Tripwire
Security

Security

Last updated June 3, 2026

Security is the product, so we hold ourselves to the standard we sell. This page describes how Tripwire is built, how we protect your data, and how to report a vulnerability. We aim to be specific and honest, including about what we are still building.

How Tripwire is built

Tripwire plants harmless decoy credentials where attackers look, then alerts you the moment one is used. Because you are placing our bait in your environment, the property that matters most is that the bait is inert.

  • The decoys are harmless. A planted Tripwire credential is bait, not a real key. The accounts behind our decoys are isolated and scoped so that using one reveals the intruder without exposing anything of value.
  • We don’t hold your secrets. Tripwire does not sit in your data path and does not store your production credentials. Its job is to detect and alert. Compromising a decoy leaves an attacker no better off.
  • Isolation limits blast radius. The infrastructure that backs the decoys is isolated from our control plane and from other customers. A tripwire firing for one customer cannot reach another customer’s data or decoys.
  • You stay in control. You can deactivate or delete your tripwires and your data at any time. Tripwire being unavailable does not expose you.

Data protection

In transit. All traffic to Tripwire is encrypted with TLS 1.2 or higher. The site is served behind a reverse proxy, and connections to our database require TLS.

At rest. Sensitive data such as provider credentials and decoy material is encrypted at the field level using envelope encryption with managed keys (AES-256). Access to those keys is tightly restricted.

Secrets. Application and provider secrets are held in a managed secrets store, never in source code.

Infrastructure

Tripwire runs on cloud infrastructure in the United States. Our database is private and is not reachable from the public internet, and our storage blocks public access. The origin sits behind a proxy, so it is not directly addressable.

Access and monitoring

Access to production systems and customer data is limited to the people who need it, on a least-privilege basis. We keep audit logs of administrative and security-relevant activity, alert automatically on sensitive changes, and monitor for anomalous behavior.

Tenant isolation

Each customer’s data is scoped to their account. Queries for tripwire activity are isolated by owner, so one customer cannot see another’s events, and the decoy infrastructure is isolated from our control plane.

Data handling and retention

We collect the minimum we need and keep it only as long as necessary. Bundle links expire after seven days, and the contents of notification emails are discarded once sent. You can request deletion of your data at any time. Our Privacy Policy has the full detail.

Reporting a vulnerability

We welcome reports from security researchers. If you believe you have found a vulnerability in Tripwire, email [email protected] with the details and steps to reproduce.

Safe harbor. If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. Please avoid privacy violations, data destruction, and service disruption, and stop and report immediately if you reach data that is not yours.

We don’t run a paid bug-bounty program today, but we are grateful for reports and will credit researchers who would like recognition. Machine-readable contact details are published at /.well-known/security.txt.

Contact

For security questions, vulnerability reports, or a copy of our data-processing terms, email [email protected].