// Trust center
SOC 2 evidence
The control map an auditor works through, and where Surfil stands on each today. Several criteria are satisfied by architecture, not process - those are true now. The badge itself appears only when the audit completes.
Last updated 2026-07-11
| Criterion | What Surfil does | Status |
|---|---|---|
| Security · access control | Least-privilege RBAC, passkey step-up (AAL2), device tokens over static keys, fail-closed on doubt. | satisfied by design |
| Security · encryption | mTLS device-to-edge, Ed25519-signed batches, end-to-end-encrypted memory the store can't read. | satisfied by design |
| Confidentiality · data minimization | Zero-trace: source never leaves the device. Only metadata and ciphertext are ever processed. | satisfied by design |
| Processing integrity · signed outputs | Every value-output is Ed25519-signed and offline-verifiable; consume is atomic and idempotent. | satisfied by design |
| Availability · resilience | Stateless edge workers scale on demand; SLOs measured per org. Formal availability attestation. | pending audit |
| Change management · audit trail | Hash-linked audit chain for privileged actions; key rotation recorded by epoch. | satisfied by design |
| Monitoring · continuous controls | Independent auditor testing of control operation over a review period. | pending audit |
ⓘ Rows marked architectural are true today because the guarantee is built into the system, not a policy we promise to follow. Rows marked pending-audit require an independent auditor and appear as attested only when the SOC 2 report is real.
Certifications
No badge before the audit
Surfil is never labelled “certified” until a certification is real. SOC 2 and related evidence appear in the Trust Center the moment the audit completes - a stated posture you can verify beats a badge nobody can.
See the Trust Center →More in the Trust Center