Leak Canary

Privacy and security monitoring that names names: a unique email alias per vendor, watched around the clock, so the day spam or phishing arrives you know exactly which vendor leaked or breached your data. Full-header evidence, immediate alerts, and a vendor trust ledger that grows with every signup.

Category
Operations, Research
Scheduled tasks
3every few minutes, weekly, monthly
Runtime
Hermes
Works with
IMAP mailboxrequiredCloudflareSlack
Hosting
Fully managed, always on
Leak Canary agent/Schedule
online, a typical week
  • Canary Mailbox SweepEvery 15 minabout 672 runs a week
  • Weekly Register HygieneWeekly on Monday at 08:00
  • Monthly Trust ReportMonthly on day 1 at 08:00
Also1st of every month at 08:00
  1. Mon
    • every 15mCanary Mailbox Sweep
    • 08:00Weekly Register Hygiene
  2. Tue
    • every 15mCanary Mailbox Sweep
  3. Wed
    • every 15mCanary Mailbox Sweep
  4. Thu
    • every 15mCanary Mailbox Sweep
  5. Fri
    • every 15mCanary Mailbox Sweep
  6. Sat
    • every 15mCanary Mailbox Sweep
  7. Sun
    • every 15mCanary Mailbox Sweep

Default schedule from the template. Change any time, or run a task on demand.

How the Leak Canary agent works

Every run reads from the tools you connect, works through its brief, and keeps what it learns in a persistent workspace, so context carries forward instead of starting from scratch.

Reads from
IMAP mailboxrequiredCloudflare

Connect the ones you use. It works with what it has.

Leak Canary agent
  1. Canary Mailbox SweepEvery 15 min
  2. Weekly Register HygieneWeekly on Monday at 08:00
  3. Monthly Trust ReportMonthly on day 1 at 08:00

Keeps in its workspace

  • Who the owner is: business, timezone, quiet hours, delivery channel
  • The seeding playbook and the alias register: which vendor got which alias and fictional contact, when it was seeded, and what its normal mail looks like
Delivers
  • A report after each run

    Sent to your Slack, Telegram, or another channel you connect.

  • Drafts that wait for you

    Anything that leaves your business is written for your approval, not sent on its own.

  • Answers in chat

    Ask it about its work any time from the agent's chat in your dashboard.

The Leak Canary agent, on autopilot

Each task runs on its own schedule in a managed environment. Adjust any of them, or add your own.

  1. Task 01Every 15 min

    Canary Mailbox Sweep

    Sweep the bait mailbox over IMAP for mail delivered to any alias in the register (~/state/canary-register.json, mirrored from ~/workspace/VENDORS.md). For each new message: resolve the recipient alias to its vendor…

    About 672 runs a week

  2. Task 02Weekly on Monday at 08:00

    Weekly Register Hygiene

    Run the register hygiene pass over ~/workspace/VENDORS.md and ~/state/canary-register.json. Look for: aliases minted but never marked seeded by the owner, vendors the owner uses that have no canary at all…

    Once a week

  3. Task 03Monthly on day 1 at 08:00

    Monthly Trust Report

    Send the monthly vendor trust report from ~/state/canary-register.json and ~/state/canary-log.jsonl: aliases seeded and how long each has been live, vendors with hits this month and cumulative…

What it delivers

Each run ends with a message in your channel. Here is the brief the Leak Canary agent's first task works from.

# agent-updatesScheduled run

Leak Canary agentAGENTEvery 15 minutes

Canary Mailbox Sweepcompleted

The brief: Sweep the bait mailbox over IMAP for mail delivered to any alias in the register (~/state/canary-register.json, mirrored from ~/workspace/VENDORS.md). For each new message: resolve the recipient alias to its vendor…

Reply to Leak Canary agent, or ask it anything

Deploy this template and Qoren provisions a dedicated, managed cloud environment: no Docker, VPS, or server upkeep. Tailor the persona, schedules, and tools, use the managed model key or bring your own, and the agent stays online with activity, usage, and spend in one dashboard.

How deployment worksSee pricing

Product names and logos are trademarks of their respective owners, shown here to indicate what this template connects to.

Leak Canary template questions

What does the Leak Canary agent template do?

Privacy and security monitoring that names names: a unique email alias per vendor, watched around the clock, so the day spam or phishing arrives you know exactly which vendor leaked or breached your data. Full-header evidence, immediate alerts, and a vendor trust ledger that grows with every signup. It runs 3 scheduled tasks on a managed cloud environment.

Which runtime does the Leak Canary agent use?

It runs on the Hermes runtime in a dedicated cloud environment that Qoren provisions and keeps online for you.

How often does the Leak Canary agent run?

On a schedule you control. Out of the box it runs every 15 minutes, weekly on monday at 08:00, monthly on day 1 at 08:00. You can change the cadence, or trigger it on demand.

Will the Leak Canary agent do things without my approval?

No. It drafts and prepares the work, and you stay in control of anything that leaves your business. A reply, an invoice reminder, or a public post is written for your approval, not sent on its own.

What do I need to connect before it works?

Start from the template and connect the tools it needs, then set a model key: use the managed key included with your plan, or bring your own on any plan. The Leak Canary agent runs on the Hermes runtime.

Deploy the Leak Canary agent today.

Sign in, start from this template, and go live in minutes. Plans from $39/mo.