Documentation.
Full docs are coming with the public launch. In the meantime, here's the shape of the product.
How canaries, severity, and alerts fit together. Why deterministic signals are different from probabilistic detection.
Every place Tripwire watches — cloud APIs, source control, SaaS, AI providers, databases, DNS, documents — and what fires on each.
The surfaces most teams cover on day one, with the specific files, secrets, and pages where canaries belong.
The alert schema and the channels we route to: Slack, PagerDuty, webhooks, email, and any SIEM that speaks JSON.
Issue canaries, browse events, configure routing, manage team members — from the web console or the command line.
How Tripwire keeps its own posture honest. Isolated decoy infrastructure, self-test heartbeats, SOC2.