Everything here exists. Read it now.
No phantom whitepapers and no “webinar coming soon”. Everything indexed here exists. One item, the August field report, asks for an email before its full detail, and its findings and every caveat on them are readable without one.
Seven reads, one of them asks for an address
Six of these link straight to the material. The seventh is the field report: its headline finding, its method and every caveat are public, and the full run detail opens once you confirm an address.
Field report: what 533 intercepted requests measured
One machine, two sessions, August 2026. Only 21 requests reported what they cost. Findings and caveats public; full run detail by email.
Read it now →ArchitectureZero-trace architecture, in depth
How interception stays on-device and why telemetry is metadata only.
Read it now →ArchitectureHow the pipeline works, end to end
Install → one interception point → five stages → one signed spine.
Read it now →SpecThe Weave format
Signed Markdown: frontmatter, provenance, code hash, automatic STALE flagging.
Read it now →MethodologyBenchmarking agents honestly
Dated runs, false-positive/negative rates, no fixed injection numbers.
Read it now →MethodologyThe case against cost dashboards
Why every paid claim ships as a signature you can verify offline.
Read it now →DocsDocs & CLI reference
Install, consolidate, audit, verify, export - the full command surface.
Read it now →What each label means
Four kinds of material, held to different standards.
Architecture
How the system is built and why. Verifiable against the product's behavior, not marketing diagrams.
Methodology
How we measure before we claim - benchmarks, savings floors, false-positive rates. Dated and reproducible.
Spec
Formats you can build against: signed Markdown, frontmatter, provenance, code hashes.
Docs
The operational surface - install, consolidate, audit, verify, export. Kept current with what's shipped.
Three ways in, depending on your question
Most visitors arrive with one of these three jobs. Each has a shortest path.
Evaluating the security story
Start with the zero-trace architecture, then the Weave format - that pair answers most security-review questions.
Start the security readJustifying the cost
Read how savings are measured and signed, then estimate your own floor from the pricing page's seat estimator.
Estimate your floorGetting hands-on
Skip the reading: install Surfil, run a week of traffic, and let the receipt be the resource.
Install and measureWhat we'll add - when it's real
Two things belong in this library and aren't in it yet. They'll appear when they exist, not before.
Fleet rollout playbook
A simulate-before-enforce rollout template for 50+ developer orgs - published once it's been exercised by a real rollout, so it's a record rather than a guess.
Standalone offline verifier
A single binary that verifies any receipt with no Surfil install at all. On the roadmap, planned column - which tells you exactly how committed and how scheduled it is.
Or skip the library entirely
The most convincing resource is a receipt measured on your own repos. One install, one week of normal traffic, one signed number.