Most of what we recommend is infrastructure — something that sits in a rack or on an endpoint and quietly does its job. This one is closer to personal hygiene, and it is aimed at the people who run the business rather than the servers they run it on.
What it actually does
Cloaked gives every account you create its own identity. A generated email address, a generated phone number, and a stored password, all pointing back to you and each revocable on its own. The email forwards to your real inbox. The phone number forwards calls and texts to your real handset. The vendor on the other end never receives either real one. Around that core it bundles a password manager, removal requests to consumer data brokers, a VPN, and an identity theft insurance policy.
The part worth understanding is the aliasing, and specifically what it buys you beyond a quieter inbox. It buys attribution and containment. When a masked address starts collecting phishing, you know exactly which company leaked or sold it, because exactly one company ever had it. And you can burn that single alias without touching your real address, your password, or any of the other two hundred accounts you have quietly accumulated since 2011.
That is the practical answer to a problem we wrote about after the Canvas breach: you cannot audit a vendor's security, and you will not find out they were careless until well after the fact. Compartmentalizing what you hand each one is the part you actually control.
Why this lands on our desk
Almost none of the incidents we get called about start at the firewall. They start with a person.
- A password reused across a personal account and a business one, surfacing in a breach corpus years later.
- A mobile number that is public enough to support a SIM swap, or simply a convincing callback.
- An owner's home address, age and relatives sitting on a people-search site, giving a wire-fraud pretext all the texture it needs to sound like someone who knows you.
None of that is fixed by a better firewall, because none of it touches your network until the moment it does. The personal data of the people who sign the checks is part of the business attack surface, and it is the part that no endpoint policy reaches.
The data broker part, which is the one people underrate
Data brokers are companies whose business is compiling and selling profiles of people who never agreed to it. Public records, property filings, loyalty programs, app SDKs and other brokers all feed in, and what comes out is a profile carrying your home address, your age, your phone numbers, your past addresses and the names of your relatives. The people-search sites you can find yourself on in about thirty seconds are just the retail storefront for that industry.
For a business, that inventory is the raw material for pretexting. Wire fraud rarely succeeds because someone in accounting was careless. It succeeds because the caller knew the owner's street, their spouse's first name and which bank the company uses, and so sounded like a person who belonged. Every one of those details is purchasable, and none of it required breaking anything.
Removing yourself by hand is possible, and it does not scale. California alone has over 500 registered brokers. Each runs its own opt-out, several want more identifying information before they will act on it, and — the part that defeats most people who try — they re-list. Brokers pull from upstream sources that keep supplying you, so removal is a standing obligation rather than an afternoon's work.
The legal picture is moving, but unevenly, and the difference matters depending on where you sit. California residents got a real answer on January 1, 2026, when the state privacy agency opened DROP, the Delete Request and Opt-out Platform: one verified request that reaches every broker registered in the state, free, operated by the government rather than by a vendor. Brokers must begin honoring those requests on August 1, 2026, under penalties of $200 per request per day.
Texas has the rights but not the machinery. Under the Texas Data Privacy and Security Act, in force since July 2024, you can demand access, correction and deletion, and the Secretary of State maintains a searchable registry of the brokers required to register here. What Texas does not have is a DROP. There is no single request and no one-click delete, so you exercise the right broker by broker, and only the Attorney General can enforce it — the statute carries no private right of action.
That gap is what a removal service actually sells you. Not a legal right you were missing, but the labor of exercising a right you already have, several hundred times over, and then again next quarter. Cloaked puts its own coverage at over a thousand sites, though it is worth knowing that published counts in this category are not comparable between vendors, because they each define a site differently.
Where it overlaps with what you already pay for
We would rather talk you out of a duplicate subscription than sell you enthusiasm, so be clear about the overlap before you buy.
If you already run 1Password, you have the password manager and the authenticator, and Cloaked's versions of those are not a reason to switch. If you use Proton, you already have email aliasing through Proton Pass. In both cases the sensible read is that you are buying Cloaked for what those do not do.
What is genuinely distinctive is the combination of phone number aliasing, data broker removal, and identity theft insurance sitting behind one subscription and one app. Phone aliasing in particular has no good equivalent in the tools most people already own, and it is the one that closes the SIM-swap and callback-pretext gap above.
What we would check before you subscribe
Four things, none of which are dealbreakers, all of which are easier to know now than later.
- It is US and Canada only. If you have staff or family outside those, the aliasing will not follow them.
- Cloaked Pay, the virtual card feature, is invite-only. It appears in the marketing and it is genuinely useful, but do not subscribe on the assumption you get it on day one.
- Data broker removal is a subscription, not an event. For the re-listing reason above, the protection lapses when the subscription does. Budget it as an ongoing service line rather than a one-time cleanup.
- Plan the exit before you need it. Once a few dozen logins route through masked addresses, those aliases are load-bearing. Ask how you export and re-point them before you commit, the same question we would ask of any vendor holding something you would struggle to reproduce.
On the security of the thing itself, the posture is better than most consumer privacy apps. Cloaked publishes SOC 2 Type II, ISO 27001 and ISO 27701 certifications, PCI DSS compliance for the payments side, and a zero-knowledge architecture where the provider cannot read your stored data. We are not aware of a breach. Weigh that against the obvious structural point, which is true of every service in this category: you are consolidating a map of every account you own with one more company.
What it costs
At the time of writing, $14.99 a month for an individual, or $119.99 a year. Couple and family plans cover two and four people respectively, and every tier includes the same feature set — you are paying for seats, not capabilities. There is also a Cloaked Enterprise offering pitched at companies as an employee benefit, though the published detail is thin enough that we would want specifics on administration and reporting before recommending it as a rollout.
The bottom line
For an owner, an executive, or anyone whose personal exposure is genuinely a business risk, this is a reasonable few hundred dollars a year and one of the few privacy products where we can point at the mechanism rather than the marketing. For a general staff rollout, we would want to see the Enterprise administration story first.
We are recommending this one from use rather than from a datasheet. It runs on our own accounts, it has been genuinely useful, and that is the only reason it is written up here.
It is not a substitute for the boring work — patched endpoints, enforced MFA, managed identity — and it does not pretend to be. It closes a gap that sits alongside all of that, on the personal side of the line where most real attacks actually begin.
If you would like help deciding whether it fits, or want the same thinking applied to the rest of your security posture, call 281-407-1619 or contact us.
Disclosure: Tomotechi has no affiliate, referral or reseller relationship with Cloaked, and earns nothing if you sign up. We pay for it like everyone else.
Sources
- Cloaked product overview
- Cloaked plans and pricing
- Cloaked achieves SOC 2 Type II compliance
- Common questions about privacy and security — Cloaked Support
- Cloaked Enterprise
- Is Cloaked legit? A review from a competitor — Proton
- DROP, the Delete Request and Opt-out Platform — California Privacy Protection Agency
- Data broker registration — Texas Secretary of State
- Consumer privacy rights and the Texas Data Privacy and Security Act — Texas Attorney General