---
title: FAQ
description: Short answers to the questions people ask before and after installing Surface.
---

## Does the scanner read our files?

It reads configuration files to find AI tools, and reports facts about them: name, version, install path, settings, and which policies they break. It does not upload file contents. Skill and memory files are reduced to metadata before anything is sent, and a password found in a configuration file is reported as a finding, never as the password itself. See [Data handling](/surface/admin/data-handling).

## Does it record what people type into AI tools?

Only if you turn on a [prompt collector](/surface/extensions/endpoint/prompt-collectors/overview), and only for the tools you choose. Recording is off by default. Even when it is on, reading a transcript takes an extra confirmation in the console and is written to the [audit log](/surface/admin/audit-log).

## Will it slow the laptop down?

The scanner runs as a background service and scans once every 15 minutes. Between scans it waits. After the first full report it sends only changes, so network use is small.

## What does a person see when I block a tool?

A system notification titled **BLOCKED** with the tool's name. The tool is backed up and removed. If it cannot be removed, the scanner closes it each time it opens, with the same notification. For **Warn**, the notification is titled **WARNING** and the tool stays installed. See [Allow, Warn, Block](/surface/governance/decisions) and [For employees](/surface/get-started/for-employees).

## How fast does a decision reach laptops?

Within seconds for laptops that are online. Laptops that are offline apply it at their next scan, up to 15 minutes after they reconnect.

## Does it block AI websites?

No. Surface does not filter web traffic. With the Chrome collector on, it records conversations on ChatGPT, Claude, Gemini, and Perplexity. Conversation rules only tag a session; they never stop a message.

## Can employees see what was collected about their laptop?

Yes. The **My Device** item in the tray menu opens the laptop's own page from the console. People with the Member role see only their own laptop when they sign in.

## Can we keep the data in our own cloud?

Yes. Connect [Amazon S3](/surface/extensions/cloud/s3) to store session data only in your bucket, or [Splunk](/surface/extensions/cloud/splunk) to receive a copy of every session message. Inventory and audit data stay in SuperAlign.

## What happens if a laptop is lost or stolen?

Delete it on the **Endpoints** page. Its credential is cancelled at once and it can no longer report or receive decisions. Laptops that go silent on their own have their credential disabled after 60 days and deleted after 90.

## Why does a tool show a dash instead of a risk score?

No policy applies to that kind of tool yet, so no score was produced. That is different from a low score. You can still allow, warn, or block it. See [Which tools get a score](/surface/risk/scoring#which-tools-get-a-score).

## Why do two laptops show different scores for the same tool?

Because the score comes from how the tool is set up on each laptop. A connector with a plain-text password on one laptop and none on another gets two different scores. The company-wide score combines them. See [Risk rollups](/surface/risk/rollups).

## Does allowing a tool lower its risk score?

No. The score describes the tool. Allowing it records your decision and takes it out of the Open list. The two are shown separately so you always know both.

## Who receives the weekly report?

Everyone with the Owner or Admin role. To add someone, give them the Admin role. See [Weekly report](/surface/admin/weekly-report).

## Can we turn a policy off?

Not per organization. Policies are written and updated by SuperAlign, and every organization runs the same catalog. You decide what to do about the findings with Allow, Warn, or Block.
