No rate cap for the people who protect people.
Hospitals, public health, government at every level, election offices, emergency services, universities and the non-profits that fight abuse get the full Maskbreak API with the hourly limit removed. Free, no expiry, and no strings beyond an acceptable-use line.
Every Maskbreak key starts at 1,000 visitor checks an hour. Approval removes that cap on the key you already have. Same signals, same verdicts, same DPA — nothing is held back from the free tier, so nothing is added except the ceiling coming off.
- Hospitals, clinics and health systems — patient portals, e-prescriptions, telehealth logins, staff accounts.
- Public health, medicine and research — health agencies, labs, registries, research hospitals.
- Government at every level — benefits, tax, permits, citizen identity and the portals behind them.
- Election authorities — voter registration, candidate filing, results publication.
- Emergency, crisis and safety services — 112 and 911 systems, crisis lines, shelters, child-safety and domestic-violence organisations.
- Universities, schools and academic research — student and staff accounts, financial aid, security research that publishes.
- Registered non-profits, CERTs and CSIRTs — the teams fighting scams, trafficking and abuse for a living.
The whole product, with the ceiling off.
There is no better version of Maskbreak behind a paywall for anyone. What the program adds is the one thing the free tier holds back: the hourly limit, which a hospital at flu-season peak or a benefits portal on payday reaches before lunch.
No hourly cap
The 1,000-an-hour limit comes off /v1/evaluate and /v1/lookup on your key. /v1/usage reports hourly_limit: null and uncapped: true, so your monitoring can tell.
Every signal on every check
VPN, proxy, Tor and cloud-server detection with the service named when known, fake-browser and bot detection, and device linking that ties one machine to the many accounts it touches. The same API everyone gets.
Paperwork that survives procurement
A self-serve DPA aligned to UK and EU GDPR Article 28, a public sub-processor list and a security whitepaper. No certifications yet: Maskbreak is pre-audit for SOC 2 Type II and says so on every page a questionnaire will read.
An engineer, not a queue
Support goes to the person who built the detection pipeline and reads your integration logs. If you are under attack, say so on the form: the cap comes off the existing key first and verification follows.
Four steps, one of which is ours.
Create the free account
If the organisation has none, sign up with an institutional address. Every key starts at 1,000 checks an hour, no card.
Apply on this page
Public-sector and academic email domains are fast-tracked. Say what the key protects and roughly how busy it gets.
We verify the organisation
Against its own website and the public registry, never a questionnaire. One business day, UK hours.
The cap comes off your key
Nothing to rotate or redeploy. Settings and /v1/usage read “no hourly cap” from then on.
Under attack right now?
Tick the box on the form. The cap comes off first and verification follows. We would rather spend a day checking a hospital’s paperwork after the credential-stuffing run than during it. Existing customers can also write to support@maskbreak.com with “under attack” in the subject.
Five lines, none of them a logo.
- Protect your own services and the people who use them. That is the whole purpose.
- No surveillance. Do not use it to identify, track or profile individuals beyond preventing fraud and abuse of your own systems. It is not a surveillance tool and will not become one for anyone.
- No resale. A contractor may operate the integration on your account; the key is not theirs to reuse elsewhere.
- Tell us roughly what it protects, never the data behind it. Rough numbers let us size the infrastructure under you.
- Cite us if you publish. Researchers get no review and no veto from us, only a request for an advance copy so we can fix what you found.
Asked by privacy officers, answered plainly.
Do you sign HIPAA business associate agreements?
No, and we say so rather than imply otherwise. Maskbreak is pre-audit for SOC 2 Type II and holds no HIPAA BAA. In practice the API never receives a health record: it sees a connection token, an IP address and device signals from the login or reset page, never the record behind it. Most privacy officers treat that as a security control on the front door rather than PHI processing. The self-serve DPA covers UK and EU GDPR Article 28.
Is there really no cap?
No per-key cap. The service keeps a network-level denial-of-service ceiling that sits far above any real deployment, and approved public-interest keys pass through it. If you ever see a 429 on an approved key, that is a bug and we want to hear about it.
We are a private hospital, or a vendor building for a government. Do we qualify?
Non-profit and public providers qualify outright. For-profit providers, and vendors operating a system on behalf of a public body, should write to us: the usual answer is yes for the public-facing system and no for the vendor's other clients. A contractor can run the integration on the organisation's own account.
Our domain is not a .gov address.
Most are not. Estonian ministries sit on plain .ee domains and a county hospital may be on .org. Institutional suffixes are a fast lane, not a gate: everyone else is verified against the public registry and the organisation's own website, which takes a day or two.
Does this change anything for everyone else?
No. The free tier is 1,000 visitor checks an hour on every key and stays that way. This program removes the ceiling for organisations whose peak is a payday, a flu season or an election night rather than a growth curve. Companies that need more than the free tier have the enterprise evaluation program.
What about data residency?
Ask. Every sub-processor and where it runs is published on the sub-processor list, and custom residency arrangements are available on request.
Can researchers publish results that make Maskbreak look bad?
Yes. We do not review or veto findings. We ask for a citation and an advance copy so we can fix what you found before the rest of the world reads about it.
Protecting a public service?
Apply above, or write to support@maskbreak.com with “Public interest” in the subject. Either way a person answers within a business day.