Honeycake
A Philadelphia-based seed-stage startup building client-side-encrypted "self-protecting files" that carry their own permissions, redaction, and revocation, founded by Integral Ad Science founder Will Luttrell.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Honeycake, founded in 2025 and headquartered in Center City, Philadelphia, builds file-level encryption software — “self-protecting files” — that bakes encryption, per-recipient permissions, redaction, and an audit trail directly into a document rather than relying on a platform or perimeter to protect it. Files are encrypted client-side before ever reaching Honeycake’s servers (a “zero-exposure” architecture), and senders can revoke or fully “burn” access to an already-shared file at any time, including for individual recipients. The product is available via CLI, desktop and mobile apps, a web portal, and browser extensions for Gmail (beta) and Outlook (enterprise).
The company was founded by Will Luttrell, who previously founded ad-verification company Integral Ad Science (NASDAQ: IAS) and Amino Payments (acquired by IAS), and Monica Quigg, a longtime engineering leader with prior roles at Brandtech Group, Highwater, and CrossFit. Honeycake has raised a small seed round (reported at roughly $200,000) and is early-stage, with one publicly disclosed customer testimonial (Western Kentucky University) and exhibitor presence at Black Hat USA 2026 and SecTor 2026. It shipped a major 5.0 platform rewrite in July 2026 adding a searchable-but-encrypted “Ingredients” labeling feature and a redesigned management portal.
Innovation Matrix Assessment
Founded in 2025, Honeycake shipped a full 5.0 platform rewrite across macOS, Windows, iOS and Android in July 2026, adding a new searchable-but-encrypted ‘Ingredients’ labeling feature and management portal — fast iteration for a company this young, though without a multi-year track record yet.
Persistent, file-level encryption with per-recipient permissions and post-send revocation addresses a real gap: sensitive documents that leave the system of record via email, chat, or shared drives, which conventional platform-level DLP tools don't reliably follow.
Exhibitor presence at Black Hat USA 2026 and SecTor 2026 are genuine visibility signals, but disclosed traction is otherwise thin — a reported ~$200K seed round and a single public customer testimonial from a university's operations office, not an enterprise reference customer.
The file-native 'security travels with the file' model, redaction-by-recipient, and post-send revocation are a real architectural difference from platform-bound DLP, though enterprise information-rights-management for files (Microsoft Purview, Virtru, Seclore) is not a new category.
No independent validation or disclosed enterprise-scale production deployment was found; the zero-exposure client-side-encryption claim is architecturally sound per the company's own materials but unverified by a third party here.
Protecting documents once they leave the system of record is a growing, durable concern as AI agents increasingly read email, chat, and shared drives at machine speed, and the underlying need for document-level access control predates and will outlast that specific framing.
Why CISOs Should Care
Gives security and compliance teams a way to protect sensitive documents that live outside the system of record — email, chat, shared drives — with permissions, redaction, and revocation that travel with the file itself and remain enforceable even after an AI agent or unintended recipient gets a copy.
What Makes It Different
Encrypts and manages permissions client-side inside the file itself (a ‘.cake’ wrapper enforced by Honeycake's own apps and extensions) rather than relying on platform-level DLP or a cloud service that has to see the plaintext content, and extends that model with per-recipient redaction and post-send revocation.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
An Incremental Innovator: a genuinely differentiated file-native security architecture and rapid recent product development (a full 5.0 rewrite, exhibitor slots at two major security conferences) are real positives, but this is a seed-stage company (reported ~$200K raised, founded 2025) with a single publicly disclosed non-enterprise customer testimonial and no independent third-party validation yet.
Editorial Note: Claims vs. Verified Findings
The zero-exposure/client-side-encryption architecture is a verifiable design claim from the company's own technical materials, not independently audited here; the ~$200,000 funding figure and investor list come from third-party aggregators (Crunchbase/Tracxn) rather than a company funding announcement, and should be treated as approximate.
Sources
Alternatives to Honeycake
Cyera
AI-powered, agentless data security platform combining DSPM, DLP, and AI-activity monitoring, and one of the fastest-funded startups in…
Fireblocks
Fireblocks is the category-defining institutional digital-asset infrastructure provider, with roughly $2 trillion transferred and the industry's highest valuation…
SandboxAQ
Alphabet spinout building AQtive Guard, a cryptographic management platform helping enterprises inventory, assess and migrate to quantum-safe encryption.
Varonis
Data-centric security platform that monitors file, email, and cloud activity to detect insider threats and ransomware before data…
Bedrock Data
AI-native data security posture management (DSPM) platform using a Metadata Lake to discover, classify, and contextualize data across…
Halcyon
Ransomware-focused cyber resilience platform combining endpoint prevention, automated recovery, and data exfiltration protection.