Same spine. Three ways in.
Surfil installs the same way for everyone - what differs is where you start. Choose by team size, by the problem you're solving, or by your role, and get the order of operations plus the first receipt to expect.
Solo, team, or platform org
Each is a sequence, not a bundle: what to turn on first, second, third - and the signed artifact that tells you it's working.
Solo developer
Starter to ProConsolidate the agents you already run, see the recoverable spend, and carry your memory forward - starting on Starter, upgrading only once the measured savings prove it.
See this path →Small product team
Team at $20 per seatGive every developer the same guardrails and one pooled view of cost and safety - without a migration, a central gateway, or a proxy in anyone's path.
See this path →Enterprise
EnterpriseTurn an agent free-for-all into a governed rollout: a live device registry, policy you simulate before you enforce, and an evidence trail your audits stop asking twice for.
See this path →Start from the thing that hurts
Four common problems and the chain of products that removes each one - ending in a signature you can verify.
Cut token spend
Surfil trims the context agents never needed, measures the cache premium you are paying, and names the writes that are never read back - then signs the measured saving.
See this path →Block risky calls
Guard evaluates every tool call on-device before execution - catching secrets and prompt injection pre-flight, and failing closed whenever a call is ambiguous.
See this path →Portable memory
Mind gives your agents local, encrypted memory with provenance on every fact - and it follows you across agents instead of living inside one tool's silo.
See this path →Prove compliance
Surfil turns agent activity into offline-verifiable evidence: signed attestations, control-mapped bundles, and a tamper-evident trail your auditors check themselves.
See this path →Start from your role
Four roles, four jobs-to-be-done - each with what you turn on first and its own call to action.
Individual developer
Surfil sits beside the agent you already use, byte-exact, so you get lower spend, a secret firewall and memory that carries over - with nothing new to learn.
See this path →Engineering lead
Give every developer the same interception point, watch cost and risk in one pooled view, and roll out guardrails on evidence instead of on a mandate.
See this path →Security engineer
Zero-trace by construction, fail-closed enforcement and offline-verifiable evidence - the posture that turns an agent ban into a governed, reviewable rollout.
See this path →Platform / DevEx
Standardize agents the way you standardize everything else: one on-device layer, byte-exact, that every product plugs into - never a second proxy to run.
See this path →Every path gets the same guarantees
Where you start changes the rollout, never the invariants.
Zero-trace
Source stays on each developer's device - solo or five hundred seats, no exceptions to it.
One layer
One interception point per machine. Scaling up never means stacking a second proxy on top.
Signed proof
The solo dev's receipt and the platform org's evidence bundle verify with the same offline command.
Flat cost curve
Devices do the heavy work, so the per-user cost doesn't bend upward as the fleet grows.
Turn on the first stage today
The install is reversible byte-for-byte, and the first signed receipt arrives after one normal week of traffic.