Skip to content

About Us

It began as an idea in 2024. Today more than 20 organisations run on the platform.

We do not sell and walk away — we operate the platform ourselves.

Honeypot Security started in 2024 with one question: why should organisations in this region pay for protection written abroad, which does not see the local attack and makes you queue at a vendor for a single rule change?

The answer was to keep the platform in our own hands. ADR/WAF, anti-DDoS, Helix SIEM, the mail gateway and radar threat intel run on one platform today, and we are the ones who operate it. Changing a rule or answering a new attack does not mean queuing abroad.

We do not sell the product and walk away — we operate it. Every protected site on the platform doubles as a sensor: an attacker profile seen at one customer is applied to the rest immediately.

Started as an idea

2024

Organisations on the platform

20

+
Monitoring

24/7

Products on one platform

5

Why the answer arrives faster here

The difference is a way of working, not a marketing line. The five questions below get entirely different answers through a reseller than they do from the team that operates the platform — and the difference shows up precisely during an attack.

The reseller model against writing the code yourself
QuestionThrough a resellerHere
When does a rule for a new attack shipYou wait for the vendor's releaseWe ship it the same day
What happens when a bug is foundA ticket is opened and queuedWe deal with it ourselves
Regional attack profilesThinly covered by global rulesCollected from customers on the platform
Where the logs and TLS key liveIn the vendor's infrastructureInside Uzbekistan
Who does the tuningYou, or your integratorWe do — we operate it too

An attack on one customer becomes a warning for the rest

Every protected site is also a sensor. A technique an attacker tries on one customer is written into the platform and accounted for across all the others in advance — which is exactly what a foreign vendor cannot offer on regional sources.

The platformThe attack profile travels from one customer into the platform, and from there to everyone else. Each new customer therefore widens the field of view for all of them.
What We Build

Five Products, Three Services

ADR / WAF

  • Web application defence at session level, not request level
  • The stages of an attack are linked to each other
  • A graded response: observe, throttle, challenge, block
  • Traffic never leaves the country

The platform is under our control

Tuning and updates need no third party.

  • All five products on one platform
  • A rule needed today ships today
  • Fixing a problem does not need a vendor ticket

We do not sell what does not work

What sales promises has to exist in the product.

  • Every claim rests on a capability that runs
  • An unfinished feature is said to be unfinished
  • No figure is published without a source

We stay after the sale

Once it is deployed you are working with us.

  • 24/7 monitoring and incident response
  • Configuration and tuning are ours to do
  • Local language, local time zone

Honesty

What we do not promise

Over-promising is the most common sales technique in this industry. These four things we do not say — and you can check that against this site itself.

  1. “100% protection”

    No defence is total. We raise the cost of an attack and make it visible — we do not promise to eliminate it. When something gets through, we are the ones who tell you.

  2. Customer logos

    We do not publish customer names without their written consent. That is why there is not a single customer logo on this site — an absence by decision, not by omission.

  3. “Accredited certificate”

    Our Academy certificates confirm that a programme was completed; they carry no state accreditation. We say so on the Academy page and in the certificate check.

  4. Numbers without a source

    Every figure on this site rests on something checkable. An unverified number does not get published — which is why there is no invented customer quote here and no manufactured statistic.

Questions

About The Company

We do. We operate the platform, so changing a rule or answering a new attack does not mean queuing at a foreign vendor — when it is needed, it ships the same day.

Yes. There is no size threshold — scope and price follow your external surface and the work required. Starting with a single domain is fine.

Response is ours — we do not sell the product and walk away. Monitoring runs around the clock, and when an attack is identified the person who contacts you is from the team that operates the platform, not a support queue abroad. Response times are fixed in the contract: no single figure is published here, because it depends on the scope of the service.

On infrastructure inside Uzbekistan. TLS is terminated locally and logs are stored locally. The Secure Mail Gateway goes further and runs air-gapped — nothing leaves at all.

You show us a domain and we give you a first read on your external posture. Nothing is installed and nothing is blocked at that stage. What we scope next follows from what it finds.

Shall we talk?

Show us a domain and we will give you a first read on your current external posture. Nothing is changed at this stage.

Let’s start
Get in touch
Get in touch