Stuffing Prevention
Blunt credential-stuffing attacks by blocking previously leaked login credentials.
Password breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
Stuffing Prevention runs on the password breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- k-anonymity: the password never leaves the user's device
- Blocks the exact credentials attackers use in stuffing lists
- 1 credit per check, screen every registration and reset
- A single API call satisfies auditors asking for compromised-password controls
Screen at login too
Screen at login, not just creation: when a correct password is also a breached password, step up, MFA challenge, change prompt, or session flag depending on your risk posture. Combine with velocity signals: breached credentials plus a spike in attempts from new IPs is a stuffing run in progress, and the combination justifies aggressive throttling.
Doors the lists cannot open
Stuffing succeeds because reused breached credentials work by default; login-time screening makes them stop working precisely where attackers try them. The blocked-attempt counter becomes your evidence: teams typically discover thousands of stuffing attempts per week that were previously indistinguishable from failed typos.