Introducing Vulkro Cloud for Salesforce
A Salesforce org is not a codebase you scan once before a release. It changes every week: a permission set edited in Setup, a connected app approved for a new integration, a sharing rule widened to unblock a deadline. None of that goes through a pull request, and most of it never reaches a repository.
Vulkro Cloud for Salesforce is a hosted workspace for keeping every org you run under continuous review. It is available by invitation today.
What it does
You connect your Salesforce orgs, read-only. Vulkro scans them on a schedule, each scan in its own isolated container, on the same engine as vulkro-sf. It reads settings, metadata, code, and user and login activity. It never reads your business records.
Each org gets one place to work from:
- Overview, led by Fix first. The posture of the org and the open issues that matter most, ranked by severity, with the attack path behind each one.
- Issues, kept across scans. Every finding of every kind in one list per org: posture, identity, integrations, personal data, code, tests and release readiness. Each issue has a stable key (
VK-123), a status, an assignee and the date it was first reported. - Attack paths. How an issue becomes access to data: from a guest user, an integration or an internal user, through permissions and code, to the object and field at the end.
- Identity and access, and exposure. Who holds what, which users and integrations can reach what, and what an anonymous visitor can reach on your sites.
- Changes and history. Every scan is kept. When a scan no longer finds an issue it is marked fixed on its own, and if it comes back it is reopened.
Built for a security team to work in
A security finding that nobody owns does not get fixed. Vulkro Cloud is built around the people who have to act on it.
- Triage with approval. Developers mark issues in progress or fixed straight away. A false positive or an accepted risk is a proposal until someone else approves it, and it stays counted until then.
- Rules you control. Every rule is listed, including the ones that have not fired. Make one advisory or turn it off for every org or only some files, and see who decided.
- Custom rules. Write policies on your org's users, permission sets, integrations and Health Check settings, or on your Apex, and test them on the latest scan before they go live.
- Roles. Owner, Admin, Security analyst, Developer admin, Developer, Auditor and Viewer, plus your own, with per-org scope.
- Notifications where you already work. Slack, Microsoft Teams, Jira (with the ticket status read back), PagerDuty, Google Chat, Discord, email and webhooks.
Each company gets its own workspace
Each company gets its own workspace at its own address, with its own database, storage and keys. Your code and org data stay in it.
Use it from the terminal and from AI coding agents
Vulkro Cloud is not another dashboard to keep open. Connect vulkro-sf to your workspace once, approved in the browser, and list what to fix, triage, fix and verify from the terminal. Or let your AI assistant do the same through the workspace's MCP tools and the Vulkro skill. The VS Code extension shows the same issue on the line of Apex that causes it.
Getting access
Vulkro Cloud for Salesforce is available by invitation while we onboard teams directly. Request access: the form takes about two minutes and we reply within two business days. Plans are on the pricing page, and you can see how the pieces fit together on the Cloud page.
