Trust you can verify, not take on faith
Your security team doesn't have to believe a word on this page. The architecture makes the guarantees; the signatures make them checkable - offline, with no account.
Everything a reviewer checks
Each links to the surface that answers it in depth.
Security architecture
Device → edge → data plane, and exactly what each sees.
Privacy
What we collect (metadata only) and what never leaves your device.
Terms
The agreement, in plain-language sections with an anchor index.
Legal index
Cookies, sub-topics, and the full legal map in one place.
Live status
Component health against api.surfil.com, no dashboard varnish.
Weave format
How signed facts are structured, provenance-carried, and portable.
The documents procurement asks for
Subprocessors, the DPA, data protection and responsible disclosure - stated plainly, kept current.
Subprocessors
The third parties Surfil relies on to operate, and precisely what each one holds. None of them receives your source code - by construction, it never leaves the device.
Read it →Data Processing Addendum
How Surfil processes data on your behalf, in plain-language sections. The zero-trace architecture keeps the processed data narrow: metadata and ciphertext, never your source.
Read it →Data protection
What Surfil holds, how it is protected, and your rights over it. The short version: source never leaves your device, so most sensitive data is never in scope in the first place.
Read it →SOC 2 evidence
The control map an auditor works through, and where Surfil stands on each today. Several criteria are satisfied by architecture, not process - those are true now. The badge itself appears only when the audit completes.
Read it →Responsible disclosure
Surfil's security depends on people who report issues rather than exploit them. Here is how to reach us, what is in scope, and the good-faith safe harbour you can rely on.
Read it →Four guarantees, all checkable
Zero-trace by construction
Source never leaves the device. Telemetry is metadata; memory syncs as ciphertext. Architectural, not a setting.
Signed outputs
Every paid output is Ed25519-signed and verifiable offline against a public key - no trust-us dashboard.
One interception layer
A single point, by rule. We never chain a second proxy - the smaller the surface, the fewer the places to fail.
Honest posture
Never “certified” before an audit is real. Savings measured in tokens at the conservative floor, always signed.
Stated when true - never before
No badge before the audit
Surfil is never labelled “certified” until a certification is real. SOC 2 and related evidence appear in the Trust Center the moment the audit completes - a stated posture you can verify beats a badge nobody can.
See the Trust Center →Bring your security team
Read the architecture, then bring the questions. Subprocessors, the DPA, data protection and responsible disclosure are all documented above.