Who builds it, and why it works this way
Two security reviews that run where your code already lives: one goes through your codebase before a release, the other through your Salesforce build. Same answer on the same code, every time.
- Runs on your machine
- Same code, same verdict
- Published test method
- Licensed directly by our team
What we make_
Vulkro and Vulkro for Salesforce are the same job pointed at two subjects. Vulkro Red works out what an attacker would do with what the review found.

Licensed
Vulkro
Goes through every line before a release and tells you what a customer could exploit, with the path that proves it.
Learn more
Licensed
Vulkro for Salesforce
The same review for what your team built on Salesforce, plus the org settings, the way an AppExchange Security Review reads them.
Learn more
Coming soon
Vulkro Red
Works out what an attacker would do with it: which small problems chain into a real break-in, and which are noise.
Learn more
- Free tools for what enters your projectTwelve free commands that check packages, dependency files and agent tooling before it reaches your codebase. No account, nothing uploaded.Vulkro Labs →
One engine sits behind all of it, so the two reviews never check the same thing twice and nothing falls between them. Compare the two side by side if you are not sure which your team needs.
Why it exists_
None is new on its own. What is new is that all three are true at once in most teams that ship software.
- a review fast enough to run on every change
- an answer that only moves when the code moves
- an analysis that happens on the machine the code already sits on
- 01
Code is now produced faster than anyone reads it.
Review capacity is still people, still finite, and still the first thing dropped when a date slips. The cost of the gap is commercial: a vulnerability found by a customer, a regulator or an attacker is the one that sat on a laptop a month earlier, at a very different price.
- 02
A result you cannot reproduce cannot block a release.
A tool that returns a slightly different answer on the same code fails a build one morning for no reason anyone can explain, and the team switches it off within a week.
- 03
The review has to happen where the code is.
Approval to send source code to a third party is harder to win than the budget to buy the tool, so the review never gets run.
Vulkro answers all three in one product: a review fast enough to run on every change, an answer that only moves when the code moves, and an analysis that happens on the machine the code already sits on.
How it is built_
Each can be checked by the person who has to approve the tool.
- It runs where the code already isThe review happens on your machine, and everything it reads and writes stays there. One small call leaves, carrying licence and usage information only. Switch the product to offline and even that is refused.
- The same code gets the same answerNothing samples and no model decides whether a problem exists. Two runs of the same version over the same code return the same list, in the same order, on any machine. That is the only reason it is safe to put in front of a release.
- The method behind the figures is publishedThe engine that finds the problems is the licensed product and is not published. How its accuracy is measured is: what counts as a find, what counts as a false alarm, and the full list of what it missed.
What we publish_
Vulkro is scored against real applications whose vulnerabilities are already public. Here is that result.
33 of 83
Real vulnerabilities found
vulkro 0.28.0, measured 2026-09-18
- Source: vulkro 0.28.0
- Measured 2026-09-18

- 33 of 83 found
- 50 missed, published
- 20 false alarms
Every vulnerability in this test is a real, publicly documented bug in a real application, confirmed by reading the code at that exact version. The ones Vulkro cannot find stay in the test rather than being removed.
- 01
The engine is the product and is not published. Everything needed to check the claim is: which applications were tested, what counts as a find, what counts as a false alarm, and every vulnerability the product missed. A figure with no method behind it is marketing.
- 02
We also run a separate third-party suite we did not write, kept in its own frame rather than averaged into the headline. The full result, the scoring rules and the known weak spots are on the proof page.
How it is sold_
Evaluate the whole product before anyone talks to you, then a person quotes it.
- Fourteen days of the full product
- Two ways to buy
- Machines with no route out
- 01
Fourteen days of the full product
Install it, sign in once from the command line, and the trial starts on that machine. No card at sign-up, nothing to cancel, and nothing held back for the paid version.
- 02
Two ways to buy
Subscribe per seat from your account, self-serve, and cancel any time; or tell us how many seats and where the review runs and we quote per seat for teams and air-gapped machines.
- 03
Machines with no route out
A build host inside a regulated network gets a signed licence file issued against the machine itself, so it never reaches us at all.
When a licence or trial ends, nothing you produced disappears: reports, history and settings are already on your disk.
Contact_
No form and no chatbot in front of the inbox. Pick the address that matches the question.
- Licences and pricingSeats, renewals, offline licence files, and what a licence covers.license@vulkro.com
- Procurement and vendor reviewSecurity questionnaires, data-processing agreements, and anything your security team needs before a tool is installed.contact@vulkro.com
- Product supportInstall problems, a finding you think is wrong, and questions about what the product reported.support@vulkro.com
- Vulnerability reportsA security problem in Vulkro itself. Read the published policy first for scope and what to expect back.security@vulkro.com
- Invoices and billingPayment questions, licence transfers, and anything on an invoice.billing@vulkro.com
Evaluate it the way we built it: on your machine.
A 14-day trial of the full product. No card required. The account check verifies your entitlement online; it never sees your code.
Licensing and air-gapped deployment
Licences are per seat with everything included. Subscribe from your account and cancel any time, or ask our team for a quote. Air-gapped teams get a licence file that never calls home.