Surfil
// resources

Everything here exists. Read it now.

No phantom whitepapers and no “webinar coming soon”. Everything indexed here exists. One item, the August field report, asks for an email before its full detail, and its findings and every caveat on them are readable without one.

architecture.weave.md
--- fact: Auth uses device flow (RFC 8628) source: acme/api@a91f code_hash: a91f…3c2 ✓ fresh --- fact: Legacy webhook path /hooks/v0 code_hash: 2b7e…901 ⚠ STALE ---
Portable, signed, offline-verifiable.surfilpkg
The library

Seven reads, one of them asks for an address

Six of these link straight to the material. The seventh is the field report: its headline finding, its method and every caveat are public, and the full run detail opens once you confirm an address.

By type

What each label means

Four kinds of material, held to different standards.

Architecture

How the system is built and why. Verifiable against the product's behavior, not marketing diagrams.

Methodology

How we measure before we claim - benchmarks, savings floors, false-positive rates. Dated and reproducible.

Spec

Formats you can build against: signed Markdown, frontmatter, provenance, code hashes.

Docs

The operational surface - install, consolidate, audit, verify, export. Kept current with what's shipped.

Reading paths

Three ways in, depending on your question

Most visitors arrive with one of these three jobs. Each has a shortest path.

Evaluating the security story

Start with the zero-trace architecture, then the Weave format - that pair answers most security-review questions.

Start the security read

Justifying the cost

Read how savings are measured and signed, then estimate your own floor from the pricing page's seat estimator.

Estimate your floor

Getting hands-on

Skip the reading: install Surfil, run a week of traffic, and let the receipt be the resource.

Install and measure
Coming

What we'll add - when it's real

Two things belong in this library and aren't in it yet. They'll appear when they exist, not before.

Fleet rollout playbook

A simulate-before-enforce rollout template for 50+ developer orgs - published once it's been exercised by a real rollout, so it's a record rather than a guess.

Standalone offline verifier

A single binary that verifies any receipt with no Surfil install at all. On the roadmap, planned column - which tells you exactly how committed and how scheduled it is.

New methodology posts land on the blog first, then get indexed here.

Or skip the library entirely

The most convincing resource is a receipt measured on your own repos. One install, one week of normal traffic, one signed number.