Surfil
Surfil/Products/Policy
// surfil policy · enterprisepartly built

Simulate policy packs before you enforce them.

Rolling out a new security or cost policy blind risks breaking real workflows. Rolling it out slowly risks the gap it was meant to close.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Policy is partly built. Some of what follows ships on a linked device today and the rest does not. Your dashboard marks each capability, and nothing shows a number it has not measured.
What it does

Simulate before you enforce

Policy lets you simulate a policy pack against real agent activity before switching it to enforce - see exactly what it would have blocked or allowed, then flip it on with confidence.

Simulate-before-enforce - Run a policy pack in observe mode against live activity before it blocks anything.
Policy packs - Compose Guard/Fleet Control rules into a named, versioned pack you can roll out deliberately.
Diff view - See exactly what would change between your current policy and a candidate one.
Staged rollout - Move a pack from simulate to enforce per device group, not all-or-nothing.

Proof, not promises

Policy produces one metric type on the shared spine: simulated verdicts before enforcement. Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.

$ surfil verify rcpt_8f2a
✓ VALID (offline · epoch 7)
In your dashboard

Policy, as you'd actually see it

hub.surfil.com/policy
pack v4 (candidate)simulated against 7 days of real activity
+2 blocks/dayvs. current pack v3 - all secret-exfil attempts
0developer workflows newly broken
stagedenforce on platform team first, then fleet-wide
Illustrative policy diff - what a candidate pack would change before anyone enforces it.
How it works

How Policy does it

1Author or import a policy pack - named, versioned, reviewable.
2Simulate it against real recorded agent activity; nothing is blocked yet.
3The diff view shows exactly what would change versus the current pack.
4Enforce per device group - platform team first, fleet-wide when proven.
5Every verdict, simulated or enforced, lands on the same signed spine.
Use cases

Where Policy earns its place

Tightening secret rules

Prove a stricter pack blocks the bad calls and nothing else before flipping it on.

Blast-radius control

Stage the rollout by device group instead of betting the entire fleet at once.

Policy review with evidence

Bring the diff to a security review instead of just a verbal promise.

FAQ

Questions developers ask first

Can simulate mode break anything?

No - it's observe-only. Verdicts are recorded, nothing is blocked.

How long should we simulate?

As long as you need to trust the diff. Many teams run a full sprint before enforcing.

What engines do packs drive?

Guard's pre-flight checks and Fleet Control's device rules - one pack, both layers.

Works well with

One spine - products compound

Add Policy to your agents.

Core installs with Starter; Policy plugs into the same interception point - no second layer, no new setup.