| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Deception technology | Security operations | 7% | 4 of 94 | 0% | 5 | under 10 labels · led by Thinkst Canary at 37% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 0 | 1 | 0 | 0 | 1 |
| Perplexity Sonar | 0 | 0 | 0 | 0 | 0 |
| Grok 4.1 Fast | 1 | 0 | 0 | 0 | 1 |
| Mistral Small | 1 | 0 | 0 | 0 | 1 |
| DeepSeek V4 Flash | 0 | 0 | 0 | 0 | 0 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 0 | 0 | 0 | 0 |
| Kimi K2 | 0 | 0 | 0 | 0 | 0 |
| GLM 4.7 FlashX | 1 | 0 | 0 | 0 | 1 |
| MiniMax M2.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-6 Luna | 0 | 0 | 0 | 0 | 0 |
| Muse Glimmer 30B | 0 | 1 | 0 | 0 | 1 |
Verbatim evidence the judge attached to positive labels.
“HoneyWire (free) or Thinkst Canary (low-cost, easy to deploy) are the best choices” Mistral Small · Deception · budget prompt · first choice
“the best deception technology platform is HoneyWire (open‑source, AGPL‑3.0)” GLM 4.7 FlashX · Deception · budget prompt · first choice
“Top Recommendation: HoneyWire (Free, Open-Source)” Grok 4.1 Fast · Deception · budget prompt · first choice
“A newer open-source, agentless option designed for easy terminal-based deployment” Gemini 3.5 Flash · Deception · paraphrase prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 24 of the 24 answers that named HoneyWire and are not a share of its labels.
134 of the 134 domain citations in answers naming HoneyWire came from somebody else's page.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read October 5, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
| Kind | Pages | Last 90 days | 2025-11 to 2026-10 | Latest | Categories named |
|---|---|---|---|---|---|
| Blog | 2 | undated |
Every page honeywire.dev exposes, subdomains included. Kind is read from the address and title. The last 90 days, the latest date and the twelve months count pages by when they were published, from the site's feeds, a date in the address, or the page's own publication date, read from up to a hundred of its most recently changed pages; a page that says only when it last changed is counted in its kind but not in when, so the recent counts are a floor, and a kind none of whose pages gives a publication date reads undated. Read October 5, 2026.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
What HoneyWire's own pages state, read October 5, 2026: honeywire.dev. A claimed page can correct any of them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when HoneyWire's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as HoneyWire, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for HoneyWire by email, built from the raw record of the edition. It shows: