Surfil
// what teams measure

We don't have a logo wall. We have a methodology.

Surfil is early, and we won't invent customers to look bigger. Here's what teams measure with it, how the numbers are produced, and why you can check every one of them yourself.

surfil verify rcpt_8f2a
Signed savings receiptVALID
receiptrcpt_8f2a
typeprefix-cache + prune
saved48,200 tokens
measuredbefore / after
signatureed25519:… (epoch 7)
verifiedoffline · no account
Run surfil verify on any receipt - the signature is the proof.
The method

Baseline. Delta. Signature.

Every number a team gets out of Surfil follows the same three steps - which is why none of them need our marketing to be believable.

1 · Baseline

Surfil watches a normal week of your real agent traffic before changing anything. The baseline is yours, not an industry average.

2 · Measure the delta

Consolidation, cache tuning, pruning - each change is measured before/after on the same repos, in tokens where the fact is tokens.

3 · Sign the fact

The measured delta is Ed25519-signed into a receipt. From that moment it verifies offline, with no account and no Surfil in the loop.

Scenarios · illustrative

Three teams, three measurements

Unnamed on purpose. These walkthroughs show what the product measures in each situation - not results any specific customer reported.

A typical solo developer

illustrative scenario

Two agents (Claude Code + Cursor), several MCP servers accumulated over months, token spend creeping with no visibility into why.

What gets measured

Core consolidates the MCP sprawl to one endpoint and records tokens-per-operation before and after
Cap's ledger attributes spend per repo and per agent from day one
The first signed savings receipt lands after a normal week of traffic
The receipt: Recoverable tokens per week, measured on their own repos, signed as a receipt they can re-verify offline anytime.

A typical Pro team

illustrative scenario

A handful of developers, mixed agents, a security lead who wants agent tool-calls reviewed before anything is blocked in anger.

What gets measured

Guard runs in monitor, then simulate - the team sees exactly what would have been blocked, on real traffic, before enforcing
Cap measures the before/after of prefix-cache tuning across the team's shared repos
Every claim that reaches a manager is a signed receipt, not a screenshot
The receipt: A simulation report of would-be blocks plus a per-repo savings floor - both signed, both reproducible.

A typical regulated org

illustrative scenario

Agents blocked by risk & compliance because nobody can prove what leaves the box or attest to what agents produce.

What gets measured

Zero-trace is the unblock: telemetry is metadata only, memory syncs as ciphertext - verifiable from the architecture, not a policy PDF
Every paid output is Ed25519-signed; auditors run the offline verifier themselves, with no Surfil account
Evidence bundles map to their control framework without ever using the word “certified”
The receipt: An evidence trail their auditors verify independently - the signature is the proof, not our dashboard.
The artifact

What a signed receipt looks like

This is the output every scenario above ends in. The numbers in the frame are illustrative product UI - yours are measured on your own traffic.

~/your-repo - surfil
$ surfil audit --week
# baseline vs. current, same repos, same window
tokens recovered: 312k (floor: 31% of baseline)
receipt signed: rcpt_4c19 (Ed25519 · epoch 7)
$ surfil verify rcpt_4c19
✓ VALID (offline · no account · anyone can run this)
Hand the receipt to a manager, a security lead, or an auditor - surfil verify checks the signature against a public key, offline. Nobody has to trust this website.
The policy

What this page will never show

Our honest-claims policy is architectural for the product and editorial for this site. Both are enforced.

No named customers we don't have

A case study appears here when a real team agrees to publish one - measured, attributable, signed. Until then, this page stays scenario-only.

No invented quotes

Every quote you'll ever read on this site will name a real person who approved it. There are none yet, so there are none here.

No universal percentages

We publish no savings percentage at all, universal or otherwise. Every cost figure is measured per-repo on your own traffic before it is shown.

Run the measurement on your own repos

One Core install, a normal week of traffic, one signed receipt. If the floor doesn't show up in your numbers, you've lost nothing - uninstall restores every config byte-for-byte.