Surfil
// enterprise

Agents your security team can sign off on.

Zero-trace by construction, Ed25519-signed outputs and offline-verifiable evidence - plus the identity, fleet and procurement path that turns an agent ban into a governed rollout.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
The evaluation

Your reviewers verify us - not the reverse

Most vendor evaluations end at 'trust our compliance page'. Ours starts by handing risk & compliance the verifier.

Run the verifier first

Before any deployment, your team runs surfil verify on sample receipts - offline, against a public key, with no Surfil account.

Walk the architecture

A working session with your security engineers on what runs on-device, what the edge sees, and where each failure closes.

Pilot with simulation only

The pilot runs Guard and Policy in simulate. Your team reviews the would-block evidence before a single rule enforces.

The stack

Four enterprise products, one spine

Same interception point as every developer's install - these add the org-level governance on top.

Identity

SSO, devices and least privilege

Enterprise access control follows the same fail-closed doctrine as the interception path.

SSO (OIDC)

Sign-in through your identity provider. Sessions, device approvals and revocations all trace to directory identities.

Device flow + Ed25519 tokens

Developers authorize devices with a standard device flow; each device holds its own signing identity, revocable fail-closed.

RBAC, least-privilege

Admin and operator surfaces are separately gated. Nobody gets a permission because it was convenient to grant.

Tamper-evident audit

Admin actions land on a hash-chained audit trail - your reviewers can check the chain, not just read the log.

Fleet governance

From unknown agents to governed fleet, in order

The rollout sequence is fixed on purpose: visibility before rules, simulation before enforcement, enforcement before evidence.

1 · Register

Fleet Control builds the device registry: which machines, which agents, which versions - the inventory answer, finally.

2 · Discover

Shadow discovery surfaces the agents nobody declared. You govern what exists, not what was reported.

3 · Simulate

Policy runs proposed rules against real org traffic and shows the blast radius before anything is enforced.

4 · Enforce & evidence

Rules go live fail-closed; Charter accumulates the signed evidence trail on your audit cadence.

Procurement

The answers your questionnaire will ask

Six cards that map to the sections of a standard vendor-risk review.

Data handling

Telemetry is metadata only; memory syncs as ciphertext (E2E); tenants are RLS-isolated. Source never leaves developer devices.

Deployment model

On-device Rust runtime plus stateless edge workers. No appliance to rack and no gateway to scale, so cost stays flat per user.

Evidence, not badges

Control mapping plus exportable, offline-verifiable evidence bundles via Charter. We never claim “certified” - your auditor judges.

Commercials

Custom pricing, uptime SLA, dedicated engineer, quarterly security review. Practical-unlimited credits - see pricing for the model.

Exit path

Clean uninstall restores every config byte-for-byte; .surfilpkg exports the knowledge network. Leaving is engineered, not negotiated.

Security review

The complete threat model, the key-epoch design and the fail-closed inventory all live on the security page - so bring your reviewers along.

Honest-claims policy applies to sales too: we quote no savings percentage, in the deck, the pilot or the contract. What your agents cost is measured on your own traffic and reported in tokens where the fact is tokens.

Put it in front of your security team

One working session: your reviewers, our architecture, the offline verifier in their hands. If it doesn't survive that room, you'll know in an hour.