Documentation menu

Enterprise

Advanced security, compliance, and support for organizations that need more control.

SSO / SAML

Single sign-on via SAML 2.0 is in early access for Enterprise workspaces. We're building support for identity providers including Okta, Azure AD, Google Workspace, and OneLogin.

As SSO rolls out, workspace members will be able to authenticate through your identity provider. Contact sales@mask.pk to join the early-access program and discuss setup.

Custom contracts

Enterprise plans are available with annual or multi-year contracts. Custom pricing is based on usage volume, number of workspaces, and required features. Contact sales@mask.pk to discuss your requirements.

Custom invoicing (PO-based billing, net-30/60 terms) is available for qualifying organizations.

Dedicated support

Enterprise customers receive a dedicated account manager and access to a private Slack channel for direct support. SLAs and priority support are available under Enterprise contracts.

Onboarding assistance, migration support, and quarterly business reviews are included at no extra cost.

SLA

SLAs and priority support are available under Enterprise contracts. Uptime commitments, covered scope, and any service credits are defined in your individual agreement.

Priority support with defined response times is available under Enterprise contracts. Specific targets are set out in your agreement. Contact sales@mask.pk to discuss terms.

Custom domains

Enterprise workspaces can connect unlimited custom domains for branded short links. Each domain requires a DNS CNAME record pointing to cname.mask.pk.

SSL certificates are provisioned and renewed automatically. Subdomain routing is supported, and wildcard domain support is available on request.

Advanced permissions

MASK uses a nine-role model beyond the basic Owner and Admin, giving you granular role-based permissions:

  • Manager — manage team members, links, and workspace resources.
  • Editor — create and edit links, pages, and campaigns.
  • Analyst — read-only access to analytics and reports.
  • Billing — manage subscriptions and payment methods without access to links or analytics.
  • Developer — manage API keys and integrations.
  • Client Viewer — read-only access to shared client reports.
  • Client Approver — review and approve client reports before they publish.

Audit logs

Every action in an Enterprise workspace is logged with the actor, timestamp, IP address, and details of the change. Audit logs are available in Settings → Security → Audit log.

Log retention is configurable, and logs can be exported as CSV or JSON for your SIEM. Filterable by user, action type, resource, and date range.