New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Compliance evidence mapping

SOC 2 evidence mapping

BreakMesh maps each safe scan finding to the SOC 2 Trust Services Criteria it provides evidence for, so security and audit teams can turn a single authorized scan into structured, exportable audit evidence.

121 checks mapped 5 Trust Services Criteria Non-destructive scans

BreakMesh helps you gather audit evidence and reduce risk. It maps findings to control evidence to support your assessment — it does not by itself make your organization compliant or certified.

How the mapping works

Every safe check BreakMesh runs on a verified target is linked to the SOC 2 Trust Services Criteria it produces evidence for. When a scan completes you get a report that groups findings and passed checks by Trust Services Criteria, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.

SOC 2 coverage

Security

  • Account Enumeration Indicators
  • AI Response Data Leakage
  • AI Endpoint Discovery
  • AI Endpoint Rate-Limit Readiness
  • API Documentation Exposure
  • API Rate-Limit Readiness
  • API Third-Party Dependency Inventory
  • Auth Bypass Probes
  • Authenticated Deep Crawl
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • Business Logic — Price Manipulation
  • BOLA / IDOR Two-Account Comparison
  • Bot Protection Detection
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Content Moderation Bypass Canary Probe
  • Cookie Security
  • CORS Edge Cases (null origin / preflight)
  • CORS Policy
  • Credentialed Test-Account Checks
  • CSP Quality Review
  • CSRF Protection Enforcement
  • DDoS Readiness Evidence
  • Dependency CVE Matching (SBOM)
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Drive-by Download / Malicious Redirect Chain
  • Endpoint Auth Indicators
  • Error Disclosure
  • Excessive API CORS Checks
  • Error Disclosure Expansion
  • File Upload Bypass
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • GraphQL Introspection Exposure
  • Header Injection
  • HSTS Strength
  • HTTP Method Exposure
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • IDOR (Two-Account)
  • Insecure Deserialization (Timing)
  • Jailbreak Pattern Indicator
  • JWT Weakness Detection
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Mail Security SPF/DKIM/DMARC
  • API Mass Assignment
  • MFA Configuration Indicators
  • Mixed Content Detection
  • Mobile App Static Analysis (APK/IPA)
  • Model Extraction Risk Indicator
  • OAuth 2.0 / OIDC Security Checks
  • Open Redirect
  • Open Redirect (Active)
  • Origin Exposure Check
  • HTTP Parameter Pollution (HPP)
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Path Traversal
  • Prompt Injection Indicator
  • AI Prompt Reflection Check
  • Rate-Limit Readiness
  • Harmless Reflected XSS Indicators
  • Blocklist and Reputation Checks
  • HTTP Request Smuggling / Desync Readiness
  • Open Risky Ports
  • Secrets in JavaScript Bundles
  • Security Contact Evidence
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Service/Version CVE Hints (Advisory)
  • Session Cookie Scope
  • Session Fixation Check
  • Shadow API Discovery
  • Source Map Exposure
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • Subresource Integrity (SRI) Missing
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
  • AI System Prompt Exposure
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • Trusted Types Signal
  • Versioned Endpoint Discovery
  • WAF/CDN Detection
  • WAF Harmless Canary Probe
  • Weak Password Policy Review
  • WebSocket Security Check
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

Availability

  • AI Endpoint Rate-Limit Readiness
  • API Rate-Limit Readiness
  • Availability Status Evidence
  • AWS Open Security Group Ingress
  • Azure Open NSG Ingress Rules
  • Bot Protection Detection
  • Web Cache Poisoning Readiness
  • DDoS Readiness Evidence
  • Dependency CVE Matching (SBOM)
  • DNS Basics
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • GCP Open VPC Firewall Ingress
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • HTTP/2 and HTTP/3 Support
  • Insecure Deserialization (Timing)
  • Origin Exposure Check
  • Password Spray Indicator
  • Rate-Limit Readiness
  • HTTP Request Smuggling / Desync Readiness
  • Open Risky Ports
  • Service/Version CVE Hints (Advisory)
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • WAF/CDN Detection

Confidentiality

  • AI Response Data Leakage
  • AI Endpoint Discovery
  • Auth Bypass Probes
  • Authenticated Deep Crawl
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Public Blob Storage Exposure
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Command Injection (Timing)
  • Cookie Security
  • CORS Edge Cases (null origin / preflight)
  • CSP Quality Review
  • Directory Listing
  • Sitemap and Robots Exposure
  • Error Disclosure
  • Error Disclosure Expansion
  • GCP Public Cloud Storage Exposure
  • GraphQL Introspection Exposure
  • HSTS Strength
  • HTTPS Redirect
  • IDOR (Two-Account)
  • JWT Weakness Detection
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Mixed Content Detection
  • Mobile App Static Analysis (APK/IPA)
  • Model Extraction Risk Indicator
  • OAuth 2.0 / OIDC Security Checks
  • Path Traversal
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Session Cookie Scope
  • Session Fixation Check
  • Shadow API Discovery
  • Source Map Exposure
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • SSRF (Callback)
  • Subdomain Takeover Risk
  • AI System Prompt Exposure
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • Training Data Extraction Indicator
  • Trusted Types Signal
  • WebSocket Security Check
  • XXE Injection

Privacy

  • Accessibility Evidence Snapshot
  • Account Enumeration Indicators
  • AI Response Data Leakage
  • API Third-Party Dependency Inventory
  • AWS Public S3 Storage Exposure
  • Azure Public Blob Storage Exposure
  • BOLA / IDOR Two-Account Comparison
  • Cookie Consent Mechanism
  • Cookie Security
  • CORS Edge Cases (null origin / preflight)
  • CORS Policy
  • GDPR/CCPA Data Subject Rights
  • Excessive API CORS Checks
  • GCP Public Cloud Storage Exposure
  • IDOR (Two-Account)
  • Login Surface Controls
  • Mobile App Static Analysis (APK/IPA)
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Privacy and Terms Evidence
  • Sensitive Response Pattern Detection
  • Session Cookie Scope
  • Session Fixation Check
  • Training Data Extraction Indicator

Processing Integrity

  • Accessibility Evidence Snapshot
  • API Documentation Exposure
  • AWS CloudTrail Logging Disabled
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • Business Logic — Price Manipulation
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Content Moderation Bypass Canary Probe
  • CSRF Protection Enforcement
  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
  • Endpoint Auth Indicators
  • File Upload Bypass
  • Header Injection
  • HTTP Method Exposure
  • Insecure Deserialization (Timing)
  • Jailbreak Pattern Indicator
  • JWT Weakness Detection
  • API Mass Assignment
  • HTTP Parameter Pollution (HPP)
  • Prompt Injection Indicator
  • AI Prompt Reflection Check
  • HTTP Request Smuggling / Desync Readiness
  • SEO and Social Metadata Evidence
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • Subresource Integrity (SRI) Missing
  • SSTI Template Injection Indicator
  • Versioned Endpoint Discovery
  • XSS — Reflected
  • XSS — Stored