The layer underneath

HoneyCore

Zero-knowledge authentication and zero-access encryption. HoneyCore is that architecture under HoneyDoc — and under other products we help you ship.

HoneyDoc is the product. HoneyCore is the principle. A browser-first core: encrypt in the client, keep keys with the people who should have them, let the host store ciphertext and nothing else.

Zero-access encryption

  • Data is encrypted in the browser before it reaches a server.
  • The host cannot read reports, findings, or files.
  • Permissions are key possession, not a flag in a database.

Zero-knowledge authentication

  • The server never stores a password or its equivalent, only an encrypted envelope.
  • A dedicated recovery key reopens a session so you can change the password — no reset emails.

Hostile host

  • HoneyCore assumes the infrastructure is already compromised.
  • Confidentiality still holds.

Extra-layer encryption

  • A second encryption pass inside the TLS tunnel.
  • The payload stays opaque even where corporate TLS inspection is mandatory.

What HoneyDoc adds

HoneyDoc is the pentest product on HoneyCore: findings, templates, runbooks, Gantt, a client portal, and a documented API — on data the host cannot read.

Security · Features

Templates

DOCX and PPTX, not only the report. Attestations, executive decks, or any other deliverable.

Findings

Vulnerability database with duplicate, import, and export. Phases and retests on the same core.

Collaboration

QA comments and real-time editing. The host never gets a plaintext copy.

Project management

Gantt, free-resource assignment, assignable TODOs.

Client portal

Clients download deliverables, send extra documentation, and review findings.

File storage

Engagement files, evidence, logs, and deliverables. Encrypted the same way as everything else.

Your stack

We implement HoneyCore

Need the same zero-trust core under a product that is not HoneyDoc? We help teams implement HoneyCore. For more, contact us.

Contact us