What You Can Detect

Understanding the data captured by DLP policies and canary tokens

Signal Canary captures different data depending on whether you're using AI DLP policies or canary tokens. Here's everything you can detect and track.

AI DLP Detections

When your DLP policies detect sensitive data in AI prompts, Signal Canary records:

Data Point Description Example
Timestamp When the detection occurred Dec 20, 2024 at 2:34 PM UTC
Pattern Matched Which DLP pattern triggered credit_card, ssn, api_key
Action Taken What happened to the request Blocked, Redacted, Logged
Content Preview Redacted snippet of the match SSN: ***-**-6789
Source Where the request originated API, Browser Extension, Proxy
Application Target AI system ChatGPT, Claude, Custom API
DLP logs help you understand what sensitive data your team is trying to send to AI systems, allowing you to address training gaps and policy violations.

Canary Token Data

Each time a tracked document is opened, Signal Canary captures:

Data Point Description Example
Timestamp Exact date and time of access Dec 20, 2024 at 2:34 PM UTC
IP Address Network address of the viewer 203.45.67.89
City Approximate city location San Francisco
Region State, province, or region California
Country Country of origin United States
Device Type Desktop, mobile, or tablet Desktop
Operating System OS name and version Windows 11
Browser/App Application used to open document Microsoft Word 16.0
Repeat Opens Number of times opened 3 opens from same IP

Organization Detection

Signal Canary attempts to identify the organization behind each access:

  • Company Name - Identified from IP registration data
  • ASN (Network Owner) - The organization that owns the IP range
  • Network Type - Corporate, ISP, cloud provider, VPN, etc.
Organization detection works best for corporate IPs. Residential ISP users and VPN users will show the ISP or VPN provider instead of their employer.

Network Type Classifications

Type What It Means
Corporate Direct company network - high confidence identification
ISP Residential or small business internet provider
Cloud AWS, Azure, GCP - may be automated or proxied
VPN VPN service - true location hidden
TOR Anonymizing network - origin intentionally hidden

Understanding Your Data

DLP Detection Patterns

Review your DLP logs to identify:

  • Which departments are leaking the most data
  • What types of sensitive data are most commonly exposed
  • Which AI tools your team uses most frequently
  • Peak times when data leak attempts occur

Canary Token Access Patterns

What indicates legitimate human access:

  • Corporate IP address from expected organization
  • Desktop device with standard office software
  • Access during business hours
  • Single access or reasonable number of opens

What may indicate suspicious activity:

  • Access from unexpected geographic locations
  • Cloud provider IP (AWS, Azure) suggesting automation
  • Multiple rapid-fire accesses
  • Access from known threat actor infrastructure
Signal Canary helps identify patterns and potential threats, but cannot definitively prove identity or intent. Always consider the full context when interpreting data.

Ready to Try Signal Canary?

Create your first tracking pixel in under 5 minutes. No credit card required.

Get Started Free