Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
← all surfaces
01 VAULTS02 RAG03 SHIELD04 HONEYPOT05 AUDIT06 AGENT
01CANARYVAULTS

Decoy identities

Monitored decoy identities, minted for every email address you protect and seeded where stolen credentials get traded. Nobody else has them, so the first contact is proof — and it names the address the leak came from.

Protect your first addressRead the docs
decoy identity · monitored● live
protected · anna.k@meridianlaw.com
anna.kessler.4f2a91.a91c@canaryvaults.com ← its decoy
held by nobody · handed to nobody · nothing has a reason to write

✓ watching for contact · 0 hits · sealed

THE PROBLEM

Stolen credentials stay silent. Decoys make them talk.

When one of your addresses is harvested, nothing happens at first. It gets traded, pasted into a dump, and sits in a list until somebody decides to use it. You find out at that point — months later, from a phishing attempt or a password reset you did not ask for — with no idea when it leaked.

A decoy identity turns each address you protect into its own alarm. It carries a person's name and a live monitored inbox, but it belongs to nobody, it was handed to nobody, and it exists nowhere else on earth. That is the strength, not the disguise: a real contact has a dozen innocent reasons to email you, and a decoy has none. Any contact at all is proof that the address it was minted for has been harvested — with full headers, sender infrastructure, and a sealed timestamp.

HOW IT WORKS

Three steps to a monitored address.

01

Protect an email address

Add a protected email and CanaryVaults mints three decoy identities for it, one per tier, each with a monitored inbox behind it.

02

They get seeded for you

CanaryVaults publishes them to the paste sites where stolen credentials are traded, on a delay after minting. You do not place anything yourself.

03

Get the alert with evidence

Any message to the decoy fires instantly: sender, IP, ASN, full headers, and message body — hash-sealed into the evidence log.

WHAT YOU GET

Everything reports into the same console.

✓Unique monitored inbox per decoy✓Per-address leak attribution✓Full message + header capture✓Sender infrastructure fingerprint✓Hash-sealed evidence records✓Email + Telegram alerts
list_decoys.httpintegration
GET https://api.canaryvaults.com/api/canaries
Authorization: Bearer <the web app's own Supabase session JWT>

# → {
#     "canaries": [
#       {
#         "id": "8f1c…",
#         "canary_id": "mfx8k2p-a91ceb04",
#         "tier": 1,
#         "type": "SOCIAL_MEDIA",
#         "email": "james.miller.4f2a91.a91c@canaryvaults.com",
#         "status": "ACTIVE",
#         "created_at": "2026-08-21T09:14:02Z"
#       }
#     ],
#     "count": 1
#   }

Listing your decoys authenticates with a Supabase session JWT, not an API key — and that token belongs to the web app, kept in memory behind an HttpOnly cookie, so the block above is the shape the console receives rather than a call you can paste. A workspace key from Settings → API keys opens the other five surfaces; it does not open this route. There is no endpoint that creates a decoy either — decoys are minted with the protected email.

Do decoys look real?

Each decoy is a real monitored inbox with a person's name on it, so it reads like an ordinary entry in a credential dump. No real person owns it and it was never handed to anyone, so nothing legitimate has a reason to contact it. One message is enough.

What about accidental contact?

If a colleague emails a decoy by mistake, you'll see it immediately in the capture — internal senders are easy to distinguish from an unknown proxy exit node. Mark it a false positive; the sealed record stays intact either way.

FIELD NOTES

Reading that goes with this surface.

PLATFORM · 6 MIN READ

Why AI security alerts need evidence attached from the start

A useful security alert does more than say that something suspicious happened. It explains what fired, which surface was involved, and what proof is available before the incident review even begins.

PLATFORM · 6 MIN READ

One platform, six product surfaces, fewer blind spots

Why CanaryVaults keeps modules distinct while still sharing auth, routing, and alerting across the full platform.

← PREVIOUS SURFACE

06 · Agent runtime protection

NEXT SURFACE →

02 · Trap facts

Protect your first address today.

Free tier, no credit card. Five minutes to your first alert.

Protect your first address
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS