Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free

Blog — AI security insights

Featured

What a paste-site canary sees: the anatomy of a credential-stuffing hit

A walkthrough of the seeding pipeline end to end: how a decoy credential ends up on a paste site, what happens in the moments after someone tries to use it, and what lands in your alert channel.

July 20266 min readPlatform
Recent Notes

Product thinking and operating lessons

Short writing on AI security decisions, release changes, and what the team is learning while building the platform.

Postmortem

Every page on our site was shipping an empty body

One call to useSearchParams() sat inside the root layout's only Suspense boundary, and deopted the entire application to client-side rendering. Twelve words of markup left our server. Nothing in the build said so.

Platform4 min read
Engineering

It worked, it said so, and nothing happened

A contact form returned 201 and showed a green confirmation every time. Nobody was ever notified. We went looking for more of these and found about thirty, all with the same shape.

Platform4 min read
Postmortem

We were selling a proof that had never run

Several pages described CanaryAudit records as anchored on-chain. Not one record ever had been, and the code that would have done it was not in the deployed image. Here is what happened, and what we decided instead.

CanaryAudit5 min read
Operations

Your alert email probably has one leg holding it up

We read our own DMARC report properly and found every message passing on a single mechanism. If that one DNS record ever breaks, every alert we send lands silently in spam.

Platform4 min read
Operations

We audited our own documentation against the source

Five parallel passes read every page under /docs and checked each concrete claim against the code that implements it. A third of the load-bearing ones were wrong, and every error ran in the same direction.

Platform6 min read
Postmortem

Our security address had no mailbox

We published a security contact in a dozen places and nothing was behind any of them. Nothing was broken, either — every individual step had been done correctly, into a void.

Platform4 min read
Launch notes

Introducing enterprise inquiries — the honest version

The pricing page now has an Enterprise column. Here is exactly what it buys, what it doesn't, and what happens when you email us — written plainly, because the audience for this plan can smell filler.

Release4 min read
Alert design

Why AI security alerts need evidence attached from the start

A useful security alert does more than say that something suspicious happened. It explains what fired, which surface was involved, and what proof is available before the incident review even begins.

Platform6 min read
Product thinking

Why prompt injection needs its own firewall

Prompt safety breaks when it is treated like generic moderation. Inspection has to sit before execution, not after.

CanaryShield4 min read
Leak detection

Proof beats suspicion when private documents leak through AI

CanaryRAG is designed around planted facts and reproducible signals so operators can distinguish real leakage from vague answer drift.

CanaryRAG5 min read
Agent accountability

Audit trails matter when AI agents can take action

If an agent writes files, calls APIs, or changes customer state, you need a record that survives dispute resolution and compliance review.

CanaryAudit7 min read
Detection design

A believable decoy teaches you more than a blocked request

Honeypots are useful because they observe attacker behavior directly. The quality of the trap determines the quality of the signal.

CanaryHoneypot4 min read
Operations

One platform, six product surfaces, fewer blind spots

Why CanaryVaults keeps modules distinct while still sharing auth, routing, and alerting across the full platform.

Platform6 min read
Launch notes

What changed in the new trust and support surface

The public site now mirrors product boundaries more clearly so users can route privacy, billing, support, and security questions without guessing.

Release3 min read
Topics

What the team is writing about

Each topic maps directly to a product surface or operating area inside CanaryVaults.

Prompt injection and firewall design
RAG leakage detection and planted facts
AI honeypots and decoy operations
Immutable audit records for agents
Trust, billing, and support UX

Use the writing as a map into the product

If a post topic matches your problem, the product pages and trust center are the fastest way to continue evaluation.

Start Free →View ProductsView Pricing
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS