- Every key still starts at 1,000 visitor checks an hour; approval removes the cap on the key the organisation already has, nothing to rotate.
- Hospitals, public health, government at any level, election authorities, emergency services, universities and registered non-profits qualify; companies use the enterprise program.
- Institutional email domains are fast-tracked, everyone else is verified by registry and website, and the answer takes one business day.
- Under attack: the cap comes off first and verification follows.
On this page
From today, hospitals, public health bodies, governments at any level, election authorities, emergency and crisis services, universities and the registered non-profits that fight abuse can apply to have the hourly cap removed from their Maskbreak key. The form is at maskbreak.com/public-interest. This post is the reasoning, because a program like this is a set of promises, and promises should be written down where anyone can read them back to us.
What changes, precisely
Maskbreak has one tier. Every key gets the whole product — VPN, proxy, Tor and cloud-server detection with the service named when known, fake-browser and bot detection, device linking — at 1,000 visitor checks an hour, no card, no expiry. There is no paid version behind it, and that does not change.
What the program changes is the one number. On approval, the cap comes off the key the organisation already has. No new key, no new endpoint, no separate product. /v1/usage reports hourly_limit: null and uncapped: true, the X-RateLimit-* headers stop being sent because there is nothing to report, and the Settings page says “no hourly cap” in words. The per-source-IP ceiling that protects the service from a runaway client stays for everyone else and lets an approved key through.
Who qualifies
- Hospitals, clinics and health systems — patient portals, e-prescriptions, telehealth logins, staff accounts.
- Public health, medicine and research — health agencies, laboratories, registries, research hospitals.
- Government at every level — benefits, tax, permits, citizen identity and the portals in front of them.
- Election authorities — voter registration, candidate filing, results publication.
- Emergency, crisis and safety services — 112 and 911 systems, crisis lines, shelters, child-safety and domestic-violence organisations.
- Universities, schools and academic research — student and staff accounts, financial aid, security research that publishes.
- Registered non-profits, CERTs and CSIRTs — the teams fighting scams, trafficking and abuse for a living.
Who does not: companies. Not because we think less of them, but because the free tier is already the same product and the enterprise evaluation program exists for the ones that outgrow it. For-profit providers and vendors operating a system on behalf of a public body are case by case; the usual answer is yes for the public-facing system on the organisation’s own account, and no for the vendor’s other clients.
A free key returns decision, risk_score and reasons for every visit, 1,000 requests an hour, no card; public-interest organisations can apply to have the cap removed.
Get an API keyWhy the cap, and not the price
The cap is the only ceiling anyone hits on Maskbreak, and for the companies the product was built around it is generous. A startup grows into 1,000 checks an hour over months, and by the time it gets there it has a conversation with us anyway.
Public services do not grow into it. They hit it. A benefits portal reaches 1,000 logins an hour on the morning of payday and is quiet the rest of the week. A hospital reaches it the day flu-clinic bookings open. An election office reaches it once every few years, for a few hours, and those are the hours that matter. Their traffic is spiky in a way a rate limit is built to punish, and their procurement is slow in a way that makes “write to us when you need more” a six-week answer to a six-hour problem.
Those peaks are also when the attack shows up. Credential-stuffing runs and fake-account floods are timed to hide in legitimate load, so the hour the cap bites is the hour the check was needed most. Removing the cap for these organisations is not generosity; it is the product doing what it says at the only moment that counts.
Why these organisations
Fraud against a public service is fraud against everyone who pays for it. Benefit payments redirected to a mule account after a takeover. Tax refunds re-routed by changing bank details on a hijacked account. Patient portals taken over to refill prescriptions or redirect insurance claims. Unemployment and relief schemes drained with stolen identities at scale, every application arriving through a residential proxy on a fresh browser profile. Student financial aid claimed by accounts that were never students. Participation platforms flooded with fake citizens during a consultation.
The people defending those systems have the least budget, the longest procurement and the most to lose from a false positive, because on their side of the login a false positive is a person locked out of their medicine or their money rather than a lost trial signup. That last point matters for which product they use, not only whether they can afford one. Maskbreak returns review for a VPN on its own and never blocks on it; it returns the reasons behind every verdict so a decision can be explained to the person it affected; and it links devices per customer and hash-only, so it cannot become a way to identify anyone across services. Those are the properties a public body should demand, and they are the ones we already had.
How verification works
Institutional email domains are fast-tracked: an application from a .gov, .gov.uk, .nhs.uk, .edu, .ac.uk, .gouv.fr or similar address goes to the top of the pile. That is a fast lane, not a gate. Most public bodies are not on a suffix like that — Estonian ministries sit on plain .ee domains, a county hospital may be on .org — so everyone else is verified against the public registry and the organisation’s own website. It takes a business day, and it is done by a person, not a questionnaire.
There is one clause we want to be explicit about. If an organisation is under attack right now, it says so on the form, and the cap comes off the existing key first. Verification follows. We can afford that asymmetry because the downside of a wrong lift is some free checks, and the downside of a slow one is a hospital fighting a credential-stuffing run at 1,000 checks an hour while we check its paperwork.
What we ask in return
- Protect your own services and the people who use them. That is the whole purpose.
- No surveillance. Do not use it to identify, track or profile individuals beyond preventing fraud and abuse of your own systems. The API classifies connections and devices; it does not identify people, and we will refuse and revoke any use that tries to make it.
- No resale. A contractor may operate the integration on your account; the key is not theirs to reuse elsewhere.
- Tell us roughly what it protects, never the data behind it. Rough numbers let us size the infrastructure ahead of you.
- Cite us if you publish. Researchers get no review and no veto from us, only a request for an advance copy so we can fix what you found before everyone else reads about it.
No logo rights. No case-study obligation. No expiry, no pilot period, no “introductory” anything.
What we are not promising
A HIPAA business associate agreement, because we do not sign them and will not pretend to. Maskbreak is pre-audit for SOC 2 Type II and holds no certifications; the pricing page and the trust page say so, and the program page says it again where a privacy officer will read it. In practice the API never receives a health record — it sees a connection token, an IP address and device signals from the login page, never the record behind it — and the self-serve DPA covers UK and EU GDPR Article 28. That is a security control on the front door, and we describe it as one.
We are also a small team, and the service level terms are the same for an approved key as for any other. If the program ever has to change, approved keys get the same 30 days’ notice by email that the pricing page promises every key.
Apply
The form is at maskbreak.com/public-interest. If the organisation has no account yet, create the free one with an institutional address first; approval removes the cap from the key you already have rather than issuing a new one. Existing customers who are under attack can also write to support@maskbreak.com with “under attack” in the subject.
Questions people ask
- Do we need a new API key once we are approved?
- No. Approval removes the hourly cap from the key the organisation already has, so nothing is rotated or redeployed. Settings and the /v1/usage endpoint read "no hourly cap" from then on, and the X-RateLimit headers stop being sent because there is no limit to report.
- Can a vendor apply on behalf of a hospital or a ministry?
- Yes, on the organisation's own account. The key belongs to the hospital or the ministry and the vendor operates the integration on it. The vendor's other clients are not covered; a company that needs more than the free tier for its own product has the enterprise evaluation program instead.
- Is there a limit on how many organisations can join?
- No fixed number. Each approval is a decision about one organisation, not a draw from a pool, and the infrastructure is sized as the program grows. The only thing we ask for on volume is a rough number, so we can size it ahead of you rather than behind you.
- Why not just raise the free tier for everyone?
- Because the cap is doing a job for everyone else: it is the anti-abuse backstop that lets the product be free without a card on file. A public body's peak is a payday or an election night, not a growth curve, and the program removes the ceiling for exactly the organisations whose traffic looks like that.
The same API, whoever you are
Every key gets the whole product: VPN, proxy, Tor and cloud-server detection with the service named when known, fake-browser and bot detection, device linking. 1,000 requests an hour, no card. Public-interest organisations can apply to have the <a href="/public-interest">cap removed</a>.