Decoy assistants
Fake AI endpoints that look exactly like your production assistant — but answer with synthetic data and record everything. Attackers rehearse their attacks on them; you collect the playbook.
THE PROBLEM
Attackers rehearse. Give them the wrong stage.
Before anyone attacks your production assistant, they probe: jailbreak attempts, system-prompt fishing, extraction prompts, tool-abuse experiments. On your real endpoint that rehearsal is invisible — it looks like slightly odd traffic.
A honeypot is a decoy endpoint that answers convincingly with synthetic data. Every prompt against it is classified by intent — jailbreak, extraction, probing, normal — and recorded with its source IP, the full set of headers it sent, and a suspicion score. By the time they turn to your real assistant, you already know their toolchain, their patterns, and their goal.
HOW IT WORKS
Deploy, deceive, learn.
Deploy a decoy endpoint
Two fields — a name and the persona you want it to hold. The honeypot answers in that shape with entirely synthetic data.
Let it answer
Convincing responses keep the visitor engaged while every prompt, header, and timing pattern is recorded.
Read the playbook
Intent classification, per-hit suspicion scores, and full transcripts show you exactly what's being rehearsed against you.
WHAT YOU GET
Everything reports into the same console.
The public endpoint URL comes back in the response — place it in a leaked-looking config, a docs page, anywhere a snoop would find it. API keys are not a paid feature: mint one at Settings → API keys on any plan, Free included, or deploy the same trap from the console.
Could a real user land on the honeypot?
Only if they went looking. Honeypot endpoints are never linked from your real product — they're placed where only someone hunting for credentials or hidden endpoints would find them. Presence is itself a signal.
Can it leak anything real?
No. The honeypot has no connection to your systems or data — every response is generated from synthetic profiles. The worst an attacker gets is a convincing fiction.
FIELD NOTES
Reading that goes with this surface.
CANARYHONEYPOT · 4 MIN READ
A believable decoy teaches you more than a blocked request
Honeypots are useful because they observe attacker behavior directly. The quality of the trap determines the quality of the signal.
CANARYSHIELD · 4 MIN READ
Why prompt injection needs its own firewall
Prompt safety breaks when it is treated like generic moderation. Inspection has to sit before execution, not after.
Know the attack before it reaches production.
Free tier, no credit card. Five minutes to your first alert.
Deploy a honeypot