Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
Trust Center

Security and trust center

Last updated: March 31, 2026. Security design, incident handling, and disclosure paths across the full platform.

Multiple product surfaces, one security posture

Each module solves a different risk, but all of them aim for believable signals, clear alerts, and evidence you can act on.

CanaryVaults

Real-account early warning

This surface focuses on inboxes, recovery paths, and attacker contact against real identities. The control goal is to create believable tripwires without exposing the real account workflow.

CanaryRAG

Private-document AI leakage detection

This surface focuses on documents entering copilots, chatbots, and retrieval systems. The control goal is to catch answer leakage quickly, preserve evidence, and reduce ambiguity during investigation.

CanaryShield

Prompt injection prevention

This surface focuses on blocking instruction override, role hijacking, extraction attempts, and jailbreak patterns before they reach a live model.

CanaryHoneypot

Attacker trapping and fingerprinting

This surface focuses on public AI decoys that classify hostile probing, capture request telemetry, and escalate suspicious hits without revealing the trap.

CanaryAudit

Tamper-evident agent accountability

This surface focuses on tamper-evident audit trails for AI agents, with content hashes that make later tampering easy to detect.

Operating controls

How the platform reduces unnecessary exposure

  • Synthetic or planted signals are separated from the real user-facing protection workflow wherever practical.
  • Alerting is structured around clear trigger context so responders can tell what fired and why.
  • Authenticated workspaces, account-scoped data, and controlled routing reduce cross-account exposure.
  • Content-hash evidence is treated as an extension of, not a replacement for, operational logs.
Response model

How incidents and disclosures are handled

  • Severity-based triage and user-facing alert states are used so incidents are easier to interpret.
  • Security-sensitive reports can go directly to the security mailbox instead of general support.
  • Support, privacy, and product surfaces are linked so users can move quickly between the correct trust documents.

Assurance roadmap

This is the direction of travel for external validation, hardening, and published trust updates.

  • Independent testing and publishable trust updates as the platform matures.
  • Clearer documentation of assurance milestones for teams evaluating operational risk.
  • Ongoing hardening of the split between monitored identities, prompt defense, honeypots, and audit workflows.

Responsible disclosure

If you identify a security issue, send it to the security mailbox so the team can validate, contain, and respond through the correct path.

Email securityOpen support pathsReview privacy detailsExplore CanaryShield
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS