About
Vulkro is a security vendor built on one conviction: a vendor should prove its claims. We build deterministic security scanners that run entirely on your machine, give the same verdict on the same commit every run, and publish the benchmark methodology behind their accuracy numbers, with every catalogued bug pinned to a public advisory you can check.
What we ship
Two flagship scanners, equal peers, both local:
- Vulkro scans application code: endpoints, cross-file taint, secrets, dependencies, and infrastructure files.
- Vulkro for Salesforce scans the Salesforce platform: Apex, LWC, Aura, Flows, metadata, and Agentforce agents.
Around them:
- Vulkro Inspect reads code you did not write for author-planted malice before you run it. It reports what it finds and never certifies anything clean.
- Vulkro AI (local) is advisory assistance through local Ollama: it explains findings and drafts fixes, and it never changes a scan verdict.
- Vulkro Labs is 12 free, keyless commands that vet what enters your project.
The conviction
Security tooling for AI-written code has to be deterministic and local-first.
- Local-first. Scans run on your machine. Your code, file paths, and findings never leave it, and air-gapped operation is supported end to end.
- Deterministic. No AI decides a finding. The same commit gets the same verdict every run, which is what a CI gate and an auditor both need. Vulkro AI (local) stays advisory, and the benchmark is scored AI-free.
- Proven, not asserted. The detection engine is the licensed product and stays proprietary. The proof method and the complete benchmark results are public.
The proof
Every catalogued bug in the benchmark corpus is pinned to a public CVE or GHSA advisory in a real project, and a finding counts only within five lines of it. You can check any number against the advisory it cites.
On that corpus, Vulkro finds 47 of 83 catalogued bugs at 0.78 precision, drawing on 150+ checks. If a release regressed, the benchmark would show it, in your run as well as ours. The benchmark page walks through the methodology in full.
How we license
Vulkro is licensed per seat, directly through our team. The scanner requires an account, a 14-day trial of the full product starts on your first login, and licenses are set up by writing to [email protected]. There is no self-serve checkout: we work directly with every customer, and air-gapped environments get a license file that needs no network access. When a license or trial lapses, the CLI prints a one-line note and asks you to renew through us; your reports, scan history, and configuration stay on your machine.
Get in touch
- Security issues: [email protected] (see the security policy)
- Sales and partnerships: [email protected]
- Everything else: [email protected]