How Breka operates
You set the boundary.
Breka applies the pressure.
The engagement starts with one application and a written boundary. Breka operates from the outside, so repository access, cloud credentials, and installed software are not required.
New engagement
Targetapi.acme.io
Authorized byA. Marsh, S. Cole, M. Ito
StatusScope confirmed
Authorize
Define the applications, APIs, environments, accounts, testing intensity, and stop conditions. Breka begins only after ownership and permission are confirmed in writing.
Attack cycle
Reasoning acrossIdentities & workflows
Also coversBusiness logic
ObjectiveMeaningful outcome
Attack
Breka deploys autonomous attack agents to form and test hypotheses across identities, workflows, business logic, and trust boundaries. They share context and work toward meaningful objectives, not alert counts.
GET /v2/invoices/84120
role: viewer (lowest privilege)
response: 200 OK · cross-tenant read
Prove
Breka reports behavior it can reproduce. Your team receives the starting access, connected attack path, business consequence, supporting evidence, and remediation direction.
Retest
TriggerFix or product change
Path/v2/invoices/{id}
ResultFix confirmed
Return
After remediation or a relevant product change, Breka repeats affected paths, records the outcome, and continues from the knowledge already accumulated.
Every engagement operates within written scope and is overseen by Breka’s security team.