Two capabilities, built and working. One protects what you send. The other tells you when somebody is inside. This document is written for the people who decide, not for the people who would operate it — there is a technical whitepaper for them, and it is linked at the end.
Two episodes set the terms of this conversation, and neither is disputed as a matter of public record.
In January 2018, Le Monde reported that the headquarters of the African Union in Addis Ababa had been transmitting data to servers in Shanghai every night, roughly between midnight and 2am, for five years. The building had been constructed and largely equipped through Chinese funding. The pattern was noticed in January 2017 — not by the institution, and not by an audit, but by one AU computer scientist who happened to look. Listening devices were subsequently reported found in the building. China and Huawei denied the allegations. [1][2]
The second is closer to home and harder to dismiss as foreign interference. The Pegasus disclosures implicated Morocco, Rwanda and Togo as clients of commercial spyware, with target lists running into the thousands and including heads of state, prime ministers, journalists and activists — in several cases a government’s own citizens and its own officials. [3][4][5]
The useful conclusion is not “buy encryption”. It is this: in both cases the people being read could not tell. The infrastructure carrying the communications was not theirs, the question of who else was reading was not answerable, and the discovery, when it came, was accidental. A capability that only works if you already trust the people running it does not address either episode. It relocates them.
Two separate systems. Each runs on its own, neither depends on the other, and they answer opposite halves of the same problem.
A way to send a document so that only the people you name can open it, so that it becomes permanently unreadable at a time you set — including to us, including to whoever runs the server — and so that any later attempt to alter the record of who sent what to whom can be detected by someone other than us.
A way to find out that somebody is already inside your network. It puts out things that look worth stealing and are not real — a file server, an administrator login, a credentials file — and tells you the moment anybody touches one, while holding them in material that wastes their time and never existed.
ZeroHawk protects the traffic you send. Labyrinth protects the infrastructure they attack.
The distinction matters in a meeting about budget, because the two failures are different. The first is a document reaching someone it should not have reached. The second is an intruder sitting on a ministry network for months while every system reports normal. Nothing that solves the first one detects the second.
Concrete situations, in the order they would actually come up.
Circulated to nine named officials, readable for 72 hours. After that no copy anywhere can be opened — not the copies on their devices, not the copy on the server, not by the person who sent it. The encrypted bytes are deliberately left in place, so the guarantee can be demonstrated to you rather than asserted.
A file that two officials must both authorise before it can be opened at all. This is the two-person rule from defence, and the four-eyes rule from banking — the same mechanism, built once.
A figure, sealed with the time it was sealed, in a record where changing it afterwards is detectable by a party that is not us and not the operator. The value here is not secrecy. It is being able to prove afterwards that nothing was altered.
Instead of assuming everything on it is compromised, you get a list: these four documents were on that device, these three are already unreadable, this one is still live — revoke it now. The difference between a crisis and a task.
An intruder finds a file server of departmental backups and works through folders — payroll, procurement, archives, each one opening into more. None of it exists. You were told at the first folder, with their tooling identified and the time logged. They cannot finish: measured against the real system, a crawler spent 76 seconds to see 42 pages and ended with 175 more still waiting — the backlog grows faster than anyone can work through it.
A single page per intruder: when they arrived, what they touched, which decoy credential they took, what they tried to use it on, and how long you held them — in a record that survives being challenged, because an intruder who later edits it leaves evidence of the edit.
Four properties, each of which can be inspected rather than taken on faith.
The usual failure in this field is not weak cryptography. It is a claim that outruns it — and then one person in the room tests the claim and the whole proposal goes with it. So here are the limits, stated by us, up front.
Once a person is authorised to read something, they can point a camera at it. No cryptography reaches a camera. Signal and Snapchat share this limit and so does every system that will ever be sold to you. What we can do is attribution rather than prevention: each reader’s copy carries a marker, so a leaked photograph identifies which copy it came from.
This is exactly what Pegasus does — it does not break encryption, it reads the phone. Any honest system is designed around that rather than pretending otherwise. The single most effective control is short expiry: a device compromised next month yields nothing from a document that stopped being readable last week. Hardware-held keys, two-person authorisation and revoking a device all narrow it further.
An intruder who touches none of the decoys is not detected by it. It does not replace network monitoring, firewalls or patching — it catches what those miss, which in practice is the quiet intruder who already has valid credentials. It is also not undetectable: a careful operator who studies it closely can work out what it is.
We will be asked whether the decoy can locate the intruder, or serve them something. The answer is no, and the reason is practical rather than squeamish: the machine attacking you is usually a third party’s compromised equipment — a hospital, a university, a small business — so acting against it means acting against another victim. Two rules are written down and govern every future change: it never initiates contact with the intruder’s infrastructure, and nothing it serves is built to execute, exploit or damage. Acting on what it finds belongs to your own operators, under your own authority.
Both are built, both are working, and both are tested far harder than is usual — including by a test suite that plays the attacker. But a local test suite is not a deployment record, and we will not describe either system as battle-tested until something has actually tried it. That is what a pilot is for.
Nothing in this document asks to be taken on trust, and that is the point of it.
Both systems ship with the tests an evaluator runs themselves, on their own machine, without us present: the cryptographic guarantees, two independent implementations checked against each other, hardware key custody against real silicon, and an adversary holding full administrative control of the server.
That last suite is the one worth asking about, because it reports its own unresolved finding rather than only its successes. A security test that returns nothing is evidence of nothing. Ask any supplier for the findings their own testing produced; the answer tells you more than the product literature does.
Small, bounded, measurable, and designed so that a negative result is still a result you can act on.
Five to ten named officials. Real documents of real sensitivity, with a seven-day expiry. The tamper-evident record anchored to a witness you operate, so the sovereignty property is exercised and not just described. Deployed on your infrastructure, inside the country.
Labyrinth on a single segment, under written authorisation naming the host and the interface, with alerts going to your own operations centre rather than to us. A retention period and a lawful basis for the logs agreed before it is switched on, because source addresses are personal data under the Data Protection Act.
What was caught, how long intruders were held, what the expiry guarantee did under real use, what broke, and what your own evaluator could and could not verify. “It detected nothing” is a legitimate outcome and should be written into the criteria in advance — a tripwire in a quiet building is supposed to be quiet.
Three things, none of them expensive, and the first one is free.