Swiss · Document security

Know when it opens.

Place believable files, credentials, and web sensors near sensitive systems. Hacked alerts you when someone opens, copies, or tries to use them.

Start with CHF 0 3 active documents · Email alerts · 30 day history

Put a live decoy in your environment within 5 minutes.

Create your account, choose a document lure, download it, and place it where a real file belongs. Hacked starts watching immediately, with nothing to install on employee devices.

Deploy my free trap From account to live trap in 5 minutes
Your free workspace includes
Keep 3 document lures active at the same time
Receive alerts at 1 email address
See basic location data for every opening
Review 30 days of alert history
How the signal works Enters · Copies · Opens · Signals · Alerts
01 / Breaks in

Initial access happens somewhere else.

A phished password, a leaked credential, or an unpatched server creates the opening. Hacked watches what happens after access begins.

02 / Steals

The decoy travels with the valuable files.

Place a believable document beside the data someone would copy. Its filename and contents give no reason to leave it behind.

03 / Opens

The lure fits normal work.

Current dates, credible content, and familiar file names keep each lure in context.

04 / Sends a signal

The hidden tracker sends the evidence.

Render sensors can fire on load. Credential lures fire when someone tries to use them.

05 / We alert you

You receive the context needed to act.

The alert carries the IP, city, device, network flags, and exact lure that opened. Send it by email, Slack, Microsoft Teams, or webhook.

What changes for you One workspace · One dashboard

Know when a decoy opens and where the signal came from.

CHF 199 per workspace per month gives your team up to 25 active lures, 5 recipients, richer network context, integrations, and 1 year of alert history. Start with 3 document lures free and upgrade when the workflow proves useful.

01 / Insider access

Know which device touched an HR decoy.

A salary lure assigned to HR opens from a finance laptop. The alert identifies the device and gives your investigation a clear first step.

02 / Off hours access

Turn unusual timing into a clear investigation lead.

A board minutes lure opens at 02:00 from an unfamiliar device. The alert puts the file, IP, operating system, and location in one view.

03 / Exfiltration

Learn where a copied file resurfaced.

A client export lure opens on a residential network in another country. The alert shows which decoy travelled and where it appeared.

04 / Lure catalogue

Cover files, sites, cloud tools, and AI clients.

Use Office files, site clone sensors, Kubernetes access files, MCP configurations, images, links, and QR codes.

05 / Fast triage

Dismiss expected access with enough context.

Deployment zones label approved access while the source IP, ASN, device fingerprint, and network flags explain the signal. VPN, proxy, and Tor traffic appears separately.

06 / Fits your stack

Send alerts into the tools your team watches.

Route signals to Slack, Microsoft Teams, webhooks, or your own REST API workflow. Business keeps 1 year of history and exports CSV or JSON.

Choose your coverage Free · Business · Enterprise
All prices in CHF · VAT excluded · Swiss jurisdiction
Questions Common

Is using deception lures legal?

You place and monitor decoys on systems you own or are authorized to protect. Hacked records access to those decoys and does not enter or modify another system.

Can the intruder tell that the file is a trap?

Lures use normal file formats and credible content. Some document readers show their standard external content prompt, while render and credential sensors have no special Hacked marker.

Do I need to install anything?

Create a lure in the dashboard, download it or copy its tracker URL, and place it where it belongs. You install no agent and push no endpoint configuration.

What if my own employees trigger false alerts?

Use deployment zones to label approved access. Each alert includes the source IP, ASN, device fingerprint, and separate VPN or proxy flags, giving you enough context to dismiss expected activity.

What about remote workers and VPN users?

Business alerts flag VPN, proxy, and Tor exit traffic. The dashboard shows the observed IP and ASN, then labels known commercial VPN providers so expected remote work is easier to recognize.

Where is the data stored?

The platform runs in Frankfurt on encrypted volumes, while Swiss jurisdiction applies to your customer agreement. Hacked keeps Free alert data for 30 days and Business alert data for 1 year.

Can I export alerts to my SIEM or my SOC tool?

Business includes a REST API with eh_ prefix keys and webhook delivery to Slack, Microsoft Teams, or any endpoint that accepts JSON. Export CSV or JSON for offline analysis.

Deploy 3 document lures free and know when one opens.