Surfil
// industries

Same architecture. Different regulators.

Zero-trace, signed outputs and offline verification don't change per industry - what changes is which of them your reviewer cares about. Here's the honest mapping.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Before the list

What our evidence is - and isn't

Every industry section below stands on the same three artifacts. None of them is a certification.

Signed attestations

Proof signs what your agents produced. The signature is checkable offline against a public key - that's the whole trust chain.

Mapped evidence

Charter maps measured facts onto control frameworks and exports the bundle. Your auditor draws the conclusion; we supply the verifiable inputs.

Architecture, inspectable

Zero-trace isn't attested by us - it's how the system is built. Your reviewers can validate it from the design, not our word.

We never say “certified”. Certification is a judgment only your auditor or regulator can make - Surfil's job is to hand them evidence they can verify without trusting us.
The contexts

Where the pressure lands, sector by sector

Each card names the regulatory pressure and states precisely what Surfil produces against it.

§ Financial services

the pressure

Model-risk reviews, vendor-risk questionnaires, and a blanket rule: nothing leaves the estate unaccounted for.

what Surfil produces

Proof attests each signed output; Charter maps Surfil's controls onto your framework (e.g. SOC 2-style control families) as evidence bundles your auditors verify offline - without a Surfil account.

Healthcare

the pressure

PHI exposure is the veto. Any tool that could carry patient data off-device is dead on arrival.

what Surfil produces

The zero-trace argument itself: source and prompts never leave the device, telemetry is metadata only, memory syncs as ciphertext. That's an architectural fact reviewers can check, not a policy promise.

Public sector

the pressure

Procurement wants evidence with provenance and a story for tampering - and distrusts vendor dashboards on principle.

what Surfil produces

Ed25519-signed outputs on a tamper-evident audit chain, plus an offline verifier. The evaluation can run in an air-gapped review room.

EU AI Act scope

the pressure

Documentation duties for AI use in development pipelines are arriving, and screenshots won't satisfy them.

what Surfil produces

Charter is being built to assemble dated, signed usage evidence into exportable bundles. It documents what your agents did - it does not and will not grade you compliant.

Agencies & consultancies

the pressure

Client contracts increasingly ask what AI touched the deliverable and whether the code stayed inside the engagement.

what Surfil produces

Per-repo signed receipts you can cite in a handover, and a portable Weave export at project end - the client keeps the knowledge, you keep the proof.

Framework mapping

What we produce, and what we won't claim

For the frameworks reviewers name most, here is the honest split: the artifact Surfil produces, and the judgment that stays with your auditor.

FrameworkWhat Surfil producesWhat it does not claim
SOC 2 control familiesCharter maps controls to signed evidence bundles your auditor verifies offline.That you are “SOC 2 compliant” - only your auditor makes that call.
HIPAA context (PHI)The zero-trace boundary: PHI-bearing source never leaves the device; telemetry is metadata only.To be a BAA or a HIPAA certification - it lowers exposure, it is not a legal status.
EU AI Act documentationDated, signed usage evidence assembled into exportable bundles (in build).A compliance grade - it documents what agents did, it does not judge you compliant.
Public-sector reviewEd25519-signed outputs on a tamper-evident chain, plus an offline verifier for air-gapped rooms.An authorization to operate - it produces the evidence, never the ATO itself.
The pattern

Every regulated rollout follows the same path

Whatever the sector, the sequence that turns a ban into a sign-off doesn't change.

1 · Architecture review

Your security team walks the zero-trace design: what runs on-device, what the edge sees, what telemetry contains.

2 · Verifier in their hands

Risk & compliance run surfil verify themselves, offline, before anything is deployed.

3 · Simulate first

Guard runs in monitor and simulate on real traffic - the would-block report goes to the reviewer, not past them.

4 · Evidence on a schedule

Signed bundles export on your audit cadence. The trail accumulates without anyone remembering to screenshot.

Put the verifier in your reviewer's hands

The fastest way through a regulated evaluation is letting risk & compliance check the signatures themselves. We'll set that up with your team.