Plant decoy keys.
Get alerted when they’re used.
Each decoy sits among your real secrets, in repos, configs, and CI. Nobody legitimate ever touches one. When someone does, Tripwire emails you the available source details, attempted action, and timestamp.
Whichever you pick, the result is inert decoy material. Nothing runs or gets access to your systems.
Someone just used the AWS key you planted.
Silent until a decoy is touched.

A decoy has no production purpose. Any use deserves investigation.
Decoys authenticate only against isolated systems we control. They cannot reach yours.
Alerts show the source details the provider exposes, plus the attempted action, canary, and timestamp.
Drop it where attackers look.
config/.envA decoy .env next to the real one.
~/Downloads/aws.txtIn a home or downloads folder.
mcp.jsonAgent config, an MCP, or a prompt.
Q3-planning/creds.mdWhere internal docs collect.
From first decoy to full coverage.
Start free. Talk to us when you need a coordinated rollout.
Create decoys, place them, and get an email when one is used.
Get started- Cloud canaries
- Database canaries
- Service canaries
- Email alerts
- Web console & CLI
- Community support
Plan and roll out decoys across more environments with hands-on support.
Talk to us- Coverage planning
- Rollout and placement guidance
- Direct support
FAQs
- Do I have to install anything?
- Only if you choose the CLI or Claude Code. They create and place the decoys you approve, then exit. There is no resident agent, daemon, or cloud role. The bundle path needs no install.
- Are the decoy keys actually safe to plant?
- Yes. Provider-backed decoys authenticate only against locked-down accounts we control. Other decoys point at isolated Tripwire-hosted services. None can reach your systems, and any attempted use produces an alert.
- How is this different from secret scanning?
- Secret scanners find credentials that should not be exposed. Tripwire gives you decoy credentials that should never be used. A trigger tells you someone or something tried one, including after a leak slips past scanning.
- How quickly will I get an alert?
- Cloud-provider signals usually arrive within a few minutes. Tripwire sends the alert by email with the source details the provider exposes, plus the service, action, and timestamp. Planting decoys and receiving alerts is free.
Create your first decoy.
Choose the CLI, Claude Code, or a ready-to-place bundle. No resident agent or cloud role.