MFA Enforcement
Require stronger authentication for accounts whose emails appear in known breaches.
Email breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
MFA Enforcement runs on the email breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- Full breach history, names, dates and exposed data classes per breach
- 1 credit per check, so continuous monitoring stays affordable
- New-breach detection turns a public leak into a same-day security response
- Works for one address or your whole domain
Enforce where the risk is
Implement as a policy tier: accounts with recent password-exposed breaches require MFA at next login; clean accounts keep the optional path. Check at login time with cached results so the policy evaluates fresh without adding latency. Pair enforcement with the reason, 'your email appeared in a breach, so we're requiring extra protection', and resistance drops.
Security without the revolt
Risk-based enforcement gets most of universal MFA's security benefit at a fraction of the adoption pain, and it concentrates support load on exactly the users who most needed the protection. Track takeover attempts against the enforced cohort, the before/after on that segment is the clearest security ROI number you'll produce this year.