Skip to main content
By invitationVulkro Cloud for Salesforce, the hosted workspace for your team

Continuous security review of your whole Salesforce org

Vulkro Cloud reads every org end to end: who can sign in and what each user holds, what a guest or an integration can reach, the settings, the personal data and the code. It scans on your schedule, keeps one owned list of issues and shows what changed since the last scan.

Available by invitation. We reply within two business days.

  • <name>.vulkro.comYour company’s own workspace, at its own address.
  • Its own databaseAnd its own storage and keys. Your code and org data stay in it.
  • A container per scanEvery scan runs isolated, and several orgs scan in parallel.
  • Read onlyOrgs connect read-only. Vulkro never changes an org.
acme.vulkro.comWorkspace · 4 orgs
Posture81/100+9 since last scan
Open issues376 fixed · 2 new
Attack paths31 reaches personal data
Fix firstranked by reach and severity
  1. 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
  2. 2VK-188Integration user holds Modify All DataIdentityHigh
  3. 3VK-231Connected app allows all users, no IP rangeExposureHigh
  4. 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
Changes5 Oct compared with 28 Sep: 6 fixed, 2 new, 1 reopened

01The problem

A code scan covers one of the eight layers of an org

Code is one row of a Salesforce org. The access, exposure, integrations and settings around it are where the recent attacks came in, and where Vulkro Cloud looks on every scan.

  1. 01Most of an org’s risk is set in Setup, not written in code: who holds Modify All Data, what a guest can read, which apps are authorised.
  2. 02A review is a snapshot. A permission set edited on Tuesday is not in last quarter’s report.
  3. 03Several orgs mean several reviews, and nobody owns the gaps between them.

02Why now

Recent Salesforce data thefts came through org access settings

Connected apps, agent actions and guest users: each attack used access an org had already granted. Pick one to see what Vulkro flags and where the workspace shows it.

How Salesforce orgs get breached

What happened

The FBI’s alert describes voice phishing that got malicious connected apps authorised in Salesforce orgs, and OAuth tokens stolen from a third-party integration.

The weaknessConnected apps any user could authorise, and integration access with broad scope and no IP restriction.

FBI FLASH alert (Sep 2025)

What Vulkro flags

Vulkro for Salesforce flags authorised apps that match published malicious app names, logins that match published campaign indicators, and broad-scope OAuth apps with no IP restriction (live-org checks, part of Pro).

  • SF-OAUTH-IOC-002
  • SF-OAUTH-IOC-001
  • SF-OAUTH-APP-002

Where Vulkro Cloud shows itApps & Integrations, under OAuth Risk, and Activity & Monitoring, under Login History.

03More than code analysis

What Vulkro Cloud shows for each org

Pick an area to see what the workspace shows for every live org, and real checks behind it. Filter by whether a check reads the org or the code.

Vulkro Cloud documentation

Identity and access

Every user, what each one actually holds, and the admins and integrations that hold too much.

In the workspace

  • Users
  • Permissions
  • Sharing & Roles
  • Access Review
  • Access Graph

Example checks

  • Over-privileged profile or permission setSF-PERM-001OrgHigh
  • Permission set group adds up to full data accessSF-PSG-COMPOSITION-001OrgHigh
  • Dormant administrator accountSF-PERM-002OrgHigh
  • Integration user on an admin profileSF-INTEG-USER-001OrgHigh

How it works

  1. 01ConnectAuthorise a read-only connection for each org. No package is installed, and you can disconnect at any time.changes Vulkro makes to an org
  2. 02ScanDaily, weekly or monthly at a time and time zone you choose, or on demand. Several orgs scan in parallel.checks in the catalogue Vulkro Cloud shares with Vulkro for Salesforce: 147 org, 606 code
  3. 03WorkEach issue has a key, an owner and a status. Accepted risk waits for a second person. A fixed issue closes on the next scan.issue list per org, kept across every scan

Counts: vulkro-sf checks, vulkro-sf 0.22.1.

04An isolated tenant

Each company gets its own isolated tenant

A tool that holds your org’s weak spots has to be the most careful system you run. Each company gets a workspace of its own, and every scan runs in its own container. Pick a part to see what it means.

How Vulkro Cloud is built

Your own workspaceEach company gets its own workspace at its own address, https://<name>.vulkro.com. Your code and org data stay in it.

  • Sign-in rulesRequired MFA, allowed email domains, network limits and session timeouts for the workspace.
  • RolesOwner, Admin, Security analyst, Developer admin, Developer, Auditor and Viewer, or your own, with per-org scope.
  • Data retention and exportSet result retention, mask personal data, export the workspace or delete it, and export the activity log.
  • Support accessTime-limited, and only when you grant it.

05How your team works issues

Issues go to Slack, Jira and the tools your team already uses

An issue found in production reaches its owner in the channel they already watch, is fixed where code is written, and is closed by the next scan. Follow one issue through.

Your Salesforce

  • acme-prodProduction
  • acme-uatSandbox
  • acme-partnerExperience Cloud

Read-only. Settings, metadata, code.

Vulkro Cloud

acme.vulkro.com

  • Posture and Fix first
  • Issues, kept across scans
  • Attack paths
  • Identity & access, exposure
  • Changes and history
VK-214Open

Editor

VS Code extension

Findings on the line, as you write Apex, LWC, Aura, Visualforce and Flow.

VS Code · Cursor · Windsurf

Terminal and CI

vulkro-sf

Scan the project, audit an org, gate the deploy, work the workspace list.

macOS · Linux · Windows

MCP and skill

AI coding agents

Assistants ask for a check, read the path, fix and verify.

Claude Code · Cursor · Codex · Copilot

Your team's tools

  • Slack
  • Microsoft Teams
  • Jira
  • PagerDuty
  • Google Chat
  • Discord
  • Email
  • Webhooks

Production, sandboxes and Experience Cloud orgs are scanned in parallel, read-only: settings, metadata and code, never records.

Where alerts and tickets go

Posts to a Slack channel through an incoming webhook.

From the terminal and your assistant

terminal
# connect once, approved in the browser
$ vulkro-sf cloud connect https://<name>.vulkro.com
# what to fix, ranked
$ vulkro-sf cloud todo
# let your assistant work the same list
$ claude mcp add vulkro-sf -- vulkro-sf mcp serve

06Questions

Common questions about connecting a production org

Running scans on one machine instead? Vulkro for Salesforce has its own local console.

Vulkro for Salesforce
Does Vulkro Cloud read our customer records?
No. It reads settings, metadata, code, and user and login activity through a read-only connection. Accounts, contacts, cases and other business records are never read.
Is our data kept apart from other customers?
Yes. Each company gets its own workspace at its own address, with its own database, storage and keys, and every scan runs in an isolated container. Your code and org data stay in your workspace.
Do we need to install anything in our org?
No package is installed. You authorise a read-only connection, and you can disconnect the org at any time; its history is kept, read only.
Is it the same engine as Vulkro for Salesforce?
Yes. An issue in Vulkro Cloud comes from the same finding, with the same rule, as in the CLI and the editor, and developers can work the list from the terminal or their AI assistant.
How do we get access?
Vulkro Cloud for Salesforce is available by invitation while we onboard teams directly. Request access and we reply within two business days.

Put every Salesforce org under continuous review.