decoyrail

Decoyrail documentation

Decoyrail runs AI coding agents behind a local TLS-intercepting proxy. The agent holds decoy credentials, the proxy swaps in real secrets only for approved destinations, and a decoy seen anywhere else is treated as an exfiltration attempt: blocked and recorded.

Doc Read it when you want to
Getting started install Decoyrail and protect your first agent
How it works follow the architecture and request path
Policy reference write egress and secret-release rules
Vault & secret release manage secrets, decoys, and release destinations
Sensitive-data filtering block, mask, or warn on structured sensitive data
AWS and SigV4 how decoyed AWS credentials keep working, and the supported surface
Audit & metering inspect events, verify logs, and control spend
Analytics query spend, usage, and security events
Licensing install a license and understand tiers, expiry, and grace
Threat model understand Decoyrail's guarantees and limits
Latency SLO what added latency is measured, and how it is gated

What's coming next is in the roadmap.