Plant high-value decoy credentials in your repositories, databases, and environments. When an intruder or unauthorized scraper invokes them, our edge gateway isolates the adversary, logs their forensic JA4 fingerprint, and signs a tamper-evident XDR-1 breach attestation.
c402_canary_... credential in public staging .env files, developer notebooks, or client-side bundles. Any API call using it triggers instant edge alerting.
AKIA... access key. Plant in GitHub repos or Docker images. The moment an automated credential-stuffing scanner touches it, forensic telemetry logs the attacker.
c402_canary_...
/api/canary/status/<id>