Basic Hygiene
Baseline checks for HTTPS, TLS, security headers, cookies, DNS and common internet-facing exposure signals.
15 checks
View Basic Hygiene →What we check
There are 10 packages, each covering a different part of your setup: your website, your logins, the services your application depends on, your cloud account, your AI features or your mobile app. None of them alter or slow your site. Start with one and add others as you need them.
You always prove a website is yours before we scan it. Checks that need a login, a file you upload, or that push harder, ask for your permission separately.
These read and test only. They never delete data, alter settings, or slow your site.
Basic Hygiene
Baseline checks for HTTPS, TLS, security headers, cookies, DNS and common internet-facing exposure signals.
15 checks
View Basic Hygiene →OWASP Starter
Non-destructive indicators for common web-application weaknesses including CORS, CSP, redirects, sensitive files, source maps and selected injection signals.
14 checks
View OWASP checks →Threat Readiness
Review observable WAF/CDN, bot-protection, rate-limit, origin-exposure, subdomain and DDoS-readiness signals using controlled checks.
8 checks
View Threat Readiness →Authentication & Session Security
Assess login controls, sessions, password-reset flows, OAuth/OIDC, CSRF, account-enumeration and authorization signals.
16 checks
View Auth & Session →API Security
Assess API exposure, authentication, CORS, JWTs, GraphQL, rate limiting, shadow APIs and sensitive-response indicators.
16 checks
View API Security →Compliance Evidence
Collect selected security, privacy, domain, email-security, reputation and availability evidence for customer and compliance reviews.
10 checks
View Compliance Evidence →Cloud Posture Checks
Read-only AWS, Azure and GCP configuration checks for selected public-exposure, network, IAM, logging and encryption risks.
10 checks
View Cloud Posture →AI Security
Consent-gated text-only canary probes for approved LLM and AI chat interfaces, covering selected prompt-injection, exposure, leakage and moderation indicators.
10 checks
View AI Security →Mobile Static Analysis
Offline static analysis of uploaded APK/IPA files for secrets, transport security, storage, exported components and sensitive permissions.
1 analysis workflow
View Mobile Analysis →Web Quality Evidence
Optional accessibility, SEO and social-metadata snapshots for agency and client reporting.
2 checks
View Web Quality →These go further and safely attempt the weaknesses they find, to establish which ones a real attacker could use. Nothing runs until you sign a short agreement setting out what may be tested, and for how long.
Pentest Basic
Consent-gated active probes for selected OWASP vulnerability classes including SQL injection, XSS, XXE, path traversal, authentication bypass, IDOR and BFLA.
12 active probes
See plan availability →Pentest Advanced
Additional active probes covering command injection, SSRF, unsafe deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks.
9 active probes
See plan availability →Prove you own the site
One line of text in your domain settings. Needed before we scan any website.
Confirm in the app
For checks that sign in as a test user, or that probe your AI features.
Grant read-only access
For your cloud account. We can read your settings, never change them.
Upload your app file
For mobile apps. We inspect the file itself and send nothing anywhere.
Sign an agreement
Only for the packages that actively attempt the weakness. It sets the limits in writing.
We look at your systems the way someone outside would see them. We are not a replacement for tools that watch your code or your internal network.
BreakMesh focuses on
You will want other tools for
Start with a baseline
The first package is free and takes about two minutes. Add the others as you need them.