Plant decoy keys.
Get alerted when they’re used.

Each decoy sits among your real secrets, in repos, configs, and CI. Nobody legitimate ever touches one. When someone does, Tripwire emails you the available source details, attempted action, and timestamp.

npm install -g @tachyonhq/tripwire
tripwire bundle download
Install the CLI and download a ready-to-place decoy bundle. Alerts go to your email.

Whichever you pick, the result is inert decoy material. Nothing runs or gets access to your systems.

Decoys for
AWSGoogle CloudAzureGitHubTerraformAnthropicOpenAISlack
Tripwirenow
AWS canary triggered

Someone just used the AWS key you planted.

198.51.100.24 · sts:GetCallerIdentity

Silent until a decoy is touched.

The Tripwire console showing one AWS decoy trigger and 279 located events, including 109 from Ashburn.
High signal

A decoy has no production purpose. Any use deserves investigation.

Contained

Decoys authenticate only against isolated systems we control. They cannot reach yours.

Event detail

Alerts show the source details the provider exposes, plus the attempted action, canary, and timestamp.

Where it goes

Drop it where attackers look.

config/.env
Beside real config

A decoy .env next to the real one.

~/Downloads/aws.txt
On a dev laptop

In a home or downloads folder.

mcp.json
In an agent's context

Agent config, an MCP, or a prompt.

Q3-planning/creds.md
In a shared drive

Where internal docs collect.

Pricing

From first decoy to full coverage.

Start free. Talk to us when you need a coordinated rollout.

Free
$0

Create decoys, place them, and get an email when one is used.

Get started
  • Cloud canaries
  • Database canaries
  • Service canaries
  • Email alerts
  • Web console & CLI
  • Community support
Teams & Enterprise
Custom
Let's talk

Plan and roll out decoys across more environments with hands-on support.

Talk to us
Everything in Free
  • Coverage planning
  • Rollout and placement guidance
  • Direct support

FAQs

Do I have to install anything?
Only if you choose the CLI or Claude Code. They create and place the decoys you approve, then exit. There is no resident agent, daemon, or cloud role. The bundle path needs no install.
Are the decoy keys actually safe to plant?
Yes. Provider-backed decoys authenticate only against locked-down accounts we control. Other decoys point at isolated Tripwire-hosted services. None can reach your systems, and any attempted use produces an alert.
How is this different from secret scanning?
Secret scanners find credentials that should not be exposed. Tripwire gives you decoy credentials that should never be used. A trigger tells you someone or something tried one, including after a leak slips past scanning.
How quickly will I get an alert?
Cloud-provider signals usually arrive within a few minutes. Tripwire sends the alert by email with the source details the provider exposes, plus the service, action, and timestamp. Planting decoys and receiving alerts is free.
Start free

Create your first decoy.

Choose the CLI, Claude Code, or a ready-to-place bundle. No resident agent or cloud role.