Who else is reading your messages?

Reading someone's messages leaves no trace. Blue Decoy places canaries (digital tripwires) only you know about, and tells you when somebody else finds them.

Request early access Limited availability

The gap

Everything you can check tells you about access you can already see. Device logs, active sessions, password changes, login alerts. If someone is reading your messages through a channel none of that covers, there is nothing to find, and no way to tell the difference between being watched and being anxious about it.

What it does

Blue Decoy places canaries in your own communications. You know which they are and you never touch them. Nobody else has a reason to. If one is opened, someone who is not supposed to be there found it.

What you learn

  • Where the access came from.
  • What network it used.
  • What device and browser.
  • Whether it was a person or automation.

Together those signals tell you what kind of access this was, which is what makes a detection actionable rather than alarming.

How you are told

Alerts do not go to the channel being watched. If your messages are compromised, a warning delivered to those messages tells the wrong person. We reach you somewhere else.

Interaction with a canary is never legitimate.

There is nothing to configure and no baseline to learn, no threshold to set and no judgment call to make. Automated access from link-preview services and scanners is identified and separated, so what reaches you is access by something that chose to look.

Who it is for

Journalists protecting sources. Executives and legal teams handling material others want early. Government personnel. And people leaving controlling relationships, where knowing whether your messages are being read changes what is safe to say and when it is safe to go.

Boundaries

Blue Decoy works only on accounts you hold: your own SMS number, Signal, and email. It is not a tool for monitoring another person, and it is not built to be.

For organizations

Blue Decoy Enterprise places canaries across an organization's infrastructure, records everything that touches them, and answers with Pseudoscape, deception that adapts to what the attacker does.

See Blue Decoy Enterprise

Request early access

Leave an address and we will be in touch when a place opens. Nothing else is asked for.

Your address is used to reply to you and for nothing else. How we handle it, and what to do if you think this device is being watched.

Something you would rather not send in the clear? Encrypt it to our public key and write to security@bluedecoy.com.