Surfil
// trust center

Trust you can verify, not take on faith

Your security team doesn't have to believe a word on this page. The architecture makes the guarantees; the signatures make them checkable - offline, with no account.

surfil · charter - coverage
72%mapped
Controls mapped72%
Never labelled “certified”policy
Evidence offline-verifiablesigned
What lives here

Everything a reviewer checks

Each links to the surface that answers it in depth.

Policies

The documents procurement asks for

Subprocessors, the DPA, data protection and responsible disclosure - stated plainly, kept current.

How we prove it

Four guarantees, all checkable

Zero-trace by construction

Source never leaves the device. Telemetry is metadata; memory syncs as ciphertext. Architectural, not a setting.

Signed outputs

Every paid output is Ed25519-signed and verifiable offline against a public key - no trust-us dashboard.

One interception layer

A single point, by rule. We never chain a second proxy - the smaller the surface, the fewer the places to fail.

Honest posture

Never “certified” before an audit is real. Savings measured in tokens at the conservative floor, always signed.

Certifications

Stated when true - never before

Certifications

No badge before the audit

Surfil is never labelled “certified” until a certification is real. SOC 2 and related evidence appear in the Trust Center the moment the audit completes - a stated posture you can verify beats a badge nobody can.

See the Trust Center

Bring your security team

Read the architecture, then bring the questions. Subprocessors, the DPA, data protection and responsible disclosure are all documented above.