You are handing someone the keys to your operation.
So here is exactly what happens next: the standard Surge holds itself to in writing, the gate every automated system passes before it is allowed near a customer, and an honest list of the things this firm cannot claim today.
Five rules, and none of them bend for a deadline.
- A person releases anything that leaves the building
- No system sends an email, posts a reply, deploys code, or moves money on its own authority. Software drafts and proposes; a human ships. This is enforced in how the systems are built, not just written down somewhere.
- Credentials live in a password manager, nowhere else
- Never in a document, a repo, a chat window, an AI prompt, or a text message. You hold your own accounts and grant the narrowest access that does the job, read-only wherever read-only is enough.
- Summarize before the model sees it
- Raw customer records, financials, and personal information do not get handed to a language model. Counts, rates, totals, and drafts do. Where raw data genuinely has to move, it moves to vendors configured to retain nothing and train on nothing.
- Least privilege, and revoked the same day
- Access is scoped to the task and removed the day it stops being needed, on both sides of the relationship.
- A suspected exposure is a breach until proven otherwise
- Not a maybe, not a wait and see. It gets treated as real, investigated, and told to you, before anyone knows how bad it is.
The gate every automated system passes first.
- Your data cannot reach anyone else's
- Isolation is enforced at the query layer rather than by filtering results afterward, and it is tested in both directions before launch.
- Ten tests, and one failure fails the suite
- Zero fabrications, zero leaks between clients, zero refusals of questions it should have answered. A single invented fact fails the whole suite regardless of the other ninety-nine passes.
- A kill switch and a log
- You can stop it yourself, and everything it did is recorded and readable after the fact.
- Tested against the known attacks
- Prompt injection, unsafe output handling, agents given more authority than the task needs, and leaking information it holds but should not share. Reviewed against the standard industry list, plus an adversarial pass where the goal is to make it misbehave.
- Never confidently wrong
- The standard is not usually right. A client who catches one invented number stops believing the other nine, including the nine that were correct. So a system that does not know is built to say it does not know.
What never runs without a person.
- Moving money, or anything that touches a payment
- Signing anything, or agreeing to terms on your behalf
- Granting, changing, or revoking anyone's access
- Publishing a response to a negative review
- Pricing shown to a customer, without a person checking it
- The monthly report you make decisions from
- Any statement of fact your own records do not contain
This list is not a limitation we are working to remove. Judgment work stays yours by design: which customers to chase, who to hire, what the company should become, and the relationships that are yours to hold. The goal was never a business that runs without you. It is a business that only asks for you when the thing genuinely deserves you.
Nothing starts trusted. It moves up as it proves accurate, and it moves back down the same way the moment it gets one wrong. In practice you hear about it like this:
- New
- A person reads every message before it sends.
- Standard
- Running with spot-checks. You see everything it did in the weekly report.
- Trusted
- Running on its own. Anything unusual reaches a person the same hour.
- Under review
- We caught one we did not like, so it is back to full review for two weeks.
Built so you can leave.
- You own the accounts
- Every integration, every login, every system is in your name and paid by you. I work inside them; I do not hold them.
- You own the data and the work
- Your data is yours, exportable at any time. The systems built for you are yours to keep and to run.
- Leaving is designed before you need it
- Written documentation and an offboarding package exist from day one, so another qualified person could take this over. Built so you can leave, which is the only version of this that is honest when one person builds it.
- A data agreement before any personal data moves
- Signed first, covering what is processed, where it goes, and who is responsible for what. The list of vendors involved is shared on request.
The gaps, stated plainly, so you do not have to discover them in procurement.
- Surge is not SOC 2 certified. Several vendors underneath it are, which is not the same thing and is not presented as if it were.
- The data processing agreement is drafted and ready for counsel. It has not been through a lawyer yet, and it will be before it is signed.
- No HIPAA work and no signed business associate agreement, so nothing involving patient records today.
- No multi-client agent has been deployed yet. The go-live gate above is the standard held for when one is, not a record of times it has been passed.
- Surge is one person who builds every system himself. That is why the handover and offboarding above exist, and why they are stated before you ask.
If any of these is a blocker for your organization, it is better for both of us that you know now. Say so on the first call and I will tell you honestly whether it is something Surge can close for you or whether you need a different firm.
Tell us what is not working.
Two minutes to write it down, a reply within one business day, and the option to book a call straight away. You keep whatever I find either way.