New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Safe security simulation platform

Scan production safely. Prove you own it first.

BreakMesh verifies ownership before it touches a target, runs non-destructive checks across 10 implemented scanner packages (plus active penetration testing on Enterprise), and turns findings into audit evidence, instantly — remediation plans, SOC 2 mapping, and client-ready PDF reports.

Prove ownership first 101 non-destructive checks Audit evidence, instantly
Built for security-conscious teams Ownership-verified Non-destructive SOC 2 mapped GDPR-ready
10 Scanner packages
101 Safe checks
SOC 2 Evidence mapping
PDF Client reports

Why teams use BreakMesh

From one free baseline to recurring assurance evidence

BreakMesh now covers production hygiene, OWASP-style checks, threat readiness, auth/session controls, API exposure, compliance evidence, web quality snapshots, AI/LLM canary probes, cloud posture (AWS/Azure/GCP), and offline mobile app analysis.

For owners

Know what needs attention

See risk score, grade, severity counts, passed checks, failed checks, and historical change in one report.

For developers

Fix with clear evidence

Each finding includes affected URLs, confidence, evidence, remediation, and references that map to implementation work.

For agencies

Show clients measurable progress

Use scheduled scans, PDF reports, white-label branding, JSON exports, and SOC 2 evidence mapping for client delivery.

Workflow

From target verification to evidence export

A controlled workflow keeps scans authorized, repeatable, and useful for remediation, reporting, and audit readiness.

01

Add a target

Register the domain and base URL you own or manage so the scan boundary is clear.

02

Verify control

Confirm authorization with DNS verification before any assessment can run.

03

Choose a package

Run Basic Hygiene, OWASP, threat-readiness, auth, API, compliance, web quality, AI security, cloud posture, or mobile security checks based on plan access.

04

Export evidence

Review severity, evidence, passed checks, SOC 2 mapping, comparison history, and PDF/JSON exports.

Approach Turnaround Repeatable Evidence output
Traditional pentest Days to weeks PDF report per engagement
Manual audit Days Varies by auditor

Security coverage

10 passive packages and active pentest for comprehensive security assurance

Start free with Basic Hygiene, then expand into OWASP, threat-readiness, auth, API, compliance, web quality, AI security, cloud posture, and mobile static analysis. Enterprise plan unlocks active penetration testing with digital consent and CVSS-scored findings.

Developer
OW

OWASP Starter

Safe simulations for common OWASP-style risks without destructive exploitation.

  • 14 checks for CORS, CSP, open redirects, source maps, and sensitive files
  • Harmless reflected XSS, SQL, and SSTI indicators using safe canary patterns
  • CORS edge cases (null origin / preflight), secrets in JS bundles, and expanded error disclosure
Team
TR

Threat Readiness

Evidence for edge, abuse, and availability controls without generating attack traffic.

  • 8 checks: WAF/CDN, bot protection, rate-limit, and DDoS readiness signals
  • Certificate-transparency subdomain discovery and takeover risk detection
  • Harmless WAF canary probe and origin exposure indicators
Team
AS

Auth & Session

Review login and session controls in approved test environments or scoped accounts.

  • 15 checks across login surface, session scope, reset flow, and enumeration indicators
  • OAuth/OIDC, CSRF, session fixation, BOLA/IDOR, and BFLA privilege-escalation checks
  • Low-rate login rate-limit, password-spray, and consent-gated credentialed evidence
Team
API

API Security

Inspect known API surfaces for exposure, permissive policies, and response leakage.

  • 16 checks for API docs, methods, versioned endpoints, auth signals, and CORS
  • JWT weakness, GraphQL introspection + DoS readiness, shadow API, and WebSocket security checks
  • Dependency CVE matching (SBOM), SRI, and drive-by download / redirect chain detection
Team
CE

Compliance Evidence

Collect lightweight evidence for security, availability, privacy, and operational controls.

  • 10 checks for security.txt, privacy, terms, DNSSEC, domain expiry, and mail security
  • Mail/DNS hardening (MTA-STS, TLS-RPT, CAA), cookie consent, and GDPR/CCPA data subject rights evidence
  • Availability evidence and blocklist/reputation checks
Team
WQ

Web Quality Evidence

Add client-ready digital readiness snapshots alongside security evidence.

  • Accessibility evidence for language, image alt text, and form labels
  • SEO and social metadata checks for canonical, Open Graph, and structured data
  • Useful for agency reporting without changing the security risk score
Team
AI

AI Security

Scan your own AI features automatically, on every scan — harmless canary probes for applications with LLM or AI chat interfaces, consent-gated.

  • 10 checks: endpoint discovery, prompt injection, system-prompt exposure
  • Training-data extraction, model-extraction risk, and jailbreak pattern indicators
  • Content-moderation bypass canary and response data-leakage detection
  • Maps to 5 of 10 OWASP LLM Top 10 risks (LLM01, LLM02, LLM05, LLM07, LLM10)
  • Requires confirmation that tool-calling and agentic actions are disabled
Team
CP

Cloud Posture

Read-only AWS/Azure/GCP checks using customer-supplied, scoped credentials — never stored.

  • 10 checks across AWS, Azure, and GCP
  • Public storage exposure (S3, Blob Storage, Cloud Storage)
  • Open security-group/firewall ingress, stale/over-permissive IAM, CloudTrail logging, and encryption gaps
Team
MS

Mobile Security

Offline static analysis of an uploaded APK or IPA — zero network traffic.

  • Hardcoded secrets, ATS/cleartext-traffic misconfiguration, insecure storage flags
  • Sensitive Android permission review and iOS file-sharing/ATS checks
  • Runs entirely against the uploaded artifact — never contacts a live service

Built for authorized testing

Controlled simulations your team can defend

BreakMesh is designed around consent, scope control, low-rate checks, and auditability so every scan can be tied back to an approved target.

  • OK DNS ownership verification before scans can run
  • OK No destructive payloads or volumetric traffic
  • OK Private IP ranges and localhost blocked by default
  • OK Explicit consent required for credentialed auth checks
  • OK Pentest mode requires signed SOW + Rules of Engagement before any active probe is sent
  • OK Destructive payloads (DROP, rm -rf, reverse shells) permanently banned in all modes
  • OK Per-plan URL limits, scan cooldowns, and worker timeouts
  • OK Evidence, remediation, and references captured for every finding
Team threat_readiness

WAF and DDoS readiness evidence

Checks edge-provider, bot-control, rate-limit, and origin-exposure signals without generating attack traffic.

Report value: Adds availability and security evidence for operational reviews.

Team compliance_report

SOC 2 evidence mapping

Completed checks map to security, availability, confidentiality, privacy, and processing integrity themes.

Report value: Export audit-ready PDF and JSON evidence with reviewer sign-off fields.

Questions

Frequently asked questions

Answers for teams evaluating BreakMesh for safe simulations, recurring assurance, and client evidence.

Is BreakMesh a penetration testing tool?

BreakMesh offers two modes. Passive simulation packages (Free–Agency) check for misconfigurations without exploiting them. The Enterprise plan adds active pentest packages that send real exploitation probes — but only after a signed Statement of Work and digital Rules of Engagement consent, within a time-bounded engagement window.

Do I need to verify my domain?

Yes. Targets must be verified before scanning, which helps keep testing scoped to websites you own or are approved to manage.

Which packages are live today?

Basic Hygiene, OWASP Starter, Threat Readiness, Auth & Session, API Security, Compliance Evidence, Web Quality Evidence, AI Security, Cloud Posture, and Mobile Security are all implemented, plus Pentest Basic and Pentest Advanced on the Enterprise plan.

Can reports support audit and client reviews?

Yes. Reports include passed checks, findings, severity, evidence, remediation, SOC 2 theme mapping, historical comparison, and PDF/JSON export support.

Start with a free baseline, grow into full evidence reporting

Create a free account, verify your first domain, and expand into OWASP, threat-readiness, auth, API, compliance, web quality, AI security, cloud posture, and mobile security packages as your needs grow.