Surfil On-device control plane for AI coding agents

Samaradam3 pts0 comments

Surfil - the control plane for your AI coding agents<br>⌕ Search & commands ⌘K◈HomeMarketing<br>▦ProductsMarketing<br>◇SolutionsMarketing<br>$PricingMarketing<br>⛨SecurityMarketing<br>≋WeaveMarketing<br>?DocsHelp<br>✎BlogMarketing<br>@ContactMarketing<br>→Sign inAccount

↑↓ navigate↵ openesc close

// on-device control plane for AI coding agents<br>One install. Cheaper, safer, and remembered.<br>Surfil runs beside Claude Code, Cursor, Codex & Copilot. The tools that route through it get cheaper and safer; editors like Cursor connect through MCP - every claim proven with a signature, and your source never leaves the machine.<br>Install SurfilSee pricing →How it works →

surfil · your control plane<br>▤ Saved / mo<br>$412

⛨ Blocked<br>27

≋ Memory<br>94%

Savings trendsigned<br>Trend, last 12 points

✓rcpt_8f2aepoch 7 · offlineVALID<br>!AWS key in payloadacme/apiblocked

Works with<br>Claude CodeCursorCodexCopilotMCP agents

byte-exact<br>never busts your prompt cache

lines of source leave device

100%<br>offline-verifiable receipts

interception point

Proof you can verify yourself<br>Don't trust our numbers. Check the signature.<br>Every Surfil claim ships as an Ed25519-signed receipt. Verification runs offline, with no account - on your machine, against a public key. This is what it looks like:<br>~/acme/api - surfil<br>$ surfil consolidate<br># scanning 6 MCP servers across Claude Code + Cursor…<br>✓ consolidated 6 → 1 endpoint saved ~48k tokens/op<br>$ surfil audit<br>✓ recoverable spend this week: $96.40 (signed: rcpt_8f2a)<br>$ surfil verify rcpt_8f2a<br>✓ VALID (offline · epoch 7 · no account)

ⓘ The numbers above are illustrative. Yours are measured on your own repos. We publish no fixed savings percentage, because the honest answer depends on your traffic: what Surfil guarantees is that every figure is measured and signed , and that interception is byte-exact , so the provider prompt cache that already removes most of your input cost keeps hitting.

The problem<br>Agents are expensive, risky, and forgetful<br>Not because they're bad - because nothing sits beside them watching cost, safety and memory across all of them at once.<br>Expensive<br>Agents re-send the same context and re-read the same files. Token spend creeps up and nobody can point to why - or prove what's recoverable.

Risky<br>Agents run shell commands, hit the network, and paste payloads. One leaked key or injected tool-call is discovered after it already happened.

Forgetful<br>Every session starts from zero. Agents re-derive your architecture, re-ask settled questions, and forget the decisions you already made.

What Surfil does<br>Cheaper, safer, remembered - on one spine<br>Three products carry the consumer story. All of them are stages on the same pipeline, writing to the same signed knowledge network.<br>Cheaper<br>Cap measures where your input cost actually sits: the 1.25x premium on every cached write, and how often it is read back. Every figure is the provider’s own count, measured before and after.<br>Details →Safer<br>Guard blocks secrets and OWASP-scored injection pre-flight, on-device. Simulate before you enforce; nothing runs unchecked.<br>Details →Remembered<br>Mind gives you memory that follows you across agents - facts carry provenance, stale is auto-flagged, and everything is portable.<br>Details →

How it works<br>Install. Intercept once. Verify the receipt.<br>Three steps between your current agent bill and a signed number you can hand to anyone.<br>1 · Install<br>One install beside Claude Code, Cursor, Codex and Copilot. Core consolidates your scattered agent configs and bootstraps Weave.

2 · Intercept once<br>A single on-device interception point, byte-exact passthrough. Every product is a stage on the same pipeline; no second proxy, ever.

3 · Verify the receipt<br>Savings and outputs are measured, then Ed25519-signed. Run surfil verify on any receipt - offline, no account. The signature is the proof.

The catalog<br>Eleven products, one interception point<br>Each product produces exactly one metric type on the shared spine - so every number has a source and a signature.<br>Core<br>Consumer<br>The install that bootstraps everything else.<br>Cap<br>Consumer<br>Cut token spend with measured, signed savings.<br>Guard<br>Consumer<br>Sandbox and block risky tool calls before they run.<br>Mind<br>Consumer<br>Local, encrypted memory your agents can reuse.<br>Radar<br>Consumer<br>Observability and rewind - metadata only.<br>Bench<br>Consumer<br>Leaderboard and a signed savings receipt.

See all 11 products →

Why you can trust it<br>Four rules we can't break<br>These aren't policies - they're architecture. Breaking any of them would require rebuilding the product.<br>Zero-trace<br>Source never leaves the device. Telemetry is metadata only; memory syncs as ciphertext.

Signed outputs<br>Every paid output is Ed25519-signed and verifiable offline - no trust-us dashboards.

Honest claims<br>Measured facts, never “certified”. Savings reported in tokens, at the conservative floor.

One layer<br>A single interception point, by rule. We never chain a second proxy to sell you more.

Read the security architecture →

Pricing<br>Execution is unmetered. Signed output...

surfil signed agents consumer device install

Related Articles