Surfil
// build log

Shipped means the gate passed.

Surfil is built in a fixed, gated order - each phase must close before the next opens. This log is that order, showing only what has actually cleared its gate.

surfil · one interception point
Claude CodeCursorCodex · Copilot
◈ interceptor
1. security2. cost3. quality4. observability5. memory
≋ one signed Weave spine
How to read it

Why this isn't a normal changelog

Three properties make this log different from the release notes you're used to skimming.

Gated, not dated

Entries are ordered by the build sequence, not a calendar. A phase ships when its closure criteria pass - never to hit a date.

Nothing pre-announced

A capability appears here only after it works. Everything still in flight lives on the roadmap, clearly marked as such.

Claims stay signed

When an entry says “verified”, there's a check behind it - byte-exact uninstall and passthrough are asserted in CI, not asserted in prose.

Shipped

The log, oldest gate first

Each block is one closed phase of the build order and what it locked in.

01

Foundation - governance & pricing

shippedFoundation
Pricing model validated: execution unmetered, one signed value-output = one Credit
Governance CI: honest-claims checks gate every release
Byte-exact passthrough asserted in CI - provider prefix hashes preserved
02

Interception core

shippedCoreSecurity
Single on-device interception point: CLIs (Claude Code, Codex) route through it, editors (Cursor, Windsurf) connect via MCP
No-key device auth (device flow, Ed25519 device tokens)
Weave engine + event spine: signed Markdown facts with provenance and code hash
Metering core: atomic, idempotent Credit decrements
03

Core product

shippedAdded
MCP consolidation engine with per-server verdicts
Clean uninstall: every agent config restored byte-for-byte, zero residue - verified
.surfilpkg export: your whole Weave, portable
04

Cap - first paid output

shippedAdded
Signed savings receipt: consume → sign → verify offline, no account
Savings reported in tokens where the fact is tokens - the conservative floor, measured before/after
Edge pipeline pinned to api.surfil.com with signed batches
Continuity

Old receipts never rot

A build log matters most for what it doesn't break. Signing key epochs rotate; history stays valid.

Key epochs

Signing keys rotate in epochs. A receipt signed in an earlier epoch keeps verifying against its epoch's public key forever - rotation never orphans your proof.

Offline verification, unversioned

surfil verify works against any receipt from any release, with no account and no network. Upgrading Surfil never invalidates a fact you already signed.

Incidents and their fixes will land in this log too, alongside features - see the status page for the standing incident-report policy.

See what's gated behind what

The roadmap shows the same build order pointing forward: what's in progress, what's planned, and why nothing has a promised date.