Skip to main content
Vulkro
Products
Platform
Vulkro Core
JS/TS, Python, Go, Java, PHP, C, C++: code, packages, secrets
Vulkro for Salesforce
Apex, LWC, Flows, permissions and the live org
Vulkro Cloud
Every Salesforce org under continuous review
Where you work
VS Code extension
The finding on the line, as you write it
AI coding agents
MCP server, skill and guard for AI coding agents
All features
Every capability, by product and plan
New
Vulkro Cloud for Salesforce
Available by invitation. Every org, scanned on a schedule, one list of what to fix first.
Request access →
Solutions
Application security
API security
Every endpoint, and what an attacker can reach
Supply chain and secrets
Packages, lockfiles and leaked keys
Release gating
Stop a vulnerable release in CI
AI-written code
Security findings for AI coding agents
Salesforce
AgentExchange Security Review
Pass the review in fewer rounds
Continuous org security
Scheduled scans of every Salesforce org
Guest user exposure
What an anonymous visitor can reach
By team
Developers
Security while you write the code
Security and compliance
Findings turned into audit evidence
Consultancies
Security for every client org
Air-gapped and regulated
Analysis that never leaves the network
Why now
Recent attacks and the EU laws that now apply
Recent attacks, the check that flags each root cause, and the EU laws that now require evidence.
Read the briefing →
Resources
Learn
Blog
Articles on attacks, attack paths and token use
Security research
Guides, methods and the benchmark
Documentation
Install, scan, integrate
Changelog
Every release, every change
Company
Why Vulkro
Attack paths with the proof behind them
About
Vulkro, a product of Reveriext
Partners
For Salesforce consultancies
Contact
Talk to the team
Briefing
The attacks of 2026 so far, and the checks that flag their root causes
Read the briefing →
Pricing
Sign in
Get started
Authors
Vulkro
19
Security research
Talk to us
Chat on WhatsApp
Email us
hello@vulkro.com