Everything here exists. Read it now.
No gated PDFs, no “webinar coming soon”. This library indexes the deep material already published on this site - architecture, methodology and specs.
Six reads, zero gates
Each card links straight to the material - no email wall, because an email wall in front of an honesty pitch would be a joke.
Zero-trace architecture, in depth
How interception stays on-device and why telemetry is metadata only.
Read it now →ArchitectureHow the pipeline works, end to end
Install → one interception point → five stages → one signed spine.
Read it now →SpecThe Weave format
Signed Markdown: frontmatter, provenance, code hash, automatic STALE flagging.
Read it now →MethodologyBenchmarking agents honestly
Dated runs, false-positive/negative rates, no fixed injection numbers.
Read it now →MethodologyThe case against cost dashboards
Why every paid claim ships as a signature you can verify offline.
Read it now →DocsDocs & CLI reference
Install, consolidate, audit, verify, export - the full command surface.
Read it now →What each label means
Four kinds of material, held to different standards.
Architecture
How the system is built and why. Verifiable against the product's behavior, not marketing diagrams.
Methodology
How we measure before we claim - benchmarks, savings floors, false-positive rates. Dated and reproducible.
Spec
Formats you can build against: signed Markdown, frontmatter, provenance, code hashes.
Docs
The operational surface - install, consolidate, audit, verify, export. Kept current with what's shipped.
Three ways in, depending on your question
Most visitors arrive with one of these three jobs. Each has a shortest path.
Evaluating the security story
Start with the zero-trace architecture, then the Weave format - that pair answers most security-review questions.
Start the security readJustifying the cost
Read how savings are measured and signed, then estimate your own floor from the pricing page's seat estimator.
Estimate your floorGetting hands-on
Skip the reading: install Surfil, run a week of traffic, and let the receipt be the resource.
Install and measureWhat we'll add - when it's real
Two things belong in this library and aren't in it yet. They'll appear when they exist, not before.
Fleet rollout playbook
A simulate-before-enforce rollout template for 50+ developer orgs - published once it's been exercised by a real rollout, so it's a record rather than a guess.
Standalone offline verifier
A single binary that verifies any receipt with no Surfil install at all. On the roadmap, planned column - which tells you exactly how committed and how scheduled it is.
Or skip the library entirely
The most convincing resource is a receipt measured on your own repos. One install, one week of normal traffic, one signed number.