BreakMesh – Vulnerability Simulator & Cyber Range

Pricing

Pick a plan that matches how much you need checking

Start free with one website. Move up when you have more sites to watch, want the checks to run on their own, or need the deeper tests.

Every plan works the same way. Bigger plans just cover more sites, run more often, and unlock more kinds of check.

Save 20% with annual billing. Applicable taxes/VAT are calculated at checkout.

No subscription needed

Just need a few package runs? Pay as you go.

Use wallet credit for eligible standard security and assurance package runs without a recurring subscription. Top up any amount — balances never expire.

Create a free account
₹95.74–₹478.70 Per standard package run
₹1914.80 Pentest Basic · per authorized probe run
₹3829.60 Pentest Advanced · per authorized probe run
View all 10 package rates
PackageWallet cost / run
Basic Hygiene₹95.74
OWASP Starter₹143.61
Threat Readiness₹143.61
Auth & Session₹191.48
API Security₹191.48
Compliance Evidence₹114.89
Web Quality Evidence₹191.48
AI Security₹191.48
Cloud Posture₹478.70
Mobile Static Analysis₹478.70
Pentest Basic₹1914.80
Pentest Advanced₹3829.60

Wallet prices are billed in USD; amounts above are converted to INR at the current exchange rate for display only. Active Pentest is not purchased on a per-run basis — Pentest Basic and Pentest Advanced engagements are quoted per authorized SOW; the rate above is the wallet-equivalent per confirmed engagement probe run.

Trying it out

Free

Free

No subscription required

For seeing what this finds on one website, before paying anything.

1verified target
10package runs / month
25URLs per run
Manualscheduling
JSONreport format
  • Basic Hygiene package (15 checks)
Start free

No credit card required

One person

Developer

₹2400/mo

₹28800 billed yearly · save ₹7200

For one developer looking after a few sites who wants to check them regularly.

3verified targets
40package runs / month
150URLs per run
Weeklyscheduling available
JSONreport format
  • Basic Hygiene + OWASP Starter packages
Choose Developer

A team that needs proof

Business

₹15200/mo

₹182400 billed yearly · save ₹45600

For when spotting weak points is not enough and you need to prove which ones are real.

25verified targets
400package runs / month
1000URLs per run
2active validation engagements
Dailyscheduling available
  • Everything in Team
  • Pentest Basic — 12 active probes
  • Signed SOW + Rules of Engagement
  • Emergency pause & scope controls
Choose Business

Working for clients

Agency

₹33600/mo

₹403200 billed yearly · save ₹100800

For agencies checking many client sites and sending branded reports to each of them.

60verified targets
900package runs / month
1500URLs per run
Dailyscheduling + priority queue
PDF + JSONreport formats
  • Everything in Business
  • White-label PDF reporting
  • API & webhooks
  • Priority queue
Choose Agency

Large organisation

Enterprise

₹79200/mo

₹950400 billed yearly · save ₹237600

For bigger security teams who need the deepest tests and control over who can run them.

250verified targets
2,000package runs / month
2,500URLs per run
Dailyscheduling + priority queue
PDF + JSONreport formats
  • Pentest Basic + Advanced — 21 active probes
  • CVSS + PoC evidence
  • Digital consent workflow, emergency pause & hard scope enforcement
Talk to Security Team

Standard coverage

Standard coverage across multiple security surfaces.

From Team onward, BreakMesh includes all ten standard security and assurance packages. Usage is governed by the target, URL and package-run limits of the selected plan.

Plus 2 web-quality evidence checks (accessibility and SEO metadata) for agency reporting — 102 non-destructive checks in total, with 12 consent-gated Pentest Basic active probes available on Business, Agency and Enterprise, plus 9 additional Pentest Advanced probes on Enterprise.

Usage limits, explained

What counts as a package run?

One package run means one selected scanner package executed against one target. Running all 10 standard packages once against 10 targets uses 100 package runs.

Example — Team

10 standard packages × 10 targets = 100 package runs

Team includes 150 package runs/month, so 50 package runs remain for follow-up or additional assessments.

Full comparison

See exactly what's in every plan

All standard package checks are designed to be non-destructive. Active Pentest is separate and requires explicit authorization under an approved engagement scope.

Free Developer
₹3000/mo
Team
₹7500/mo
Business
₹19000/mo
Agency
₹42000/mo
Enterprise
₹99000/mo
Usage limits
Verified targets 1 3 25 60 250
Package runs per month 10 40 400 900 2,000
URLs per run 25 150 1,000 1,500 2,500
Active engagements 2 5 15
Workflow & delivery
Scheduling Manual only Weekly auto Daily auto Daily + priority queue Daily + priority queue
Report formats JSON JSON PDF + JSON PDF + JSON PDF + JSON + Pentest
White-label PDF reports
Multi-user workspace Admin + Analyst roles Admin + Analyst roles Admin + Analyst roles
Webhooks & API access CI/CD integration CI/CD integration
Active Validation
Pentest Basic OWASP A01–A07 · 12 active probes
Show probes
  • SQL Injection (error-based + blind)
  • Reflected & Stored XSS
  • XXE Injection (OOB callback + error-based)
  • Path Traversal
  • Open Redirect
  • Auth Bypass
  • IDOR Probe
  • Broken Function Level Auth
  • HTTP Parameter Pollution (HPP)
With consent With consent With consent
Pentest Advanced OWASP A03–A10 · 9 additional active probes
Show probes
  • Command Injection (timing)
  • SSRF Callback
  • Header Injection (Host header reflection)
  • File Upload Bypass (dangerous extension / double extension)
  • Mass Assignment
  • Insecure Deserialization (timing)
  • Business Logic — price manipulation
  • HTTP Request Smuggling / Desync Readiness
  • Web Cache Poisoning Readiness
With consent
CVSS scores & PoC evidence
Digital consent workflow (SOW + RoE)
Emergency pause & scope enforcement
Standard security & assurance packages
Basic Hygiene 15 checks
Show checks
  • Security Headers
  • HTTPS Redirect
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • HSTS Strength
  • Mixed Content Detection
  • Sitemap and Robots Exposure
  • DNS Basics
  • Open Risky Ports
  • Cookie Security
  • Server Header Disclosure
  • Error Disclosure
  • HTTP/2 and HTTP/3 Support
  • Service/Version CVE Hints (Advisory)
OWASP Starter 14 checks
Show checks
  • CORS Policy
  • CORS Edge Cases (null origin / preflight)
  • Open Redirect
  • Directory Listing
  • Sensitive Files
  • Secrets in JavaScript Bundles
  • CSP Quality Review
  • Trusted Types Signal
  • Source Map Exposure
  • Deprecated Browser APIs
  • Harmless Reflected XSS Indicators
  • Safe SQL Injection Indicators
  • SSTI Template Injection Indicator
  • Error Disclosure Expansion
Threat Readiness 8 checks
Show checks
  • WAF/CDN Detection
  • WAF Harmless Canary Probe
  • Bot Protection Detection
  • Rate-Limit Readiness
  • DDoS Readiness Evidence
  • Origin Exposure Check
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
Auth & Session 16 checks
Show checks
  • Login Surface Controls
  • Session Cookie Scope
  • Login Rate-Limit Simulation
  • Password Reset Flow Checks
  • Account Enumeration Indicators
  • Credentialed Test-Account Checks
  • Weak Password Policy Review
  • MFA Configuration Indicators
  • Authenticated Deep Crawl
  • OAuth 2.0 / OIDC Security Checks
  • BOLA / IDOR Two-Account Comparison
  • BFLA Privilege Escalation Probe
  • CSRF Protection Enforcement
  • Session Fixation Check
  • Password Spray Indicator
API Security 16 checks
Show checks
  • API Documentation Exposure
  • HTTP Method Exposure
  • Versioned Endpoint Discovery
  • Endpoint Auth Indicators
  • Excessive API CORS Checks
  • Sensitive Response Pattern Detection
  • API Rate-Limit Readiness
  • API Third-Party Dependency Inventory
  • JWT Weakness Detection
  • GraphQL Introspection Exposure
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • Shadow API Discovery
  • WebSocket Security Check
  • Subresource Integrity (SRI) Missing
  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
Compliance Evidence 10 checks
Show checks
  • Security Contact Evidence
  • Privacy and Terms Evidence
  • Cookie Consent Mechanism
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Mail Security SPF/DKIM/DMARC
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Availability Status Evidence
  • Blocklist and Reputation Checks
  • GDPR/CCPA Data Subject Rights
Web Quality 2 checks
Show checks
  • Accessibility Evidence Snapshot
  • SEO and Social Metadata Evidence
AI Security 10 checks
Show checks
  • AI Endpoint Discovery
  • AI Prompt Reflection Check
  • AI System Prompt Exposure
  • Prompt Injection Indicator
  • AI Response Data Leakage
  • AI Endpoint Rate-Limit Readiness
  • Training Data Extraction Indicator
  • Model Extraction Risk Indicator
  • Content Moderation Bypass Canary Probe
  • Jailbreak Pattern Indicator
Cloud Posture 10 checks
Show checks
  • AWS Public S3 Storage Exposure
  • AWS Open Security Group Ingress
  • AWS IAM Stale Access Keys
  • AWS Overly-Permissive IAM Policies
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • Azure Public Blob Storage Exposure
  • Azure Open NSG Ingress Rules
  • GCP Public Cloud Storage Exposure
  • GCP Open VPC Firewall Ingress
Mobile Static Analysis 1 analysis workflow
Show checks
  • Mobile App Static Analysis (APK/IPA) — offline, no network traffic
Sign up Get started Get started Get started Talk to Security Team

Active Validation requires explicit authorization.

All standard package checks are designed to be non-destructive. Active Pentest is a separate testing mode that uses consent-gated active probes within an approved, time-bounded engagement.

Pentest Basic

12 active probes

Pentest Advanced

9 additional active probes

Authorization

Signed SOW + Rules of Engagement

Governance

Approved scope + time window + emergency pause

An Active Pentest engagement is one approved, time-bounded testing scope governed by its own SOW and Rules of Engagement, with its own target, URL, duration and probe-count limits set out in that engagement's scope document.

Designed to complement your internal security tools

BreakMesh is an application and security-assurance layer that complements source-code, repository and infrastructure-as-code tools. It does not replace specialist internal security tooling.

BreakMesh focuses on

  • Web application and external security posture
  • API and authentication indicators
  • Selected cloud-posture checks
  • Approved AI-interface testing
  • Uploaded mobile application analysis
  • Security and compliance-review evidence

Use specialist tools for

  • Source-code SAST
  • Repository dependency monitoring
  • Infrastructure-as-code analysis

Safe by design

Built for authorized testing

BreakMesh verifies target ownership, and all standard package checks are designed to be non-destructive and keep scope focused on customer-approved targets. Active Pentest is separate and requires explicit authorization under an approved engagement scope. No credentials are stored beyond the session.

Actionable output

Reports teams can act on

Every finding includes severity, confidence, evidence snippet, and remediation guidance so teams can go from scan result to fix in the same workflow.

Common questions

Can I cancel any time?

Yes. You can cancel a paid subscription at any time. Your plan remains active until the end of the current billing period.

What happens if my payment fails?

Existing reports stay viewable, but new paid-plan scans are paused until billing is restored.

Do you scan without permission?

No. BreakMesh requires explicit authorization before assessments run. Domain-based testing uses DNS verification; credentialed, file-based and active assessments use authorization appropriate to those workflows.

What counts as a package run?

Each execution of one selected scanner package against one target consumes one package run. Running all 10 standard packages against one target consumes 10 package runs.

Can I run multiple packages on one target?

Yes — each package is run independently. Running all 10 standard packages on one target counts as 10 package runs.

How does Active Pentest differ from standard scanning?

All standard package checks are designed to be non-destructive. Active Pentest is a separate, consent-gated testing mode that uses controlled active probes within an approved scope and engagement window.

Is the AI Security package safe?

AI Security uses controlled, text-only canary probes and requires explicit consent. Testing should only be enabled for approved endpoints where tool-calling or agentic real-world actions are disabled.

Is your pricing per-domain or per-page?

Per verified target, not per page. A single target's URL limit scales up to 2500 URLs per scan on Enterprise, so one target can represent a full authenticated application with many endpoints — not a single static page counted the way some per-target pricing implies.

Start with a baseline

Start with a baseline. Upgrade when you need more coverage.

Try Basic Hygiene on one verified target, then move to recurring application, cloud and active-validation workflows as your requirements grow.