Policy Enforcement
Screen employee passwords against breach databases to enforce your security policy.
Password breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
Policy Enforcement runs on the password breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- k-anonymity: the password never leaves the user's device
- Blocks the exact credentials attackers use in stuffing lists
- 1 credit per check, screen every registration and reset
- A single API call satisfies auditors asking for compromised-password controls
Policy as code, logged
Encode the policy as code at every password event: length and uniqueness rules from your existing validator, breach screening from the API, both enforced at creation, change and reset. Log each check's verdict and timestamp, the log stream is the enforcement evidence, and it accumulates without anyone maintaining a spreadsheet.
Paper and practice finally match
The gap between written policy and enforced policy is where audits find findings: 'no compromised passwords' on paper with only complexity rules in code is exactly the discrepancy assessors look for. With screening wired in, the policy document and the system behavior finally match, and the breach-count data tells you the policy is doing real work.