Authorization differs by assessment type
Different assessment workflows use different authorization mechanisms — BreakMesh does not use DNS verification for every assessment.
Verified domain: domain-based website and application testing. Explicit consent: selected interactive and AI workflows. Read-only cloud credentials: AWS/Azure/GCP Cloud Posture. Uploaded artifact: APK/IPA Mobile Static Analysis. Signed SOW + Rules of Engagement: automated Active Pentest.
Scope controls
Standard assessments are constrained to verified target boundaries and do not follow off-scope redirects.
Private-network, localhost, link-local, and cloud metadata-endpoint access are all blocked to prevent internal network abuse.
Controlled concurrency, scan cooldowns, and bounded request behavior keep repeated scan activity from overwhelming a target or organization.
Designed to minimize production impact
Standard BreakMesh packages are designed to minimize production impact through non-destructive observations, controlled requests, scope restrictions, concurrency controls and cooldowns.
Standard scanning vs. Active Pentest
All standard package checks are designed to be non-destructive. Active Pentest is a separate testing mode that uses consent-gated automated active probes within an approved, time-bounded engagement.
Active Pentest is fully automated — no human pentester manually executes the supported Pentest Basic or Pentest Advanced probe set. It requires its own signed Statement of Work and Rules of Engagement before any probe runs.
What should I do if testing needs to stop?
Use Emergency Pause for Active Pentest. Pause or disable scheduled standard assessments. Contact BreakMesh support if unexpected target behavior continues.