About Us
It began as an idea in 2024. Today more than 20 organisations run on the platform.
It began as an idea in 2024. Today more than 20 organisations run on the platform.
We do not sell and walk away — we operate the platform ourselves.
Honeypot Security started in 2024 with one question: why should organisations in this region pay for protection written abroad, which does not see the local attack and makes you queue at a vendor for a single rule change?
The answer was to keep the platform in our own hands. ADR/WAF, anti-DDoS, Helix SIEM, the mail gateway and radar threat intel run on one platform today, and we are the ones who operate it. Changing a rule or answering a new attack does not mean queuing abroad.
We do not sell the product and walk away — we operate it. Every protected site on the platform doubles as a sensor: an attacker profile seen at one customer is applied to the rest immediately.

The difference is a way of working, not a marketing line. The five questions below get entirely different answers through a reseller than they do from the team that operates the platform — and the difference shows up precisely during an attack.
| Question | Through a reseller | Here |
|---|---|---|
| When does a rule for a new attack ship | You wait for the vendor's release | We ship it the same day |
| What happens when a bug is found | A ticket is opened and queued | We deal with it ourselves |
| Regional attack profiles | Thinly covered by global rules | Collected from customers on the platform |
| Where the logs and TLS key live | In the vendor's infrastructure | Inside Uzbekistan |
| Who does the tuning | You, or your integrator | We do — we operate it too |
Every protected site is also a sensor. A technique an attacker tries on one customer is written into the platform and accounted for across all the others in advance — which is exactly what a foreign vendor cannot offer on regional sources.
Tuning and updates need no third party.
What sales promises has to exist in the product.
Once it is deployed you are working with us.
Honesty
Over-promising is the most common sales technique in this industry. These four things we do not say — and you can check that against this site itself.
No defence is total. We raise the cost of an attack and make it visible — we do not promise to eliminate it. When something gets through, we are the ones who tell you.
We do not publish customer names without their written consent. That is why there is not a single customer logo on this site — an absence by decision, not by omission.
Our Academy certificates confirm that a programme was completed; they carry no state accreditation. We say so on the Academy page and in the certificate check.
Every figure on this site rests on something checkable. An unverified number does not get published — which is why there is no invented customer quote here and no manufactured statistic.
We do. We operate the platform, so changing a rule or answering a new attack does not mean queuing at a foreign vendor — when it is needed, it ships the same day.
Yes. There is no size threshold — scope and price follow your external surface and the work required. Starting with a single domain is fine.
Response is ours — we do not sell the product and walk away. Monitoring runs around the clock, and when an attack is identified the person who contacts you is from the team that operates the platform, not a support queue abroad. Response times are fixed in the contract: no single figure is published here, because it depends on the scope of the service.
On infrastructure inside Uzbekistan. TLS is terminated locally and logs are stored locally. The Secure Mail Gateway goes further and runs air-gapped — nothing leaves at all.
You show us a domain and we give you a first read on your external posture. Nothing is installed and nothing is blocked at that stage. What we scope next follows from what it finds.
Show us a domain and we will give you a first read on your current external posture. Nothing is changed at this stage.

