Same architecture. Different regulators.
Zero-trace, signed outputs and offline verification don't change per industry - what changes is which of them your reviewer cares about. Here's the honest mapping.
What our evidence is - and isn't
Every industry section below stands on the same three artifacts. None of them is a certification.
Signed attestations
Proof signs what your agents produced. The signature is checkable offline against a public key - that's the whole trust chain.
Mapped evidence
Charter maps measured facts onto control frameworks and exports the bundle. Your auditor draws the conclusion; we supply the verifiable inputs.
Architecture, inspectable
Zero-trace isn't attested by us - it's how the system is built. Your reviewers can validate it from the design, not our word.
Where the pressure lands, sector by sector
Each card names the regulatory pressure and states precisely what Surfil produces against it.
§ Financial services
Model-risk reviews, vendor-risk questionnaires, and a blanket rule: nothing leaves the estate unaccounted for.
Proof attests each signed output; Charter maps Surfil's controls onto your framework (e.g. SOC 2-style control families) as evidence bundles your auditors verify offline - without a Surfil account.
⛨ Healthcare
PHI exposure is the veto. Any tool that could carry patient data off-device is dead on arrival.
The zero-trace argument itself: source and prompts never leave the device, telemetry is metadata only, memory syncs as ciphertext. That's an architectural fact reviewers can check, not a policy promise.
◆ Public sector
Procurement wants evidence with provenance and a story for tampering - and distrusts vendor dashboards on principle.
Ed25519-signed outputs on a tamper-evident audit chain, plus an offline verifier. The evaluation can run in an air-gapped review room.
⚖ EU AI Act scope
Documentation duties for AI use in development pipelines are arriving, and screenshots won't satisfy them.
Charter is being built to assemble dated, signed usage evidence into exportable bundles. It documents what your agents did - it does not and will not grade you compliant.
▲ Agencies & consultancies
Client contracts increasingly ask what AI touched the deliverable and whether the code stayed inside the engagement.
Per-repo signed receipts you can cite in a handover, and a portable Weave export at project end - the client keeps the knowledge, you keep the proof.
What we produce, and what we won't claim
For the frameworks reviewers name most, here is the honest split: the artifact Surfil produces, and the judgment that stays with your auditor.
| Framework | What Surfil produces | What it does not claim |
|---|---|---|
| SOC 2 control families | Charter maps controls to signed evidence bundles your auditor verifies offline. | That you are “SOC 2 compliant” - only your auditor makes that call. |
| HIPAA context (PHI) | The zero-trace boundary: PHI-bearing source never leaves the device; telemetry is metadata only. | To be a BAA or a HIPAA certification - it lowers exposure, it is not a legal status. |
| EU AI Act documentation | Dated, signed usage evidence assembled into exportable bundles (in build). | A compliance grade - it documents what agents did, it does not judge you compliant. |
| Public-sector review | Ed25519-signed outputs on a tamper-evident chain, plus an offline verifier for air-gapped rooms. | An authorization to operate - it produces the evidence, never the ATO itself. |
Every regulated rollout follows the same path
Whatever the sector, the sequence that turns a ban into a sign-off doesn't change.
1 · Architecture review
Your security team walks the zero-trace design: what runs on-device, what the edge sees, what telemetry contains.
2 · Verifier in their hands
Risk & compliance run surfil verify themselves, offline, before anything is deployed.
3 · Simulate first
Guard runs in monitor and simulate on real traffic - the would-block report goes to the reviewer, not past them.
4 · Evidence on a schedule
Signed bundles export on your audit cadence. The trail accumulates without anyone remembering to screenshot.
Put the verifier in your reviewer's hands
The fastest way through a regulated evaluation is letting risk & compliance check the signatures themselves. We'll set that up with your team.