BreakMesh – Vulnerability Simulator & Cyber Range

What we check

Pick the checks that match what you run

There are 10 packages, each covering a different part of your setup: your website, your logins, the services your application depends on, your cloud account, your AI features or your mobile app. None of them alter or slow your site. Start with one and add others as you need them.

You always prove a website is yours before we scan it. Checks that need a login, a file you upload, or that push harder, ask for your permission separately.

10 Packages to choose from
102 Individual checks
Site + App + Cloud Covered in one place
2 Packages that prove the weakness

Standard packages

These read and test only. They never delete data, alter settings, or slow your site.

Your website and app

OWASP Starter

Non-destructive indicators for common web-application weaknesses including CORS, CSP, redirects, sensitive files, source maps and selected injection signals.

Verified domain Non-destructive

14 checks

View OWASP checks →

Threat Readiness

Review observable WAF/CDN, bot-protection, rate-limit, origin-exposure, subdomain and DDoS-readiness signals using controlled checks.

Verified domain Optional consent-gated probe

8 checks

View Threat Readiness →

Authentication & Session Security

Assess login controls, sessions, password-reset flows, OAuth/OIDC, CSRF, account-enumeration and authorization signals.

Verified domain Credentials optional

16 checks

View Auth & Session →

API Security

Assess API exposure, authentication, CORS, JWTs, GraphQL, rate limiting, shadow APIs and sensitive-response indicators.

Verified target Credentials / consent optional

16 checks

View API Security →

Cloud, AI, mobile and reporting

Compliance Evidence

Collect selected security, privacy, domain, email-security, reputation and availability evidence for customer and compliance reviews.

Verified domain Evidence collection

10 checks

View Compliance Evidence →

Cloud Posture Checks

Read-only AWS, Azure and GCP configuration checks for selected public-exposure, network, IAM, logging and encryption risks.

Read-only cloud credentials AWS · Azure · GCP

10 checks

View Cloud Posture →

AI Security

Consent-gated text-only canary probes for approved LLM and AI chat interfaces, covering selected prompt-injection, exposure, leakage and moderation indicators.

Explicit consent Text-only probes No agentic actions

10 checks

View AI Security →

Mobile Static Analysis

Offline static analysis of uploaded APK/IPA files for secrets, transport security, storage, exported components and sensitive permissions.

Uploaded APK / IPA Offline analysis

1 analysis workflow

View Mobile Analysis →
Additional assurance

Web Quality Evidence

Optional accessibility, SEO and social-metadata snapshots for agency and client reporting.

Agency reporting Assurance evidence

2 checks

View Web Quality →

Packages that prove the weakness

These go further and safely attempt the weaknesses they find, to establish which ones a real attacker could use. Nothing runs until you sign a short agreement setting out what may be tested, and for how long.

Pentest Basic

Consent-gated active probes for selected OWASP vulnerability classes including SQL injection, XSS, XXE, path traversal, authentication bypass, IDOR and BFLA.

Signed SOW + RoE Explicit consent

12 active probes

See plan availability →

Pentest Advanced

Additional active probes covering command injection, SSRF, unsafe deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks.

Signed SOW + RoE Explicit consent

9 active probes

See plan availability →

How you give us permission

Prove you own the site

One line of text in your domain settings. Needed before we scan any website.

Confirm in the app

For checks that sign in as a test user, or that probe your AI features.

Grant read-only access

For your cloud account. We can read your settings, never change them.

Upload your app file

For mobile apps. We inspect the file itself and send nothing anywhere.

Sign an agreement

Only for the packages that actively attempt the weakness. It sets the limits in writing.

What we do, and what we do not

We look at your systems the way someone outside would see them. We are not a replacement for tools that watch your code or your internal network.

BreakMesh focuses on

  • Your website, as the outside world sees it
  • Your logins and the services your app talks to
  • Settings left open in your cloud account
  • Your AI features, with your permission
  • Mobile app files you upload
  • Reports for customers and auditors

You will want other tools for

  • Reading through your source code
  • Watching for out-of-date libraries you depend on
  • Checking your server setup files
  • Endpoint protection on staff laptops
  • Monitoring your internal office network

Start with a baseline

Ready to see where you stand?

The first package is free and takes about two minutes. Add the others as you need them.