Do you have questions?

Here are answers to common questions about HoneyDoc's security model and features.

Need more details? Feel free to reach out!

How does zero-knowledge authentication work?

Zero-knowledge authentication means the password never reaches the server. HoneyDoc uses OPAQUE: the password becomes a key on your device, and only that key authenticates.

  • Your password is transformed into a secure key on your device
  • Only this transformed key is used to authenticate with the server
  • Even if our servers are breached, attackers can't recover your password or impersonate you
  • The server never sees or stores your actual password

Think of it like a high-tech lock where you keep the only key, and the server only knows how to verify if the key is correct without ever seeing it.

What is zero-access encryption?

Zero-access encryption means findings are encrypted in the browser; the host cannot read them. HoneyDoc uses XChaCha20-Poly1305 and X25519 keys.

  • All sensitive data is encrypted in your browser before it reaches the server
  • Each team member has their own unique key pair for accessing shared data
  • Even the server cannot read the data
  • The encryption is so strong it would take supercomputers millions of years to break

Imagine having a vault where each document is locked in an unbreakable box, and only authorized team members have the keys to open them. The server just stores these locked boxes without any ability to peek inside.

Can we self-host HoneyDoc?

Yes! Thanks to our browser-first security model, you can host HoneyDoc anywhere:

  • Your own infrastructure or private cloud
  • Air-gapped environments for maximum isolation
  • Local network for internal use only

Since all security measures happen in your browser, the hosting location doesn't affect the security of your data. See self-hosting.

How fast is decryption in the browser?

Our encryption system is optimized for real-world use:

  • Documents open instantly for most sizes
  • Large files (100MB+) decrypt in seconds
  • Bulk operations are processed in parallel
  • Everything happens locally in your browser for maximum speed

Modern browsers are incredibly fast at encryption operations, so you won't notice any delay in your daily work.

What happens if we lose access to a user?

We've designed the system with backup access in mind:

  • Administrators can reassign access to projects
  • During registration, users receive a recovery key that should be securely stored offline

This ensures you can always regain access to your data in case of emergency.

Is HoneyDoc easy to use?

Yes! We've designed HoneyDoc with usability in mind:

  • Intuitive interface designed by pentesters for pentesters
  • All security happens behind the scenes
  • Built-in templates and automation save time
  • Comprehensive but easy-to-navigate dashboard

You get enterprise-grade security without compromising on user experience.

Which browsers are supported?

HoneyDoc runs in desktop browsers with the Web Crypto API:

  • Chrome, Firefox, Safari, and Edge (latest versions)
  • No plugins or extensions
  • All cryptography uses native browser APIs

Mobile is not supported — and there is no need for it. Pentest reporting is workstation work. Use a laptop or desktop.

What about compliance requirements?

Our security model helps meet strict compliance requirements:

  • Zero-access encryption exceeds most data protection standards
  • Detailed security logs for user actions
  • Self-hosting option for data sovereignty
  • Configurable retention policies

The browser-based security model ensures your data handling aligns with regulations like GDPR, HIPAA, and others.

How does HoneyDoc compare to PwnDoc or Sysreptor?

HoneyDoc is a pentest reporting platform with zero-access encryption, Gantt, runbooks, and a client portal.

See the PwnDoc alternative, the Sysreptor alternative, or the full comparison.

Ready for a demo?

Discover our solution now

Contact us