Surfil
// contact

A human reads this. Usually a founder.

Surfil is a small team, which cuts both ways: no support labyrinth, but also no pretend 24/7 chat widget. Here's every real way to reach us and what to expect from each.

surfil verify rcpt_8f2a
Signed savings receiptVALID
receiptrcpt_8f2a
typeprefix-cache + prune
saved48,200 tokens
measuredbefore / after
signatureed25519:… (epoch 7)
verifiedoffline · no account
Run surfil verify on any receipt - the signature is the proof.
Faster than email

Three questions that answer themselves

If yours is one of these, you'll have the answer before we'd have opened your message.

Product question?

The help center's search usually beats an email round-trip.

Search the answers

Something seems down?

Check the live health endpoint before writing - it answers instantly.

Check live status

How-does-it-work question?

The pipeline deep-dive answers most architecture questions end to end.

Read the deep-dive
Write to us

Send a message

Pick a topic so it lands with the right person. Submitting opens your own mail client - your message goes directly to us, not into a CRM you never consented to.

Send a message

Direct routes

Sales & procurement
sales@surfil.com

Plans, seats, enterprise evaluations and architecture reviews.

Security disclosure
security@surfil.com

Vulnerabilities and security concerns - read the disclosure notes below first.

Careers
careers@surfil.com

Applications and role questions - open roles are on the careers page.

What to expect

Honest response targets

The same targets our support tiers commit to - stated here so nobody has to guess.

Standard

One business day for Pro and Team accounts, best-effort for Community-tier and pre-sales questions. A real reply, not an autoresponder.

Priority & Enterprise

Four-hour targets and SLA-backed response respectively, with a named contact. Details on the services page.

Security reports

Acknowledged fastest of all. Fail-closed applies to comms too - if we're investigating, you'll know we received it.

Security disclosure

Found something? Tell us properly.

Reports about the interception path, signing, or the verifier get priority handling.

What helps us fix it fast

Steps to reproduce, the surface involved (runtime, edge, Hub), and impact as you understand it. Don't include real secrets or your own source in the report - consistent with what we'd tell you about any channel.

What you can expect back

Acknowledgment, an honest severity assessment, and the fix landing in the build log once shipped. We credit reporters who want credit.

Full security posture - threat model, signing, fail-closed inventory - is on the security page.