Sensor
Deterministic wire-level execution. Policy, personas, and synthetic responses: score-independent, fail-closed.
- Owns attacker-visible bytes
- No model chooses egress / OS exec
Authority matrix
Who may touch what. Wire authority stays in the sensor; AI stays suggestion-only.
Deterministic wire-level execution. Policy, personas, and synthetic responses: score-independent, fail-closed.
Bounded, schema-validated AI fills over UDS. Fail-closed when the broker is unavailable.
ValidateSlotFill gateOperator-approved deception change management with a signed audit ledger.
Cited evidence assembly without mid-session risk or auto-containment.
Attacker path
Operator path
Planes stay separated. Scores never grant wire authority.
Deception fabric
Purpose-built coverage for enterprise identity, cyber-physical plants, and AI agent infrastructure.
Identity & host defense
ITDR = Identity Threat Detection and Response. Agentless host and directory-oriented tripwires that end at honeypot surfaces : without a heavyweight endpoint agent as the default path.
Built for · CISO & IT SecOps
Cyber-physical realism
ScenarioPlans with fluid, pressure, and duty-cycle drift that reads like a plant, not a static banner.
Built for · OT & Plant Engineers
Runtime agentic deception
Honey tools and poisoned context for LLM loops: telemetry isolated from production evals.
Built for · MLOps & AI Platform Eng · A.I. Decoy Engine →
Safety interlocks
Human-gated, decoy-touch scoped. No score-driven IPS. No silent cloud mutation.
Simulate exposure before permissive binds or Live/ack-gated paths. Sign-off before the blast radius grows.
Admission and sticky per-source controls keep CTI / Internet postures from runaway scanner floods.
Hard exclusions keep protected ranges, production IAM, and non-decoy assets off the auto path.
Phase A wired (defaults off) · Phase C Beta (LocalState + BYO webhook)
Deterministic decoy-touch evidence for compromised AI agents. Complements guardrails; does not replace them. Soft/Hard are Beta via LocalState and optional customer webhook, native vendor EDR/IdP SDKs remain GA-train. Canonical wording lives in the docs positioning page: this section must not exceed it.
Install in a lab:
Install Phase A
·
Install Phase C Beta
·
All agentic tutorials
(make agentic-lab-install).
observed_anomaly → verified_decoy_touch / canary_egress / credential_use. Scores never promote a grade.
Node-local shadow index for canary memory, production top-k stays clean.
Separate Enforcement Plane; session-first ladder; rung 3 never autonomous. Soft/Hard via LocalState + BYO webhook. Native vendor APIs are GA-train only.
Non-claim: third-party canary benchmarks describe those studies, not CHN performance. Internal use remains free under PSL-1.0; no online entitlement check for enforcement.
Deception that fires when a tool-calling agent or operator touches honeytools, shadow canaries, or other bait. Phase A is advisory with defaults off. Phase C Beta Soft/Hard runs on a separate Enforcement Plane via LocalState and optional BYO webhook; native vendor EDR/IdP SDKs remain GA-train only.
The sensor notify path is evaluate-only. Ops holds the execute token and connector credentials stay on the Enforcement Plane, so a compromised sensor identity cannot Soft/Hard by itself.
Run make agentic-lab-install from a repo checkout, then follow the
Install Phase A and
Install Phase C Beta tutorials.
Confirm /healthz reports maturity beta before Soft/Hard pilots.
Next step
Deploy a staging lab in about ten minutes, tutorials walk the path without touching production.