saascode

HoneyHarbor

A hosted deception fleet for SMBs that deploys isolated decoy services, captures minimized attacker observations, clusters evidence across consenting tenants, and stages reputation reports for analyst approval.

Genesis score6.24/10
Make HoneyHarbor real.0/500
500 more votes and HoneyHarbor is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
1Verified referenced capabilities
4+Confirmed self-hosted LLM honeypot projects
The case

SMBs may benefit from active deception but lack staff to operate believable decoys, isolate them and review attacker evidence. HoneyHarbor deploys disposable tenant-scoped sensors, records protocol interactions, uses constrained generation to vary fake environments, and surfaces investigation candidates in a managed dashboard. The supplied research confirms several active open-source LLM honeypots with multi-feed reporting, one verified capability and an expensive managed-deception incumbent, while finding no SMB-priced managed LLM-deception service. The closest source project is AGPL-licensed, so a commercial service requires a documented license strategy or clean-room implementation; copying code is not permitted by assumption. Automatic external reporting is unsafe: IP addresses can belong to proxies, compromised hosts, researchers or shared infrastructure. Sensor observation, fingerprint candidate, cross-sensor correlation, analyst disposition, report approval, feed acknowledgement, later reputation action and remediation remain separate. Generated decoys operate with default-deny egress, synthetic secrets and no production authority. Cross-customer correlation uses minimized, purpose-limited features only with tenant authorization and cannot expose another tenant's events. Success is earlier, reviewable detection evidence—not attacker identity, guaranteed prevention or a universal reputation verdict.

Who pays — and why

An SMB security leader or managed security provider that wants active deception coverage without operating a sensor fleet internally.

Market signalValidate by isolated sensor, exposed protocol, retained event volume, analyst review, approved external report and response tierManaged deception appliances and open-source honeypots are observed market references, not fixed product pricing
What it unlocks
A sensor safety policy covering placement, synthetic data, egress, resource limits, retention, legal authorization and emergency shutdown.
An evidence model separating network observation, indicator, fingerprint hypothesis, correlation, analyst finding and external-report eligibility.
A cross-tenant contribution contract with consent, minimization, aggregation thresholds, correction, withdrawal and non-disclosure.
How Genesis scored it
6.24across seven criteria
tension 6temporal 8blindspot 5buyer 7leverage 5convergence 5why-not 7
8
Temporal window

Fresh open-source activity supports a strong current window.

7
Buyer persona

SMB security and managed providers are concrete, though environment size and budget need discovery.

5
Convergence

One cross-reference and no inbound links support baseline convergence.

Why it scored well

Several active open projects and a high-priced incumbent validate demand while the managed SMB tier remains open.

What's holding it back

Operations and analyst review constrain scale, external reporting creates false-positive risk and licensing requires care.

Signals detected3 sources crossed
SignalOpen-source research

SignalMarket research

SignalCompetitor research

Direction briefhoneyharbor-managed-deception-evidence.md
honeyharbor-managed-deception-evidence.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.