT±4) · Full-timeOwn parts of the on-device runtime: adapters, interceptor, pipeline stages. You care about byte-exact behavior and sub-millisecond overhead.
Edge Engineer - Workers/TypeScript
Engineering · Remote · Full-timeStateless Cloudflare Workers: auth, entitlement, ingest, metering, signing. D1 + idempotency keys. You keep cost flat per user.
Security Engineer
Security · Remote · Full-timeGuard, Proof and Charter. Threat-model the interception path, own fail-closed defaults, keep our claims honest.
Product Designer
Design · Remote · Full-timeHub dashboards and the marketing surface. Make signed proof legible to a developer at 2am.
Developer Advocate
Growth · Remote · Full-timeDocs, benchmarks, honest content. You'll publish methodology, not hype.
Four steps, no theater
You should know exactly what happens after you hit send.
1 · Email us
Send your application to the role's address. A human reads it - there's no ATS keyword filter on the other side.
2 · Two conversations
One technical deep-dive on your past work, one on how you'd hold the invariants. No whiteboard hazing.
3 · Paid work sample
A small, real, paid task from the actual backlog - you see how we work, we see how you work.
4 · Decision in writing
A clear yes or no with reasons, fast. The same honesty policy that governs our marketing governs our hiring.