Frequently asked questions
What is BreakMesh?
We check your website the way someone trying to break in would look at it, without breaking anything, and then give you a plain list of what is weak and how to fix it.
What actually happens when I run a scan?
You give us your web address and prove the site is yours by pasting one line of text into your domain settings. We then look for weak spots: old software, settings left open, ways to reach data that should be private. A couple of minutes later you get a list of what we found, sorted by how urgent it is, with the steps to fix each one.
Will this break or slow down my site?
No. The normal checks only look and test gently. They never delete data, change your settings, or send enough traffic to slow anything down. The more forceful tests are a separate product that stays switched off unless you sign an agreement turning it on.
I am not technical. Is this for me?
Yes. Every issue is written in ordinary language: what we found, why it matters, and what to change. If someone else built or looks after your site, you can forward the list straight to them — it tells them exactly what to do. You do not need to understand security to find out where you stand. If a word does come up that you have not met, we keep a plain-English list of them at /glossary.
Why do I have to prove I own the site?
So nobody can point us at a website they have nothing to do with. You paste one line of text into your domain settings — we show you exactly what and where — and that is it. Checks that use a login, or a file you upload, ask for your permission a different way instead.
What do I get at the end?
A list of what passed and what needs attention, sorted by urgency, with proof and fix steps for each item, plus how you compare with last time. You can download it as a PDF to send to a customer or an auditor, and agencies can put their own logo on it.
How is this different from what my hosting company does?
Hosting companies usually keep the server itself patched and running. That does not cover how your own site is built and configured — the settings, the logins, and what your pages give away. That is the part we look at.
Does this replace hiring a security firm?
Not entirely. We cover a lot, automatically and repeatedly, for a fraction of the cost. But if a customer or a regulation specifically requires a human expert to test your systems by hand, you will still need that. Many teams run us continuously and bring people in once a year.
How often should I run it?
Monthly suits most sites, and after any significant change to how your site works. Paid plans can run it automatically on a schedule so you do not have to remember.
Can I scan a site I do not own?
No, and this is not negotiable. You have to prove control of a website before we will touch it. Scanning someone else's systems without permission is illegal in most countries.
Can I export the report?
Yes. Every finished scan can be downloaded as a data file, and most paid plans can download a formatted PDF with your own branding on it.
Can I connect this to my own tools?
Yes, on agency plans and above. You can trigger scans from your own systems and have BreakMesh notify them automatically when a scan finishes.