My information is a couple of years out of date (I left in August 2013), but that would be hard(ish) for SurfEasy to do, and doing so would affect the entire system (all users), because we didn’t user-level pen-tapping capabilities into the system.
The proxy/VPN machines were designed to be disposable (to potentially cycle IP addresses for various reasons) and to record a minimum of information. It would have required non-trivial effort to make it so that we could do a pen-tap on just one individual given that they could end up on a different server each time. Additionally, I believe that the proxy/VPN machines had no information on the user's identity, just the device's identity (devices were given unique, derived identities when they were created; we could work that information backwards to some degree of accuracy with enough effort, precisely for LE purposes).
I don’t always use a proxy or VPN, but when I do, I trust what my former employer wrote precisely because I know what we didn’t do then, and didn’t believe would be right for us to do. Nothing I have heard from the SurfEasy team since suggests that this has changed.