Serious about security.
Built for procurement.
Everything your security, legal, and procurement teams will ask about, answered up front — no sales call required to read the fine print. When you are ready, support@maskbreak.com goes straight to the founding team.
What your security and legal teams will ask
GDPR & CCPA
UK/EU GDPR and CCPA compliant. We operate as a data processor for end-user evaluation — Art. 28 DPA self-serve at maskbreak.com/dpa, with a 30-day notice commitment before any sub-processor change.
Privacy policy →GDPR-aligned processing
UK/EU GDPR-aligned processing with Standard Contractual Clauses for international transfers (processing includes US-based infrastructure, as disclosed in our Privacy Policy). End-user analysis runs on network and device metadata — never names, emails, or payment data.
Trust & security →Minimal retention
Evaluation IPs are one-way hashed after 7 days. Passwords are bcrypt-hashed and breach-checked via k-anonymity — plaintext never leaves the device.
Retention details →Hardened by default
TOTP two-factor authentication, active session management with per-device revocation, and breach-checked password policies on every account.
Security overview →Measured, not promised
Sub-150ms server-side median evaluations, a public status page, published service level objectives, and transparent rate limits — no silent throttling, Retry-After on every 429.
Paperwork, handled
Enterprise agreements, custom MSAs, security questionnaires (CAIQ / SIG Lite), and vendor-onboarding forms are handled directly by the founding team — typical turnaround is days, not quarters.
support@maskbreak.com →The paperwork, up front
What we can put in front of your legal and security teams today:
| Document | Status | How to get it |
|---|---|---|
| Data Processing Agreement (Art. 28) | Published | maskbreak.com/dpa — self-serve, with a PDF for vendor files; countersigned copy via support@maskbreak.com |
| Master Service Agreement / custom terms | Available | Negotiated directly with the founding team |
| Service level objectives | Published | maskbreak.com/sla — contractual SLA with credits under enterprise MSA |
| Security whitepaper | Published | maskbreak.com/security-whitepaper — self-serve, with a PDF for vendor files |
| Sub-processor list | Published | maskbreak.com/sub-processors — dated change log with 30-day change notice; network & device-intel providers named under DPA |
| Security questionnaires (CAIQ, SIG Lite, custom) | Available | Send yours to support@maskbreak.com |
| SOC 2 Type II report | Pre-audit | We publish the audit firm and scope when the engagement is signed — see Trust |
Billing: there is none. Maskbreak is free — 1,000 requests an hour, every signal, no card — see the free page. Enterprise agreements exist for the paperwork (MSA, DPA, security questionnaires), not for a bill.
Startup & enterprise evaluation program
Building a startup or evaluating Maskbreak for an enterprise platform? Tell us what you're working on and we'll unlock up to 1,000,000 evaluations per month, free — full signal set, production traffic, no credit card.
A hospital, public body, election office, university or registered non-profit rather than a company? The public-interest program removes the hourly cap entirely, with institutional email domains fast-tracked.