Trying it out
Free
Free
No subscription required
For seeing what this finds on one website, before paying anything.
- Basic Hygiene package (15 checks)
No credit card required
Pricing
Start free with one website. Move up when you have more sites to watch, want the checks to run on their own, or need the deeper tests.
Every plan works the same way. Bigger plans just cover more sites, run more often, and unlock more kinds of check.
Save 20% with annual billing. Applicable taxes/VAT are calculated at checkout.
No subscription needed
Use wallet credit for eligible standard security and assurance package runs without a recurring subscription. Top up any amount — balances never expire.
| Package | Wallet cost / run |
|---|---|
| Basic Hygiene | ₹95.74 |
| OWASP Starter | ₹143.61 |
| Threat Readiness | ₹143.61 |
| Auth & Session | ₹191.48 |
| API Security | ₹191.48 |
| Compliance Evidence | ₹114.89 |
| Web Quality Evidence | ₹191.48 |
| AI Security | ₹191.48 |
| Cloud Posture | ₹478.70 |
| Mobile Static Analysis | ₹478.70 |
| Pentest Basic | ₹1914.80 |
| Pentest Advanced | ₹3829.60 |
Wallet prices are billed in USD; amounts above are converted to INR at the current exchange rate for display only. Active Pentest is not purchased on a per-run basis — Pentest Basic and Pentest Advanced engagements are quoted per authorized SOW; the rate above is the wallet-equivalent per confirmed engagement probe run.
Trying it out
Free
Free
No subscription required
For seeing what this finds on one website, before paying anything.
No credit card required
One person
Developer
₹3000/mo
billed monthly
For one developer looking after a few sites who wants to check them regularly.
A small team
Team Most popular
₹7500/mo
billed monthly
For a team with several sites and apps who want every safe check available.
A team that needs proof
Business
₹19000/mo
billed monthly
For when spotting weak points is not enough and you need to prove which ones are real.
Working for clients
Agency
₹42000/mo
billed monthly
For agencies checking many client sites and sending branded reports to each of them.
Large organisation
Enterprise
₹99000/mo
billed monthly
For bigger security teams who need the deepest tests and control over who can run them.
Standard coverage
From Team onward, BreakMesh includes all ten standard security and assurance packages. Usage is governed by the target, URL and package-run limits of the selected plan.
Plus 2 web-quality evidence checks (accessibility and SEO metadata) for agency reporting — 102 non-destructive checks in total, with 12 consent-gated Pentest Basic active probes available on Business, Agency and Enterprise, plus 9 additional Pentest Advanced probes on Enterprise.
Usage limits, explained
One package run means one selected scanner package executed against one target. Running all 10 standard packages once against 10 targets uses 100 package runs.
Example — Team
10 standard packages × 10 targets = 100 package runs
Team includes 150 package runs/month, so 50 package runs remain for follow-up or additional assessments.
Full comparison
All standard package checks are designed to be non-destructive. Active Pentest is separate and requires explicit authorization under an approved engagement scope.
| Free | Developer ₹3000/mo |
Team ₹7500/mo |
Business ₹19000/mo |
Agency ₹42000/mo |
Enterprise ₹99000/mo |
|
|---|---|---|---|---|---|---|
| Usage limits | ||||||
| Verified targets | 1 | 3 | 10 | 25 | 60 | 250 |
| Package runs per month | 10 | 40 | 150 | 400 | 900 | 2,000 |
| URLs per run | 25 | 150 | 500 | 1,000 | 1,500 | 2,500 |
| Active engagements | – | – | – | 2 | 5 | 15 |
| Workflow & delivery | ||||||
| Scheduling | Manual only | Weekly auto | Daily auto | Daily auto | Daily + priority queue | Daily + priority queue |
| Report formats | JSON | JSON | PDF + JSON | PDF + JSON | PDF + JSON | PDF + JSON + Pentest |
| White-label PDF reports | – | – | – | – | ✓ | ✓ |
| Multi-user workspace | – | – | ✓ Admin + Analyst roles | ✓ Admin + Analyst roles | ✓ Admin + Analyst roles | ✓ Admin + Analyst roles |
| Webhooks & API access | – | – | – | – | ✓ CI/CD integration | ✓ CI/CD integration |
| Active Validation | ||||||
Pentest Basic
OWASP A01–A07 · 12 active probes
Show probes
|
– | – | – | ✓ With consent | ✓ With consent | ✓ With consent |
Pentest Advanced
OWASP A03–A10 · 9 additional active probes
Show probes
|
– | – | – | – | – | ✓ With consent |
| CVSS scores & PoC evidence | – | – | – | – | – | ✓ |
| Digital consent workflow (SOW + RoE) | – | – | – | ✓ | ✓ | ✓ |
| Emergency pause & scope enforcement | – | – | – | ✓ | ✓ | ✓ |
| Standard security & assurance packages | ||||||
Basic Hygiene
15 checks
Show checks
|
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
OWASP Starter
14 checks
Show checks
|
– | ✓ | ✓ | ✓ | ✓ | ✓ |
Threat Readiness
8 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
Auth & Session
16 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
API Security
16 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
Compliance Evidence
10 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
Web Quality
2 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
AI Security
10 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
Cloud Posture
10 checks
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
Mobile Static Analysis
1 analysis workflow
Show checks
|
– | – | ✓ | ✓ | ✓ | ✓ |
| Sign up | Get started | Get started | Get started | Get started | Talk to Security Team | |
All standard package checks are designed to be non-destructive. Active Pentest is a separate testing mode that uses consent-gated active probes within an approved, time-bounded engagement.
Pentest Basic
12 active probes
Pentest Advanced
9 additional active probes
Authorization
Signed SOW + Rules of Engagement
Governance
Approved scope + time window + emergency pause
An Active Pentest engagement is one approved, time-bounded testing scope governed by its own SOW and Rules of Engagement, with its own target, URL, duration and probe-count limits set out in that engagement's scope document.
BreakMesh is an application and security-assurance layer that complements source-code, repository and infrastructure-as-code tools. It does not replace specialist internal security tooling.
BreakMesh focuses on
Use specialist tools for
Safe by design
BreakMesh verifies target ownership, and all standard package checks are designed to be non-destructive and keep scope focused on customer-approved targets. Active Pentest is separate and requires explicit authorization under an approved engagement scope. No credentials are stored beyond the session.
Actionable output
Every finding includes severity, confidence, evidence snippet, and remediation guidance so teams can go from scan result to fix in the same workflow.
Yes. You can cancel a paid subscription at any time. Your plan remains active until the end of the current billing period.
Existing reports stay viewable, but new paid-plan scans are paused until billing is restored.
No. BreakMesh requires explicit authorization before assessments run. Domain-based testing uses DNS verification; credentialed, file-based and active assessments use authorization appropriate to those workflows.
Each execution of one selected scanner package against one target consumes one package run. Running all 10 standard packages against one target consumes 10 package runs.
Yes — each package is run independently. Running all 10 standard packages on one target counts as 10 package runs.
All standard package checks are designed to be non-destructive. Active Pentest is a separate, consent-gated testing mode that uses controlled active probes within an approved scope and engagement window.
AI Security uses controlled, text-only canary probes and requires explicit consent. Testing should only be enabled for approved endpoints where tool-calling or agentic real-world actions are disabled.
Per verified target, not per page. A single target's URL limit scales up to 2500 URLs per scan on Enterprise, so one target can represent a full authenticated application with many endpoints — not a single static page counted the way some per-target pricing implies.
Start with a baseline
Try Basic Hygiene on one verified target, then move to recurring application, cloud and active-validation workflows as your requirements grow.