Surfil
Surfil/Products/Proof
// surfil proof · enterprisepartly built

Signed attestation and action log.

Enterprises need to know - and prove - what an AI agent did in their environment. A screenshot or a log line isn't evidence; it's a claim.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Proof is partly built. Some of what follows ships on a linked device today and the rest does not. Your dashboard marks each capability, and nothing shows a number it has not measured.
What it does

Evidence, not log lines

Proof produces a signed attestation for agent actions: an Ed25519-signed, append-only log that can be independently verified without trusting Surfil's servers at the moment of the claim.

Signed action log - Every recorded action carries a server signature, not just a timestamp.
Offline verification - Attestations verify against a public key - no live call to Surfil required.
Append-only - The log can't be edited after the fact; corrections are new entries, not overwrites.
Audit-ready export - Attestation chains export in a portable, signed format for compliance review.

Proof, not promises

Proof produces one metric type on the shared spine: signed attestations. Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.

$ surfil verify rcpt_8f2a
✓ VALID (offline · epoch 7)
In your terminal

Proof, as you'd actually see it

audit - surfil proof
$ surfil proof export --range 2026-06
attestation chain · 4,812 entries · append-only
$ surfil verify attest_2026-06.surfilpkg
VALID (Ed25519 · epoch 7 · verified offline)
# chain intact - no entry modified after signing
How it works

How Proof does it

1Agent actions recorded on the spine are signed into an append-only log.
2Each entry chains to the previous one - tampering breaks the chain visibly.
3Attestations verify against published epoch keys, fully offline.
4Corrections are new signed entries; history is never rewritten.
5Chains export as .surfilpkg for auditors, regulators, or your own records.
Use cases

Where Proof earns its place

Regulated environments

Prove what agents did - and didn't do - without asking anyone to trust a vendor dashboard.

Incident review

Reconstruct agent activity from signed entries instead of mutable logs.

Third-party assurance

Hand an auditor the chain and the public key; they verify it themselves.

FAQ

Questions developers ask first

What makes this evidence rather than logs?

Signatures and append-only chaining. A log line asserts; an attestation proves.

Do verifiers need a Surfil account?

No. Verification is offline against published epoch public keys.

What if a signing key is compromised?

Keys rotate by epoch; historical signatures stay valid and rotation is dual-controlled.

Works well with

One spine - products compound

Add Proof to your agents.

Core installs with Starter; Proof plugs into the same interception point - no second layer, no new setup.