Legal
Terms of Service
Last updated: 13 September 2026 · Version 1.3
These Terms of Service ("Terms") govern your use of the BreakMesh platform and related services ("Service") provided by Alphasoft Infotech Private Limited, a company incorporated in India (CIN U72900PN2021PTC204451), trading as "BreakMesh" ("BreakMesh", "we", "us", or "our").
1. Agreement
By creating an account, purchasing or using the Service, or accepting an Order Form, Statement of Work, or similar agreement, you ("Customer", "you", or "your") agree to these Terms.
If you use BreakMesh on behalf of a company or other organisation, you confirm that you have authority to bind that organisation to these Terms.
The Service is intended for business and professional security-testing purposes.
You must be at least 18 years old and legally capable of entering into a binding agreement.
2. Authorised security testing only
BreakMesh is designed for legitimate and authorised security testing.
You may only scan, assess, or test systems that you own, control, or have permission to test.
You are responsible for obtaining all permissions necessary for the testing you request, including permissions required from customers, system owners, hosting providers, cloud providers, or other third parties.
By starting an assessment, you authorise BreakMesh to access and test the selected target within the scope you configure or otherwise approve.
BreakMesh may use technical verification, credentials, consent records, Rules of Engagement, or other reasonable methods to verify authority or scope.
These controls do not replace your responsibility to obtain proper permission.
We may request reasonable evidence of authorisation where necessary.
3. Responsible use
You must comply with the BreakMesh Responsible Use Policy.
You must not:
- use the Service against systems you are not authorised to test;
- intentionally exceed an authorised testing scope;
- use the Service to unlawfully access, damage, disrupt, or interfere with systems;
- bypass BreakMesh security, scope, rate-limit, or authorisation controls;
- provide false or misleading information about your authority to test a target;
- share credentials or API keys with unauthorised persons;
- reverse engineer the Service except where applicable law expressly permits it;
- systematically use non-public BreakMesh technology or outputs to develop or materially improve a directly competing security-scanning service without our written consent; or
- resell or sublicense the Service unless your plan or written agreement permits it.
Agency plans and other eligible plans may be used to assess authorised customer environments and provide reports to those customers.
4. Active Pentest
Certain testing methods, including Active Pentest or other elevated testing, may require additional authorisation and a Rules of Engagement ("RoE"), Statement of Work ("SoW"), or equivalent approval before testing begins.
You must comply with the approved scope and testing conditions.
If an applicable RoE or SoW conflicts with these Terms regarding the scope or execution of a particular engagement, the RoE or SoW controls for that engagement.
5. Accounts
You are responsible for protecting your account credentials, API keys, and authentication methods.
You are responsible for activity performed through accounts you authorise.
You must notify BreakMesh promptly if you believe your account or credentials have been compromised.
6. Plans, billing, and wallet credits
Current plans, features, usage limits, and prices are shown on the BreakMesh Pricing page or in an applicable Order Form.
Paid subscriptions renew for the billing period shown at checkout unless cancelled.
Before payment, the applicable price, billing frequency, and renewal terms will be displayed.
You may cancel a subscription at any time.
Unless otherwise required by law or agreed in writing, your paid plan remains active until the end of the current billing period and payments already made are non-refundable.
Purchased wallet credits do not expire while your account remains active unless clearly stated otherwise before purchase.
Wallet credits:
- may be used only for eligible BreakMesh services;
- have no cash value outside BreakMesh;
- may not be transferred between unrelated accounts without our approval; and
- are normally non-refundable.
If BreakMesh permanently closes an otherwise compliant account for reasons not caused by Customer, we will refund any unused purchased wallet credits.
Promotional, bonus, trial, or complimentary credits are not refundable.
Fees are exclusive of applicable taxes unless stated otherwise.
We may change prices, features, or usage limits by giving reasonable notice before a material change applies to an existing paid subscription.
7. Customer Data, reports, and intellectual property
You retain your rights in information and content you provide to BreakMesh ("Customer Data").
You give BreakMesh permission to process Customer Data as reasonably necessary to provide, operate, secure, and support the Service.
You may use, download, reproduce, and share reports and assessment results generated for you for legitimate business purposes, including security, remediation, compliance, audit, governance, and risk-management purposes.
If your plan includes agency, client-reporting, or white-label functionality, you may provide reports to customers for whom you were authorised to perform the assessment.
BreakMesh retains all rights in the Service and its underlying technology, including its:
- software;
- scanner logic;
- algorithms;
- assessment methodologies;
- templates;
- interfaces;
- documentation; and
- trademarks.
Your right to use or share a report does not transfer ownership of the underlying BreakMesh technology used to create it.
8. Confidentiality
Each party will protect the other party's confidential information using reasonable care and will use it only for purposes connected with the Service.
Customer confidential information includes non-public:
- targets;
- credentials;
- infrastructure details;
- scan configurations;
- vulnerabilities and findings;
- evidence;
- reports; and
- Customer Data.
BreakMesh confidential information includes non-public technology, security information, documentation, methodologies, and commercial information.
Confidentiality obligations do not apply to information that:
- is already public through no breach of these Terms;
- was lawfully known without confidentiality restrictions;
- was independently developed without use of the confidential information; or
- was lawfully received from another source without confidentiality restrictions.
A party may disclose confidential information where required by law.
Where legally permitted, the receiving party will provide reasonable notice before making such disclosure.
9. Privacy and data processing
Our handling of personal data is described in the BreakMesh Privacy Policy.
Where BreakMesh processes personal data on Customer's behalf in connection with Customer-directed assessments or other applicable activities, the BreakMesh Data Processing Agreement ("DPA") applies.
Customer is responsible for having the rights, authority, permissions, and lawful basis necessary for personal data it instructs BreakMesh to process.
If the DPA conflicts with these Terms specifically regarding processing of personal data on Customer's behalf, the DPA controls.
10. Third-party services
The Service may integrate with third-party services.
If you enable an integration, you authorise BreakMesh to exchange the information reasonably necessary to provide that integration.
Third-party products and services may be subject to their own terms and privacy policies.
BreakMesh is not responsible for third-party services outside our reasonable control.
11. Security-testing risks and service availability
Security testing cannot identify every vulnerability.
A successful scan does not mean that a system is completely secure.
Assessment results may include false positives, false negatives, or recommendations requiring further validation.
Security testing involves interacting with target systems in ways that may differ from normal application use.
Some testing, particularly active penetration testing, may cause instability, interruption, or unexpected effects on vulnerable systems.
You are responsible for considering these risks before testing production or other sensitive systems.
BreakMesh may pause or stop an assessment if we reasonably believe continued testing could create a material:
- security risk;
- legal risk;
- availability risk;
- operational risk; or
- risk of exceeding authorised scope.
We do not guarantee uninterrupted or error-free availability of the Service.
12. Disclaimer and limitation of liability
Except as expressly agreed in writing, the Service is provided "as is" and "as available."
To the maximum extent permitted by applicable law, BreakMesh does not guarantee that the Service will:
- identify every vulnerability;
- identify every issue accurately;
- make a system secure; or
- satisfy every security, compliance, audit, certification, regulatory, contractual, or insurance requirement.
To the maximum extent permitted by applicable law, neither party will be liable for indirect, incidental, special, punitive, exemplary, or consequential damages, including loss of profits, revenue, goodwill, or anticipated savings.
BreakMesh's total liability arising from the Service or these Terms will not exceed the fees paid or payable by Customer to BreakMesh during the 12 months preceding the event giving rise to the claim.
For a claim relating solely to a free Service where Customer paid no fees, BreakMesh's total liability will not exceed INR 10,000.
Nothing in these Terms excludes or limits liability that applicable law does not permit to be excluded or limited.
13. Indemnification
You will indemnify and hold harmless BreakMesh, Alphasoft Infotech Private Limited, and their officers, employees, and contractors against third-party claims arising from:
- testing performed without required authorisation;
- your intentional use of the Service outside authorised scope;
- your unlawful use of the Service; or
- Customer Data that you did not have the right or authority to provide or instruct BreakMesh to process.
BreakMesh will provide reasonable notice and cooperation if such a claim arises.
14. Suspension and termination
You may stop using the Service or cancel your subscription at any time.
BreakMesh may suspend or restrict an account or assessment where reasonably necessary because of:
- suspected unauthorised testing;
- activity outside approved scope;
- security or operational risk;
- unlawful or abusive activity;
- fraud;
- non-payment; or
- material breach of these Terms.
Where reasonably possible, we will give you an opportunity to resolve the issue.
We may terminate access immediately where continued use creates a serious security or legal risk, involves deliberate unauthorised testing or fraud, or where termination is required by law.
When an account is terminated, access to the Service ends.
Customer Data will be retained or deleted according to our Privacy Policy, DPA, applicable retention practices, and legal requirements.
Any provisions that by their nature should continue after termination, including intellectual property, confidentiality, liability, indemnification, and governing law, will continue to apply.
15. Changes and governing law
We may update these Terms from time to time.
We will provide reasonable notice of material changes to registered customers through email, an account notification, or another appropriate method.
Where applicable law requires affirmative agreement to a material change, we will obtain it.
Otherwise, continued use of the Service after updated Terms become effective constitutes acceptance of the updated Terms to the extent permitted by applicable law.
These Terms are governed by the laws of India.
Subject to any mandatory rights or jurisdiction that applicable law does not permit the parties to waive, the courts at Nashik, Maharashtra, India will have exclusive jurisdiction over disputes relating to these Terms or the Service.
16. General and contact
These Terms, together with any applicable Order Form, RoE, SoW, DPA, and Responsible Use Policy, form the agreement governing your use of the Service.
If there is a conflict:
- an individually executed agreement or Order Form controls the commercial terms it expressly changes;
- an applicable RoE or SoW controls the scope and execution of the relevant Active Pentest engagement;
- the DPA controls matters relating to personal data processed on Customer's behalf; and
- these Terms otherwise apply.
If any provision of these Terms is found invalid or unenforceable, the remaining provisions will continue to apply.
Failure to enforce a provision does not waive the right to enforce it later.
Neither party is responsible for delays or failures caused by circumstances reasonably outside its control, except for payment obligations already due.
For legal or contractual questions, contact:
Alphasoft Infotech Private Limited
trading as BreakMesh
11, Vrindavan Shilp Apt
S. No. 30/34, Pipe Line Road
Nashik, Maharashtra 422001
India
Email: info@breakmesh.io