Believable wrong doors

High-intent evidence without production reachability.

A useful honeypot looks worth touching and is safe to lose. HNPT deception packs are designed to be disposable, observable, and isolated from customer data and credentials.

Early accessStatus labels distinguish working contracts from active build and roadmap items.

What the platform is designed to deliver

Each capability carries an explicit delivery state. We do not present a roadmap item as a deployed control.

  • HTTP and API decoys

    Synthetic routes, tokens, forms, and machine-facing endpoints that legitimate clients have no reason to touch.

    In development
  • SSH and terminal sessions

    Interactive, replayable sessions with bounded command timelines and isolated fake filesystems.

    Roadmap
  • Database and cache lures

    Believable PostgreSQL, MySQL, Redis, and custom-banner surfaces with no route to production data.

    Roadmap
  • Credential and document lures

    Non-production secrets and files that emit high-intent evidence when used outside their declared boundary.

    In development
  • Custom protocol packs

    Versioned deception packs with exposure, retention, egress, artifact, and shutdown policies.

    Roadmap

Every decoy ships with boundaries.

Protocol emulation is only one part of a defensible deception system. Exposure, retention, outbound access, and teardown are policies too.

Exposure

Know who can reach it

Public, partner, tenant, and internal decoys have distinct ingress contracts.

Evidence

Bound attacker input

Preserve useful raw evidence while keeping it out of SQL, shell, HTML, and metric labels.

Egress

Make escape impossible

Playpen workloads receive synthetic data and deny production credentials and network paths.

Build with us

Start with a bounded, observable pilot.

Define what may be observed, what a quarantine can affect, how it expires, and who reviews the evidence before connecting a production system.