New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Pricing

Security scanning plans built for authorized teams

Every plan runs non-destructive, ownership-verified scans. Upgrade to unlock more scan packages, higher limits, and team delivery features.

Switch to yearly and get two months free.

Free

$0/mo

Validate a single website and see the core scan workflow.

1verified target
10scans / month
25URLs per scan
Manualscheduling
JSONexport format

Scan packages included

  • Basic Hygiene Headers, HTTPS, TLS, cookies, DNS — 15 checks
  • OWASP StarterCORS, XSS, SQLi indicators — 14 checks
  • Threat ReadinessWAF, rate-limit, DDoS — 8 checks
  • Auth & SessionLogin, session, BOLA — 15 checks
  • API SecurityJWT, GraphQL, shadow API — 16 checks
  • Compliance EvidenceSPF/DKIM, reputation — 10 checks
  • Web QualityAccessibility, SEO metadata — 2 checks
  • AI SecurityLLM canary probes — 10 checks
  • Cloud PostureAWS/Azure/GCP CSPM — 10 checks
  • Mobile SecurityOffline APK/IPA static analysis — 1 check
Create account

Developer

$39/mo

billed monthly

For builders who need repeatable checks before every release.

3verified targets
40scans / month
150URLs per scan
Weeklyautomated scheduling
JSONexport format

Scan packages included

  • Basic HygieneHeaders, HTTPS, TLS, cookies, DNS — 15 checks
  • OWASP StarterCORS, XSS, SQLi indicators — 14 checks
  • Threat ReadinessWAF, rate-limit, DDoS — 8 checks
  • Auth & SessionLogin, session, BOLA — 15 checks
  • API SecurityJWT, GraphQL, shadow API — 16 checks
  • Compliance EvidenceSPF/DKIM, reputation — 10 checks
  • Web QualityAccessibility, SEO metadata — 2 checks
  • AI SecurityLLM canary probes — 10 checks
  • Cloud PostureAWS/Azure/GCP CSPM — 10 checks
  • Mobile SecurityOffline APK/IPA static analysis — 1 check
Choose Developer

Business

$249/mo

billed monthly

Everything in Team, plus consent-gated active penetration testing.

25verified targets
400scans / month
1000URLs per scan
2pentest engagements
Dailyautomated scheduling

All 10 passive packages — 101 checks — plus Pentest Basic (11 active probes)

  • Everything in TeamAll 101 non-destructive checks
  • Pentest BasicOWASP A01–A07 active probes — 11 checks, signed engagement required
  • White-label reportingAgency plan and above
  • Pentest AdvancedEnterprise plan — 9 checks
Choose Business

Agency

$549/mo

billed monthly

For agencies delivering security reviews across client sites.

60verified targets
900scans / month
1500URLs per scan
Dailyautomated scheduling
PDF + JSONexport formats

All 10 scan packages — 101 checks total

  • Basic HygieneHeaders, HTTPS, TLS, cookies, DNS — 15 checks
  • OWASP StarterCORS, XSS, SQLi indicators — 14 checks
  • Threat ReadinessWAF, rate-limit, DDoS — 8 checks
  • Auth & SessionLogin, session, BOLA — 15 checks
  • API SecurityJWT, GraphQL, shadow API — 16 checks
  • Compliance EvidenceSPF/DKIM, reputation — 10 checks
  • Web QualityAccessibility, SEO metadata — 2 checks
  • AI SecurityLLM canary probes — 10 checks
  • Cloud PostureAWS/Azure/GCP CSPM — 10 checks
  • Mobile SecurityOffline APK/IPA static analysis — 1 check
Choose Agency

Enterprise Pentest

$1299/mo

billed monthly

Active penetration testing with digital consent, CVSS reporting, and PoC evidence — for enterprise security teams.

Unlimitedverified targets
2000scans / month
2500URLs per scan
Dailyautomated scheduling
PDF + JSONexport formats

All 10 scan packages + active pentest

  • All 10 passive packagesEvery check from Basic Hygiene through Mobile Security
  • Pentest BasicActive OWASP A01–A07 probes — SQLi, XSS, XXE, path traversal, auth bypass, IDOR, BFLA
  • Pentest AdvancedActive OWASP A03–A10 — command injection, SSRF, header injection, file upload bypass, mass assignment, deserialization, business logic
  • CVSS scoring & PoC evidenceConfirmed findings include CVSS score, vector, and request/response proof
  • Digital consent workflowSOW + Rules of Engagement with time-bounded, auditable engagement consent
  • Emergency pause & scope controlHard URL scope enforcement, per-scan request budget, instant kill switch
Choose Enterprise

One subscription

Seven surfaces in a single scan

Covering this much ground usually means buying separate tools for web, API, and cloud — each priced on its own, often per asset. Breakmesh includes all of it from the Team plan, with no per-asset add-on pricing.

Plus 2 web-quality evidence checks (accessibility and SEO metadata) for agency reporting — 101 non-destructive checks in total, with 20 consent-gated active pentest probes available on Agency and Enterprise.

We scope deliberately: no source-code analysis, no dependency-repo scanning, no infrastructure-as-code. Those need access to your code or infrastructure and are a different product — Breakmesh is the external layer, and complements them.

Full comparison

See exactly what's in every plan

Every check is non-destructive and runs only on targets you own and verify.

Free Developer
$29/mo
Team
$99/mo
Agency
$249/mo
Enterprise
$499/mo
Usage limits
Verified targets 1 3 25 Unlimited
Scans per month 20 100 2,000 10,000
URLs per scan 50 50 1,000 1,000
Workflow & delivery
Scheduling Manual only Weekly auto Daily + priority queue Daily + priority queue
Report formats JSON JSON PDF + JSON PDF + JSON + Pentest
White-label PDF reports
Multi-user workspace Admin + Analyst roles Admin + Analyst roles
Webhooks & API access CI/CD integration CI/CD integration
Active penetration testing
Pentest Basic OWASP A01–A07
Show probes
  • SQL Injection (error-based + blind)
  • Reflected & Stored XSS
  • XXE Injection (OOB callback + error-based)
  • Path Traversal
  • Open Redirect
  • Auth Bypass
  • IDOR Probe
  • Broken Function Level Auth
  • HTTP Parameter Pollution (HPP)
With consent
Pentest Advanced OWASP A03–A10
Show probes
  • Command Injection (timing)
  • SSRF Callback
  • Header Injection (Host header reflection)
  • File Upload Bypass (dangerous extension / double extension)
  • Mass Assignment
  • Insecure Deserialization (timing)
  • Business Logic — price manipulation
  • HTTP Request Smuggling / Desync Readiness
  • Web Cache Poisoning Readiness
With consent
CVSS scores & PoC evidence
Digital consent workflow (SOW + RoE)
Emergency pause & scope enforcement
Passive scan packages
Basic Hygiene 15 checks
Show checks
  • Security Headers
  • HTTPS Redirect
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • HSTS Strength
  • Mixed Content Detection
  • Sitemap and Robots Exposure
  • DNS Basics
  • Open Risky Ports
  • Cookie Security
  • Server Header Disclosure
  • Error Disclosure
  • HTTP/2 and HTTP/3 Support
  • Service/Version CVE Hints (Advisory)
OWASP Starter 14 checks
Show checks
  • CORS Policy
  • CORS Edge Cases (null origin / preflight)
  • Open Redirect
  • Directory Listing
  • Sensitive Files
  • Secrets in JavaScript Bundles
  • CSP Quality Review
  • Trusted Types Signal
  • Source Map Exposure
  • Deprecated Browser APIs
  • Harmless Reflected XSS Indicators
  • Safe SQL Injection Indicators
  • SSTI Template Injection Indicator
  • Error Disclosure Expansion
Threat Readiness 8 checks
Show checks
  • WAF/CDN Detection
  • WAF Harmless Canary Probe
  • Bot Protection Detection
  • Rate-Limit Readiness
  • DDoS Readiness Evidence
  • Origin Exposure Check
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
Auth & Session 15 checks
Show checks
  • Login Surface Controls
  • Session Cookie Scope
  • Login Rate-Limit Simulation
  • Password Reset Flow Checks
  • Account Enumeration Indicators
  • Credentialed Test-Account Checks
  • Weak Password Policy Review
  • MFA Configuration Indicators
  • Authenticated Deep Crawl
  • OAuth 2.0 / OIDC Security Checks
  • BOLA / IDOR Two-Account Comparison
  • BFLA Privilege Escalation Probe
  • CSRF Protection Enforcement
  • Session Fixation Check
  • Password Spray Indicator
API Security 16 checks
Show checks
  • API Documentation Exposure
  • HTTP Method Exposure
  • Versioned Endpoint Discovery
  • Endpoint Auth Indicators
  • Excessive API CORS Checks
  • Sensitive Response Pattern Detection
  • API Rate-Limit Readiness
  • API Third-Party Dependency Inventory
  • JWT Weakness Detection
  • GraphQL Introspection Exposure
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • Shadow API Discovery
  • WebSocket Security Check
  • Subresource Integrity (SRI) Missing
  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
Compliance Evidence 10 checks
Show checks
  • Security Contact Evidence
  • Privacy and Terms Evidence
  • Cookie Consent Mechanism
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Mail Security SPF/DKIM/DMARC
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Availability Status Evidence
  • Blocklist and Reputation Checks
  • GDPR/CCPA Data Subject Rights
Web Quality 2 checks
Show checks
  • Accessibility Evidence Snapshot
  • SEO and Social Metadata Evidence
AI Security 10 checks
Show checks
  • AI Endpoint Discovery
  • AI Prompt Reflection Check
  • AI System Prompt Exposure
  • Prompt Injection Indicator
  • AI Response Data Leakage
  • AI Endpoint Rate-Limit Readiness
  • Training Data Extraction Indicator
  • Model Extraction Risk Indicator
  • Content Moderation Bypass Canary Probe
  • Jailbreak Pattern Indicator
Cloud Posture 10 checks
Show checks
  • AWS Public S3 Storage Exposure
  • AWS Open Security Group Ingress
  • AWS IAM Stale Access Keys
  • AWS Overly-Permissive IAM Policies
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • Azure Public Blob Storage Exposure
  • Azure Open NSG Ingress Rules
  • GCP Public Cloud Storage Exposure
  • GCP Open VPC Firewall Ingress
Mobile Security 1 check
Show checks
  • Mobile App Static Analysis (APK/IPA) — offline, no network traffic
Sign up Get started Get started Get started

Safe by design

Built for authorized simulation

BreakMesh verifies target ownership, runs non-destructive checks, and keeps scan scope focused on customer-approved websites. No credentials are stored beyond the session.

Actionable output

Reports teams can act on

Every finding includes severity, confidence, evidence snippet, and remediation guidance so teams can go from scan result to fix in the same workflow.

Common questions

Can I cancel any time?

Yes. Paid plans are managed through Stripe, and your access remains active through the end of the billing period.

What happens if my payment fails?

Existing reports stay viewable, but new paid-plan scans are paused until billing is restored.

Do you scan without permission?

No. BreakMesh requires website ownership verification via a DNS TXT record before any scan runs.

What counts as a scan?

Each submitted scan package run counts as one scan against your monthly quota, regardless of how many checks are inside the package.

Can I run multiple packages on one target?

Yes — each package is run independently. Running all 10 passive packages on one target counts as 10 scans.

Is the AI Security package safe?

The AI Security package sends harmless canary strings only. It requires explicit consent and your confirmation that no tool-calling or agentic actions are enabled on the endpoint.