Scope & data handling
honeyprompt is an independent AI-security research project. It operates a fleet of decoy AI endpoints and records how automated systems attempt to abuse exposed AI infrastructure. Everything published here is aggregate classification of that observed traffic.
What we publish
- Categories, counts and verdicts
- A fixed vocabulary of tradecraft tags
- Network (ASN + organisation) and country
- An anonymized source id — stable, but never reversible to an address
What we never publish
- Raw prompt text or payloads
- Source IP addresses
- Any per-host identifier
- Anything that maps a published id back to an address
Legal basis
Processing rests on legitimate interest (Art. 6(1)(f) GDPR) in securing infrastructure and conducting security research. Source addresses reach this site only as unsolicited inbound connections.
How addresses are held
Privately, on access-controlled infrastructure, with encrypted backups. They are never published, never used to identify individuals, and never shared or sold.
Retention & erasure
Research records are kept for as long as the research runs. Erasure of an address may be requested at any time, via the route under Contact.
Untrusted data
Every string shown is attacker-controlled. All of it is rendered inert as plain text.
Accuracy
Classification is automated and may contain errors. Figures describe observed probe traffic, not confirmed compromise — and are not an accusation against any named organisation.
Contact
Network operators may request context or correction; data subjects may request erasure. This project is run independently and publishes no personal contact details — requests may be directed through the registrar contact in the WHOIS record for honeyprompt.app, which will forward them.
Provided “as is” for research and informational purposes · not legal advice · not affiliated with any cloud or model provider named in the data.