Licensing security
Protect against key sharing without guessing at every customer.
Use clear signals to review suspicious access, then choose the response that fits your product and your customers.
A copied key is rarely a tidy, single event. It can look like a normal customer moving to a new PC, a key shared with a friend, or a reseller account used by more people than expected. The useful goal is to make misuse visible and give yourself a sensible way to act.
Start with device-based access
System Locker can lock a key to an HWID when it is first redeemed. A stable, privacy-conscious identifier makes it harder to casually use the same key on a second machine. Your application keeps the check close to the feature it protects, while the server remains the authority on whether the key is valid.
That is a useful first layer, but it's not a reason to treat every changed device as abuse. Customers can use the portal's reset flow, and your support team can handle exceptional cases through the developer tools or Management API.
Review the pattern before you react
Authentication logs give you a record to investigate when a key appears in places or on devices that do not match its normal use. That context is more useful than a one-off failed login: it helps distinguish an honest migration from a pattern that needs attention.
Aegis adds IP intelligence and configurable sensitivity for eligible plans. Use it to surface activity associated with VPN infrastructure, repeated sharing, or unusual reseller behavior, then tune it against what legitimate use of your software actually looks like.
Choose a response you can stand behind
Not every detection deserves the same action. You can investigate first, freeze a key while you review it, block a request, revoke a key, or block a hardware ID when the evidence warrants it. A measured policy protects your product without turning normal support into a fight.
Build the policy into your support process: explain what information you review, give staff a path for legitimate device changes, and keep automatic enforcement restrained until you understand the false-positive risk for your audience.
Start with integration, then upgrade for visibility.
Lifetime plans include 30 days of logs and our best auth API. Upgrade to a subscription for Aegis whenever you're ready.