Surfil
Surfil/Products/Charter
// surfil charter · enterprisepartly built

Offline-verifiable compliance evidence.

Compliance reviews ask for evidence, not assurances. Screenshots and self-reported logs don't hold up, and re-collecting evidence for every audit is expensive.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Charter is partly built. Some of what follows ships on a linked device today and the rest does not. Your dashboard marks each capability, and nothing shows a number it has not measured.
What it does

Compliance evidence, verified offline

Charter packages signed Weave facts and Proof attestations into compliance evidence that verifies without a network call - hand it to an auditor and let them check the signature themselves.

Signed evidence packages - Compliance artifacts are signed, not asserted.
Offline verification - An auditor can verify authenticity without contacting Surfil.
Built from Weave + Proof - Reuses facts and attestations already generated - no separate evidence-collection pass.
Portable format - Exports as `.surfilpkg`, the same portable format used across Surfil.

Proof, not promises

Charter produces one metric type on the shared spine: evidence bundles exported. Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.

$ surfil verify rcpt_8f2a
✓ VALID (offline · epoch 7)
In your terminal

Charter, as you'd actually see it

compliance - surfil charter
$ surfil charter bundle --framework soc2 --controls CC6,CC7
# collecting signed facts + attestations already on the spine…
evidence bundle: charter_soc2_q2.surfilpkg (signed)
$ surfil verify charter_soc2_q2.surfilpkg
VALID (offline · epoch 7 · auditor needs no account)
How it works

How Charter does it

1Charter maps framework controls to the signed facts and attestations you already generate.
2A bundle is assembled from Weave + Proof - no separate evidence-collection pass.
3The bundle itself is signed and exports as a portable .surfilpkg.
4Auditors verify it offline against published keys - no vendor trust required.
5Re-audits reuse the same pipeline: new bundle, same one-command export.
Use cases

Where Charter earns its place

SOC 2 evidence

Map controls to signed facts, not screenshots gathered the week before an audit.

EU AI Act preparation

Package agent-activity evidence in a form a regulator can verify independently.

Vendor security reviews

Answer 'prove it' with a signed bundle the reviewer verifies for themselves.

FAQ

Questions developers ask first

Does Charter certify us?

No - Surfil is never 'certified'. Charter produces verifiable evidence; certifying is your auditor's call.

Can auditors verify without Surfil?

Yes. Bundles verify offline against published epoch keys, with no account and no network call.

Is this extra work for the team?

No new collection pass - bundles reuse the signed facts and attestations already on the spine.

Works well with

One spine - products compound

Add Charter to your agents.

Core installs with Starter; Charter plugs into the same interception point - no second layer, no new setup.