Agents your security team can actually sign off on
Zero-trace by construction, fail-closed enforcement and offline-verifiable evidence - the posture that turns an agent ban into a governed, reviewable rollout.
What you turn on
Developers want agents; you own the blast radius. You need to know what they can do, prove what they did, and revoke fast the moment it matters.
Constrain pre-flight
Guard screens every tool call on-device, fail-closed, with secrets and injection caught before they leave.
Prove after the fact
Proof signs agent actions into a tamper-evident chain your reviewers verify against a public key.
Govern the fleet
Fleet Control surfaces shadow agents and revokes a device's access instantly, enforced at the edge.
Why you can approve it
Zero-trace by design
Source never leaves the device; telemetry is metadata and memory syncs as ciphertext - architectural, not a setting.
Fail-closed on doubt
Ambiguous calls are blocked by default and routed to approval; the signed-output root has no client-side bypass.
Bring your reviewers
The full threat model, key-epoch design and RBAC live on the security page for your team to pull apart.
More in this view
Same spine, a neighbouring starting point.
Individual developer
Surfil sits beside the agent you already use, byte-exact, so you get lower spend, a secret firewall and memory that carries over - with nothing new to learn.
See this path →Engineering lead
Give every developer the same interception point, watch cost and risk in one pooled view, and roll out guardrails on evidence instead of on a mandate.
See this path →Platform / DevEx
Standardize agents the way you standardize everything else: one on-device layer, byte-exact, that every product plugs into - never a second proxy to run.
See this path →Turn on the first stage today
The install is reversible byte-for-byte, and the first signed receipt arrives after one normal week of traffic.