How Signal Canary Works

Understand how AI DLP and canary tokens protect your sensitive data

What is Signal Canary?

Signal Canary is an AI data protection platform that helps you detect and prevent sensitive data leakage in AI systems. We specialize in proving when AI models expose your confidential information.

Signal Canary combines AI DLP (Data Loss Prevention) with AI Canary Tokens - traceable fake data that proves when your information has leaked into or out of AI systems.

In the AI era, data leaks happen in two directions:

  • Into AI systems - Employees paste sensitive data into ChatGPT, Copilot, or custom AI apps
  • Out of AI systems - RAG chatbots, AI assistants, or fine-tuned models expose your proprietary data

Signal Canary protects against both.

Two Layers of Protection

1 AI Data Loss Prevention (Input Protection)

Scan and block sensitive data before it reaches AI systems.

  • Real-time scanning of AI prompts and inputs
  • Detect PII, credentials, financial data, and custom patterns
  • Block, redact, or alert based on your policies
  • Complete audit trail for compliance

2 AI Canary Tokens (Output Detection)

Plant traceable fake data to detect when AI systems output your protected information.

  • Generate realistic fake credentials, PII, and proprietary facts
  • Plant in code repos, docs, training data, and RAG knowledge bases
  • Detect leakage even after paraphrasing, encoding, or summarization
  • Full provenance: know exactly which document leaked and through which AI app
Why output detection matters: Traditional DLP only catches data at entry. But what if your data was already scraped for AI training? What if your RAG system is leaking? AI Canary Tokens prove leakage at the point of output - when the damage actually happens.

Our Unique Value: Canary Provenance

When a canary token leaks, Signal Canary provides the complete provenance chain:

Canary → Document → Chunk → Tenant → Application

You can prove:

  • Which specific canary was leaked (e.g., "Fake AWS Key AKIA...")
  • Which source document contained it (e.g., "Internal Config v2.pdf")
  • Which RAG chunk was retrieved (for vector store debugging)
  • Which tenant's data was exposed (for multi-tenant systems)
  • Which AI application produced the leak (chatbot, copilot, API)

This provenance chain is legal-grade evidence for compliance audits, data breach investigations, and licensing disputes.

Getting Started

Choose where to start based on your immediate needs:

Detect AI Leakage

Plant canaries to prove when AI models leak your data.

Learn AI Canary Tokens
Block Sensitive Inputs

Prevent employees from pasting PII into AI tools.

Learn About AI DLP
Test Your RAG System

Run attack simulations to find data leakage in your AI apps.

RAG Testing Guide
Document Tracking

Track when documents are opened (optional add-on).

PDF Tracking

Quick Start Checklist

  1. Create an account - Sign up for free, no credit card required
  2. Create AI Canary Tokens - Generate fake credentials, SSNs, or semantic facts
  3. Plant in your data - Add canaries to code repos, docs, or training data
  4. Set up DLP policies - Block PII and credentials from reaching AI systems
  5. Test your RAG - Run attack scenarios to find vulnerabilities
  6. Configure alerts - Get notified instantly when canaries leak
Start with the RAG Testing feature - it generates test canaries automatically and walks you through detecting leakage in your AI systems.

Ready to protect your data from AI leakage? Start with the guides above.

Ready to Try Signal Canary?

Create your first tracking pixel in under 5 minutes. No credit card required.

Get Started Free