Swiss · Document security

Know when it opens.

Place a realistic Word or Excel decoy beside sensitive files. When someone opens it, Hacked sends you the IP, location, device, and network details, with no macros and no software to install.

Start with CHF 0 3 active documents · Email alerts · 30 day history

Put a live decoy in your environment within 5 minutes.

Create your account, choose a document lure, download it, and place it where a real file belongs. Hacked starts watching immediately, with nothing to install on employee devices.

Deploy my free trap From account to live trap in 5 minutes
Your free workspace includes
Keep 3 document lures active at the same time
Receive alerts at 1 email address
See basic location data for every opening
Review 30 days of alert history
How the signal works Enters · Copies · Opens · Signals · Alerts
01 / Breaks in

Initial access happens somewhere else.

A phished password, a leaked credential, or an unpatched server creates the opening. Hacked watches what happens after access begins.

02 / Steals

The decoy travels with the valuable files.

Place a believable document beside the data someone would copy. Its filename and contents give no reason to leave it behind.

03 / Opens

The document opens without giving itself away.

It can open on another device or network hours or weeks later. The file renders normally, with no popup or visible warning.

04 / Sends a signal

The hidden tracker sends the evidence.

The signal fires silently from documents, links, pixels, or QR codes. You install no agent on your network or employee devices.

05 / We alert you

You receive the context needed to act.

The alert carries the IP, city, device, network flags, and exact lure that opened. Send it by email, Slack, Microsoft Teams, or webhook.

What changes for you One workspace · One dashboard

Know when a decoy opens and where the signal came from.

CHF 199 per workspace per month gives your team up to 25 active lures, 5 recipients, richer network context, integrations, and 1 year of alert history. Start with 3 document lures free and upgrade when the workflow proves useful.

01 / Insider access

Know which device touched an HR decoy.

A salary lure assigned to HR opens from a finance laptop. The alert identifies the device and gives your investigation a clear first step.

02 / Off hours access

Turn unusual timing into a clear investigation lead.

A board minutes lure opens at 02:00 from an unfamiliar device. The alert puts the file, IP, operating system, and location in one view.

03 / Exfiltration

Learn where a copied file resurfaced.

A client export lure opens on a residential network in another country. The alert shows which decoy travelled and where it appeared.

04 / Lure catalogue

Choose the lure that fits each location.

Use 10 lure types across documents, shortcuts, images, email, web pages, links, and QR codes. Business adds custom filenames and uploaded Word or Excel templates.

05 / Fast triage

Dismiss expected access with enough context.

Deployment zones label approved access while the source IP, ASN, device fingerprint, and network flags explain the signal. VPN, proxy, and Tor traffic appears separately.

06 / Fits your stack

Send alerts into the tools your team watches.

Route signals to Slack, Microsoft Teams, webhooks, or your own REST API workflow. Business keeps 1 year of history and exports CSV or JSON.

Choose your coverage Free · Business · Enterprise
All prices in CHF · VAT excluded · Swiss jurisdiction
Questions Common

Is using deception lures legal?

You place and monitor decoys on systems you own or are authorized to protect. Hacked records access to those decoys and does not enter or modify another system.

Can the intruder tell that the file is a trap?

Lures are designed to behave like the file, page, link, or code they represent. Tracking runs silently in the background without a visible popup, warning, or marker.

Do I need to install anything?

Create a lure in the dashboard, download it or copy its tracker URL, and place it where it belongs. You install no agent and push no endpoint configuration.

What if my own employees trigger false alerts?

Use deployment zones to label approved access. Each alert includes the source IP, ASN, device fingerprint, and separate VPN or proxy flags, giving you enough context to dismiss expected activity.

What about remote workers and VPN users?

Business alerts flag VPN, proxy, and Tor exit traffic. The dashboard shows the observed IP and ASN, then labels known commercial VPN providers so expected remote work is easier to recognize.

Where is the data stored?

The platform runs in Frankfurt on encrypted volumes, while Swiss jurisdiction applies to your customer agreement. Hacked keeps Free alert data for 30 days and Business alert data for 1 year.

Can I export alerts to my SIEM or my SOC tool?

Business includes a REST API with eh_ prefix keys and webhook delivery to Slack, Microsoft Teams, or any endpoint that accepts JSON. Export CSV or JSON for offline analysis.

Deploy 3 document lures free and know when one opens.