Surfil
// services

We get you to signed proof. Then we leave.

Surfil services are deliberately finite: every engagement ends with your team self-sufficient and your uninstall path intact. No embedded consultants, no dependency by design.

surfil · your control plane
▤ Saved / mo
$412
⛨ Blocked
27
≋ Memory
94%
Savings trendsigned
Trend, last 12 points
rcpt_8f2aepoch 7 · offlineVALID
!AWS key in payloadacme/apiblocked
Engagements

Four ways we help, each with an exit

Every engagement is a fixed sequence with a defined end state - not an open-ended retainer.

Onboarding & migration

Any paid plan

Guided install across your agents, MCP consolidation, and a Guard simulation period before any enforce goes live.

1.Inventory agents & MCP servers
2.Install + consolidate, byte-exact backups taken
3.Simulate Guard on real traffic, review would-blocks together
4.Enforce only what the simulation earned

Fleet rollout

Team & Enterprise

Staged rollout for larger orgs: registry first, discovery second, policy last - so enforcement never arrives before evidence.

1.Device registry + shadow-agent discovery
2.Cohort-by-cohort install with local buffering verified
3.Policy simulation against real org traffic
4.Staged enforcement with blast-radius review at each step

Compliance evidence setup

Enterprise

Map your control framework into Charter and produce offline-verifiable evidence bundles your auditors run themselves.

1.Control-mapping workshop with your compliance owner
2.Evidence bundle format agreed with your audit team
3.First export produced and verified offline by your side
4.Cadence scheduled - evidence accumulates unattended

Weave curation

Team & Enterprise

Stand up your canonical knowledge network: authority rules, expiry, and review workflow so agents read trusted, fresh facts.

1.Seed facts from consolidation output
2.Authority & provenance rules agreed
3.Stale-flag review workflow wired into your process
4.Handoff: your team owns the network, exportable anytime
How engagements run

Simulate first. Always.

One principle governs every service engagement, because it governs the product.

Nothing enforces on day one

Guard and Policy run in monitor and simulate until the would-block report has been reviewed by your team - not ours.

Evidence before action

Every step of a rollout produces a signed artifact before the next step is taken. If the evidence isn't there, the rollout pauses.

Rollback stays byte-exact

The clean-uninstall guarantee holds throughout: at any point in any engagement, backing out restores every config exactly.

Ongoing support

Four tiers, stated plainly

Response targets as we actually operate them - the honest version of a support matrix.

TierPriceWhat you getAvailable onResponse
CommunityincludedDocs, help center, community channels.Any planbest-effort
StandardincludedEmail support with a one-business-day reply target.Pro & Team1 business day
Priorityadd-onShared channel, four-hour response target, named contact.Team4-hour target
EnterprisecustomSLA, dedicated engineer, quarterly security review.Enterpriseper SLA
The boundary

Services we deliberately don't offer

A services page should also say no. Ours says it three times.

No embedded consultants

We won't staff your team long-term. If an engagement needs to run forever, we designed it wrong - and we'd rather fix that.

No custom forks

One product, one spine, for everyone. Custom builds would fragment the security surface every other customer relies on.

No certification theater

We'll set up evidence your auditors verify themselves. We will not sell you a “Surfil Certified” stamp - it would mean nothing.

Most teams don't need services at all - the docs plus the help center cover the standard install end to end.

Tell us your agents and your team size

We'll map a simulate-first plan with a defined end state - and tell you honestly if you don't need us for it.