Data visibility and secrets
Understand company isolation, role visibility, and safe evidence sharing.
Give authorized operators enough visible state to maintain a connector while keeping complete credentials and unrelated lead data out of the UI and support evidence.
Why it matters
Provider, saved state, and a bounded credential suffix can answer which configuration is present without turning HoneyFalcon into a place that reveals the complete secret. Clear evidence rules also shorten support work without spreading personal data.
Where to work
Open Company -> Connectors and select Edit. The credential status appears near the write-only Credential or Replace credential field and the Remove the saved credential option.
Steps
- Confirm that you are in the intended company and connector before reading or changing configuration.
- Use the provider name, Saved state, and visible suffix to recognize a normal-length saved credential.
- Do not expect HoneyFalcon to return the complete saved credential; short credentials may be identified only as hidden.
- Enter a complete new value under Replace credential when rotation is required, or choose Remove the saved credential when the connector should no longer keep one.
- Run Test draft with synthetic data and Save changes before activating or resuming the reviewed revision.
- For support, share only the page, action, timestamp, visible state, Lead ID or Delivery ID, and exact non-secret message.
- Rotate or revoke any credential, webhook key, or secret URL that may have been exposed.
See it in HoneyFalcon

Recognize the stored credential without revealing or copying its reusable value.
Keep configuration transparent and secrets non-retrievable
Recognize the saved state
The editor can show the provider, Saved state, and a bounded suffix for a normal-length credential. This helps an authorized operator confirm which credential is configured.
A short credential may be reported only as hidden. Neither state returns the complete value.
Replace or remove deliberately
Replace credential is a write-only field. Enter the complete replacement, test the visible draft with synthetic data, and save the reviewed revision.
Remove the saved credential deletes the credential from the next saved configuration. Choose replacement or removal, not both.
Respect company and role boundaries
Company configuration and lead evidence are visible only through the access granted to the signed-in account. An identifier or copied URL from another company does not grant access.
Use the dedicated Roles and permissions guide for who may administer company settings; do not treat a routing role as a general access bypass.
Share the smallest useful evidence
A support case normally needs the page, action, timestamp, visible state, Lead ID or Delivery ID, saved revision, HTTP status, and exact bounded message.
It does not need the complete credential, Authorization header, request payload, secret destination URL, webhook key, or unrelated names, emails, phone numbers, addresses, and billing identifiers.
Respond to suspected exposure
Masking a screenshot after a secret has been shared does not make the credential safe again. Replace or revoke it at the provider or HoneyFalcon boundary, update the intended sender or connector, and validate with synthetic data.
Keep only the non-secret identifiers needed to correlate the incident and the replacement.
Masked state supports recognition, not recovery. Never share a reusable credential or unnecessary lead data; replace or revoke any secret that may have been exposed.
Protected configuration is handled safely when
- An authorized operator can identify the provider and saved credential state without retrieving the complete value.
- Replacement or removal is explicit, tested with synthetic data, and saved as a reviewed revision.
- Support evidence contains bounded state and identifiers but no reusable secret or unnecessary personal data.
- Any suspected exposure is closed by replacement or revocation, not only by masking the screenshot.