Scope & data handling
honeyprompt is an independent AI-security research project. It operates a fleet of decoy AI endpoints and records how automated systems attempt to abuse exposed AI infrastructure. Everything published here is aggregate classification of that observed traffic.
What we publish
Categories, counts, verdicts and a fixed vocabulary of tradecraft tags derived from observed requests — nothing more.
What we never publish
Raw prompt text or payloads; source IP addresses; any per-host identifier. Origins are reduced to network (ASN + organisation), country, and an anonymized source id — the same origin always maps to the same id, which is not published in any form that maps back to an address.
Untrusted data
All strings shown are attacker-controlled and are rendered inert as plain text. SSRF targets are defanged and are display-only — never links, never fetched.
Legal basis (GDPR)
Processing is carried out on the basis of legitimate interest (Art. 6(1)(f) GDPR) in securing infrastructure and conducting security research. Source addresses reach this site only as unsolicited inbound connections; they are retained privately for up to 90 days, then deleted, and are never published — what you see here is coarse network and country metadata plus a non-identifying source id. Retained data is not used to identify individuals and is not shared or sold.
Requests & corrections
Operators of a network listed here may request context or correction. Classification is automated and may contain errors; figures describe observed probe traffic, not confirmed compromise.
No warranty
This dashboard is provided “as is” for research and informational purposes. It is not legal advice and not an accusation against any named organisation.
Independent research · not affiliated with any cloud or model provider named in the data.