Shipped means the gate passed.
Surfil is built in a fixed, gated order - each phase must close before the next opens. This log is that order, showing only what has actually cleared its gate.
Why this isn't a normal changelog
Three properties make this log different from the release notes you're used to skimming.
Gated, not dated
Entries are ordered by the build sequence, not a calendar. A phase ships when its closure criteria pass - never to hit a date.
Nothing pre-announced
A capability appears here only after it works. Everything still in flight lives on the roadmap, clearly marked as such.
Claims stay signed
When an entry says “verified”, there's a check behind it - byte-exact uninstall and passthrough are asserted in CI, not asserted in prose.
The log, oldest gate first
Each block is one closed phase of the build order and what it locked in.
Foundation - governance & pricing
Interception core
Core product
Cap - first paid output
Old receipts never rot
A build log matters most for what it doesn't break. Signing key epochs rotate; history stays valid.
Key epochs
Signing keys rotate in epochs. A receipt signed in an earlier epoch keeps verifying against its epoch's public key forever - rotation never orphans your proof.
Offline verification, unversioned
surfil verify works against any receipt from any release, with no account and no network. Upgrading Surfil never invalidates a fact you already signed.
See what's gated behind what
The roadmap shows the same build order pointing forward: what's in progress, what's planned, and why nothing has a promised date.