Signal Canary captures different data depending on whether you're using AI DLP policies or canary tokens. Here's everything you can detect and track.
AI DLP Detections
When your DLP policies detect sensitive data in AI prompts, Signal Canary records:
| Data Point | Description | Example |
|---|---|---|
| Timestamp | When the detection occurred | Dec 20, 2024 at 2:34 PM UTC |
| Pattern Matched | Which DLP pattern triggered | credit_card, ssn, api_key |
| Action Taken | What happened to the request | Blocked, Redacted, Logged |
| Content Preview | Redacted snippet of the match | SSN: ***-**-6789 |
| Source | Where the request originated | API, Browser Extension, Proxy |
| Application | Target AI system | ChatGPT, Claude, Custom API |
DLP logs help you understand what sensitive data your team is trying to send to AI systems, allowing you to address training gaps and policy violations.
Canary Token Data
Each time a tracked document is opened, Signal Canary captures:
| Data Point | Description | Example |
|---|---|---|
| Timestamp | Exact date and time of access | Dec 20, 2024 at 2:34 PM UTC |
| IP Address | Network address of the viewer | 203.45.67.89 |
| City | Approximate city location | San Francisco |
| Region | State, province, or region | California |
| Country | Country of origin | United States |
| Device Type | Desktop, mobile, or tablet | Desktop |
| Operating System | OS name and version | Windows 11 |
| Browser/App | Application used to open document | Microsoft Word 16.0 |
| Repeat Opens | Number of times opened | 3 opens from same IP |
Organization Detection
Signal Canary attempts to identify the organization behind each access:
- Company Name - Identified from IP registration data
- ASN (Network Owner) - The organization that owns the IP range
- Network Type - Corporate, ISP, cloud provider, VPN, etc.
Organization detection works best for corporate IPs. Residential ISP users and VPN users will show the ISP or VPN provider instead of their employer.
Network Type Classifications
| Type | What It Means |
|---|---|
| Corporate | Direct company network - high confidence identification |
| ISP | Residential or small business internet provider |
| Cloud | AWS, Azure, GCP - may be automated or proxied |
| VPN | VPN service - true location hidden |
| TOR | Anonymizing network - origin intentionally hidden |
Understanding Your Data
DLP Detection Patterns
Review your DLP logs to identify:
- Which departments are leaking the most data
- What types of sensitive data are most commonly exposed
- Which AI tools your team uses most frequently
- Peak times when data leak attempts occur
Canary Token Access Patterns
What indicates legitimate human access:
- Corporate IP address from expected organization
- Desktop device with standard office software
- Access during business hours
- Single access or reasonable number of opens
What may indicate suspicious activity:
- Access from unexpected geographic locations
- Cloud provider IP (AWS, Azure) suggesting automation
- Multiple rapid-fire accesses
- Access from known threat actor infrastructure
Signal Canary helps identify patterns and potential threats, but cannot definitively prove identity or intent. Always consider the full context when interpreting data.