Serious about security.
Built for procurement.
Everything your security, legal, and procurement teams will ask about, answered up front — no sales call required to read the fine print. When you are ready, [email protected] goes straight to the founding team.
GDPR & CCPA
UK/EU GDPR and CCPA compliant. We operate as a data processor for end-user evaluation — Art. 28 DPA self-serve at maskbreak.com/dpa, with a 30-day notice commitment before any sub-processor change.
Privacy policy →GDPR-aligned processing
UK/EU GDPR-aligned processing with Standard Contractual Clauses for international transfers (processing includes US-based infrastructure, as disclosed in our Privacy Policy). End-user analysis runs on network and device metadata — never names, emails, or payment data.
Trust & security →Minimal retention
Evaluation IPs are one-way hashed after 7 days. Passwords are bcrypt-hashed and breach-checked via k-anonymity — plaintext never leaves the device.
Retention details →Hardened by default
TOTP two-factor authentication, active session management with per-device revocation, and breach-checked password policies on every account.
Security overview →Measured, not promised
Sub-40ms server-side median evaluations, a public status page, published service level objectives, and transparent rate limits — no silent throttling, Retry-After on every 429.
Paperwork, handled
Enterprise agreements, custom MSAs, security questionnaires (CAIQ / SIG Lite), and vendor-onboarding forms are handled directly by the founding team — typical turnaround is days, not quarters.
[email protected] →The paperwork, up front
What we can put in front of your legal and security teams today:
| Document | Status | How to get it |
|---|---|---|
| Data Processing Agreement (Art. 28) | Published | maskbreak.com/dpa — self-serve, with a for vendor files; countersigned copy via [email protected] |
| Master Service Agreement / custom terms | Available | Negotiated directly with the founding team |
| Service level objectives | Published | maskbreak.com/sla — contractual SLA with credits under enterprise MSA |
| Security whitepaper | Published | maskbreak.com/security-whitepaper — self-serve, with a for vendor files |
| Sub-processor list | Published | maskbreak.com/sub-processors — dated change log with 30-day change notice; network & device-intel providers named under DPA |
| Security questionnaires (CAIQ, SIG Lite, custom) | Available | Send yours to [email protected] |
| SOC 2 Type II report | Pre-audit | We publish the audit firm and scope when the engagement is signed — see Trust |
Billing: self-serve tiers (Free, and Growth at €49/mo founding price with billing starting at GA) take no card during the open beta — see pricing. Enterprise agreements are billed annually by invoice — vendor-onboarding forms and purchase orders are no problem.
Startup & enterprise evaluation program
Building a startup or evaluating Maskbreak for an enterprise platform? Tell us what you're working on and we'll unlock up to 1,000,000 evaluations per month, free — full signal set, production traffic, no credit card.