Surfil
// By persona

Agents your security team can actually sign off on

Zero-trace by construction, fail-closed enforcement and offline-verifiable evidence - the posture that turns an agent ban into a governed, reviewable rollout.

surfil · radar - sess_4459 rewind
00:00session start
01:47context drift detected
01:47rewound to checkpoint
04:12signed & closed
Caught before minute 2signed
The job: When agents run in my environment, I want them constrained and provable, so I can approve them instead of blocking them outright.
How it works

What you turn on

Developers want agents; you own the blast radius. You need to know what they can do, prove what they did, and revoke fast the moment it matters.

1

Constrain pre-flight

Guard screens every tool call on-device, fail-closed, with secrets and injection caught before they leave.

2

Prove after the fact

Proof signs agent actions into a tamper-evident chain your reviewers verify against a public key.

3

Govern the fleet

Fleet Control surfaces shadow agents and revokes a device's access instantly, enforced at the edge.

First signed receipt: A signed action-attestation chain plus a shadow-agent inventory, verifiable offline.
What holds

Why you can approve it

Zero-trace by design

Source never leaves the device; telemetry is metadata and memory syncs as ciphertext - architectural, not a setting.

Fail-closed on doubt

Ambiguous calls are blocked by default and routed to approval; the signed-output root has no client-side bypass.

Bring your reviewers

The full threat model, key-epoch design and RBAC live on the security page for your team to pull apart.

By persona

More in this view

Same spine, a neighbouring starting point.

Not the right lens? The same eleven paths are also organized by team size, by problem, and by persona on the solutions overview - pick whichever matches how you think.

Turn on the first stage today

The install is reversible byte-for-byte, and the first signed receipt arrives after one normal week of traffic.