How the mapping works
Every safe check BreakMesh runs on a verified target is linked to the SOC 2 Trust Services Criteria it produces evidence for. When a scan completes you get a report that groups findings and passed checks by Trust Services Criteria, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.
SOC 2 coverage
Security
- Account Enumeration Indicators
- AI Response Data Leakage
- AI Endpoint Discovery
- AI Endpoint Rate-Limit Readiness
- API Documentation Exposure
- API Rate-Limit Readiness
- API Third-Party Dependency Inventory
- Auth Bypass Probes
- Authenticated Deep Crawl
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- Business Logic — Price Manipulation
- BOLA / IDOR Two-Account Comparison
- Bot Protection Detection
- Web Cache Poisoning Readiness
- Command Injection (Timing)
- Content Moderation Bypass Canary Probe
- Cookie Security
- CORS Edge Cases (null origin / preflight)
- CORS Policy
- Credentialed Test-Account Checks
- CSP Quality Review
- CSRF Protection Enforcement
- DDoS Readiness Evidence
- Dependency CVE Matching (SBOM)
- Deprecated Browser APIs
- Directory Listing
- Sitemap and Robots Exposure
- DNSSEC Review
- WHOIS and Domain Expiry
- Drive-by Download / Malicious Redirect Chain
- Endpoint Auth Indicators
- Error Disclosure
- Excessive API CORS Checks
- Error Disclosure Expansion
- File Upload Bypass
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
- GraphQL DoS Readiness (Batching / Alias / Depth)
- GraphQL Introspection Exposure
- Header Injection
- HSTS Strength
- HTTP Method Exposure
- HTTP/2 and HTTP/3 Support
- HTTPS Redirect
- IDOR (Two-Account)
- Insecure Deserialization (Timing)
- Jailbreak Pattern Indicator
- JWT Weakness Detection
- Login Rate-Limit Simulation
- Login Surface Controls
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- Mail Security SPF/DKIM/DMARC
- API Mass Assignment
- MFA Configuration Indicators
- Mixed Content Detection
- Mobile App Static Analysis (APK/IPA)
- Model Extraction Risk Indicator
- OAuth 2.0 / OIDC Security Checks
- Open Redirect
- Open Redirect (Active)
- Origin Exposure Check
- HTTP Parameter Pollution (HPP)
- Password Reset Flow Checks
- Password Spray Indicator
- Path Traversal
- Prompt Injection Indicator
- AI Prompt Reflection Check
- Rate-Limit Readiness
- Harmless Reflected XSS Indicators
- Blocklist and Reputation Checks
- HTTP Request Smuggling / Desync Readiness
- Open Risky Ports
- Secrets in JavaScript Bundles
- Security Contact Evidence
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Server Header Disclosure
- Service/Version CVE Hints (Advisory)
- Session Cookie Scope
- Session Fixation Check
- Shadow API Discovery
- Source Map Exposure
- Safe SQL Injection Indicators
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- Subresource Integrity (SRI) Missing
- SSRF (Callback)
- SSTI Template Injection Indicator
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
- AI System Prompt Exposure
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- Trusted Types Signal
- Versioned Endpoint Discovery
- WAF/CDN Detection
- WAF Harmless Canary Probe
- Weak Password Policy Review
- WebSocket Security Check
- XSS — Reflected
- XSS — Stored
- XXE Injection
Availability
- AI Endpoint Rate-Limit Readiness
- API Rate-Limit Readiness
- Availability Status Evidence
- AWS Open Security Group Ingress
- Azure Open NSG Ingress Rules
- Bot Protection Detection
- Web Cache Poisoning Readiness
- DDoS Readiness Evidence
- Dependency CVE Matching (SBOM)
- DNS Basics
- DNSSEC Review
- WHOIS and Domain Expiry
- GCP Open VPC Firewall Ingress
- GraphQL DoS Readiness (Batching / Alias / Depth)
- HTTP/2 and HTTP/3 Support
- Insecure Deserialization (Timing)
- Origin Exposure Check
- Password Spray Indicator
- Rate-Limit Readiness
- HTTP Request Smuggling / Desync Readiness
- Open Risky Ports
- Service/Version CVE Hints (Advisory)
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
- TLS Certificate
- TLS Chain and Expiry Depth
- WAF/CDN Detection
Confidentiality
- AI Response Data Leakage
- AI Endpoint Discovery
- Auth Bypass Probes
- Authenticated Deep Crawl
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Public Blob Storage Exposure
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Command Injection (Timing)
- Cookie Security
- CORS Edge Cases (null origin / preflight)
- CSP Quality Review
- Directory Listing
- Sitemap and Robots Exposure
- Error Disclosure
- Error Disclosure Expansion
- GCP Public Cloud Storage Exposure
- GraphQL Introspection Exposure
- HSTS Strength
- HTTPS Redirect
- IDOR (Two-Account)
- JWT Weakness Detection
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- Mixed Content Detection
- Mobile App Static Analysis (APK/IPA)
- Model Extraction Risk Indicator
- OAuth 2.0 / OIDC Security Checks
- Path Traversal
- Secrets in JavaScript Bundles
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Session Cookie Scope
- Session Fixation Check
- Shadow API Discovery
- Source Map Exposure
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- SSRF (Callback)
- Subdomain Takeover Risk
- AI System Prompt Exposure
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- Training Data Extraction Indicator
- Trusted Types Signal
- WebSocket Security Check
- XXE Injection
Privacy
- Accessibility Evidence Snapshot
- Account Enumeration Indicators
- AI Response Data Leakage
- API Third-Party Dependency Inventory
- AWS Public S3 Storage Exposure
- Azure Public Blob Storage Exposure
- BOLA / IDOR Two-Account Comparison
- Cookie Consent Mechanism
- Cookie Security
- CORS Edge Cases (null origin / preflight)
- CORS Policy
- GDPR/CCPA Data Subject Rights
- Excessive API CORS Checks
- GCP Public Cloud Storage Exposure
- IDOR (Two-Account)
- Login Surface Controls
- Mobile App Static Analysis (APK/IPA)
- OAuth 2.0 / OIDC Security Checks
- Password Reset Flow Checks
- Privacy and Terms Evidence
- Sensitive Response Pattern Detection
- Session Cookie Scope
- Session Fixation Check
- Training Data Extraction Indicator
Processing Integrity
- Accessibility Evidence Snapshot
- API Documentation Exposure
- AWS CloudTrail Logging Disabled
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- Business Logic — Price Manipulation
- Web Cache Poisoning Readiness
- Command Injection (Timing)
- Content Moderation Bypass Canary Probe
- CSRF Protection Enforcement
- Dependency CVE Matching (SBOM)
- Drive-by Download / Malicious Redirect Chain
- Endpoint Auth Indicators
- File Upload Bypass
- Header Injection
- HTTP Method Exposure
- Insecure Deserialization (Timing)
- Jailbreak Pattern Indicator
- JWT Weakness Detection
- API Mass Assignment
- HTTP Parameter Pollution (HPP)
- Prompt Injection Indicator
- AI Prompt Reflection Check
- HTTP Request Smuggling / Desync Readiness
- SEO and Social Metadata Evidence
- Safe SQL Injection Indicators
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- Subresource Integrity (SRI) Missing
- SSTI Template Injection Indicator
- Versioned Endpoint Discovery
- XSS — Reflected
- XSS — Stored