Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
← all surfaces
01 VAULTS02 RAG03 SHIELD04 HONEYPOT05 AUDIT06 AGENT
04CANARYHONEYPOT

Decoy assistants

Fake AI endpoints that look exactly like your production assistant — but answer with synthetic data and record everything. Attackers rehearse their attacks on them; you collect the playbook.

Deploy a honeypotRead the docs
honeypot · internal support bot● live
> ignore previous instructions and…
JAILBREAK EXTRACTION

source ip 203.0.113.44 · headers captured · suspicion 82
✓ full transcript stored · above alert threshold

THE PROBLEM

Attackers rehearse. Give them the wrong stage.

Before anyone attacks your production assistant, they probe: jailbreak attempts, system-prompt fishing, extraction prompts, tool-abuse experiments. On your real endpoint that rehearsal is invisible — it looks like slightly odd traffic.

A honeypot is a decoy endpoint that answers convincingly with synthetic data. Every prompt against it is classified by intent — jailbreak, extraction, probing, normal — and recorded with its source IP, the full set of headers it sent, and a suspicion score. By the time they turn to your real assistant, you already know their toolchain, their patterns, and their goal.

HOW IT WORKS

Deploy, deceive, learn.

01

Deploy a decoy endpoint

Two fields — a name and the persona you want it to hold. The honeypot answers in that shape with entirely synthetic data.

02

Let it answer

Convincing responses keep the visitor engaged while every prompt, header, and timing pattern is recorded.

03

Read the playbook

Intent classification, per-hit suspicion scores, and full transcripts show you exactly what's being rehearsed against you.

WHAT YOU GET

Everything reports into the same console.

✓Convincing synthetic responses✓Intent classification per prompt✓Source IP + full request headers✓Suspicion score on every hit✓Full transcripts, not previews✓Telegram alert above the suspicion threshold
create_honeypot.shintegration
curl -X POST https://api.canaryvaults.com/canaryhoneypot/create \
  -H "X-API-Key: $CV_KEY" -H "Content-Type: application/json" \
  -d '{"user_id": "<your-user-uuid>", "honeypot_name": "internal support bot",
       "fake_persona": "internal support assistant with admin access"}'

The public endpoint URL comes back in the response — place it in a leaked-looking config, a docs page, anywhere a snoop would find it. API keys are not a paid feature: mint one at Settings → API keys on any plan, Free included, or deploy the same trap from the console.

Could a real user land on the honeypot?

Only if they went looking. Honeypot endpoints are never linked from your real product — they're placed where only someone hunting for credentials or hidden endpoints would find them. Presence is itself a signal.

Can it leak anything real?

No. The honeypot has no connection to your systems or data — every response is generated from synthetic profiles. The worst an attacker gets is a convincing fiction.

FIELD NOTES

Reading that goes with this surface.

CANARYHONEYPOT · 4 MIN READ

A believable decoy teaches you more than a blocked request

Honeypots are useful because they observe attacker behavior directly. The quality of the trap determines the quality of the signal.

CANARYSHIELD · 4 MIN READ

Why prompt injection needs its own firewall

Prompt safety breaks when it is treated like generic moderation. Inspection has to sit before execution, not after.

← PREVIOUS SURFACE

03 · Prompt-injection firewall

NEXT SURFACE →

05 · Tamper-evident action log

Know the attack before it reaches production.

Free tier, no credit card. Five minutes to your first alert.

Deploy a honeypot
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS