Continuous security review of your whole Salesforce org
Vulkro Cloud reads every org end to end: who can sign in and what each user holds, what a guest or an integration can reach, the settings, the personal data and the code. It scans on your schedule, keeps one owned list of issues and shows what changed since the last scan.
Available by invitation. We reply within two business days.
- <name>.vulkro.comYour company’s own workspace, at its own address.
- Its own databaseAnd its own storage and keys. Your code and org data stay in it.
- A container per scanEvery scan runs isolated, and several orgs scan in parallel.
- Read onlyOrgs connect read-only. Vulkro never changes an org.
- 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
- 2VK-188Integration user holds Modify All DataIdentityHigh
- 3VK-231Connected app allows all users, no IP rangeExposureHigh
- 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
01The problem
A code scan covers one of the eight layers of an org
Code is one row of a Salesforce org. The access, exposure, integrations and settings around it are where the recent attacks came in, and where Vulkro Cloud looks on every scan.
- 01Most of an org’s risk is set in Setup, not written in code: who holds Modify All Data, what a guest can read, which apps are authorised.
- 02A review is a snapshot. A permission set edited on Tuesday is not in last quarter’s report.
- 03Several orgs mean several reviews, and nobody owns the gaps between them.
02Why now
Recent Salesforce data thefts came through org access settings
Connected apps, agent actions and guest users: each attack used access an org had already granted. Pick one to see what Vulkro flags and where the workspace shows it.
How Salesforce orgs get breachedWhat happened
The FBI’s alert describes voice phishing that got malicious connected apps authorised in Salesforce orgs, and OAuth tokens stolen from a third-party integration.
The weaknessConnected apps any user could authorise, and integration access with broad scope and no IP restriction.
FBI FLASH alert (Sep 2025)What Vulkro flags
Vulkro for Salesforce flags authorised apps that match published malicious app names, logins that match published campaign indicators, and broad-scope OAuth apps with no IP restriction (live-org checks, part of Pro).
SF-OAUTH-IOC-002SF-OAUTH-IOC-001SF-OAUTH-APP-002
Where Vulkro Cloud shows itApps & Integrations, under OAuth Risk, and Activity & Monitoring, under Login History.
03More than code analysis
What Vulkro Cloud shows for each org
Pick an area to see what the workspace shows for every live org, and real checks behind it. Filter by whether a check reads the org or the code.
Vulkro Cloud documentationIdentity and access
Every user, what each one actually holds, and the admins and integrations that hold too much.
In the workspace
- Users
- Permissions
- Sharing & Roles
- Access Review
- Access Graph
Example checks
- Over-privileged profile or permission set
SF-PERM-001OrgHigh - Permission set group adds up to full data access
SF-PSG-COMPOSITION-001OrgHigh - Dormant administrator account
SF-PERM-002OrgHigh - Integration user on an admin profile
SF-INTEG-USER-001OrgHigh
How it works
- 01ConnectAuthorise a read-only connection for each org. No package is installed, and you can disconnect at any time.changes Vulkro makes to an org
- 02ScanDaily, weekly or monthly at a time and time zone you choose, or on demand. Several orgs scan in parallel.checks in the catalogue Vulkro Cloud shares with Vulkro for Salesforce: 147 org, 606 code
- 03WorkEach issue has a key, an owner and a status. Accepted risk waits for a second person. A fixed issue closes on the next scan.issue list per org, kept across every scan
Counts: vulkro-sf checks, vulkro-sf 0.22.1.
04An isolated tenant
Each company gets its own isolated tenant
A tool that holds your org’s weak spots has to be the most careful system you run. Each company gets a workspace of its own, and every scan runs in its own container. Pick a part to see what it means.
How Vulkro Cloud is builtYour own workspaceEach company gets its own workspace at its own address, https://<name>.vulkro.com. Your code and org data stay in it.
- Sign-in rulesRequired MFA, allowed email domains, network limits and session timeouts for the workspace.
- RolesOwner, Admin, Security analyst, Developer admin, Developer, Auditor and Viewer, or your own, with per-org scope.
- Data retention and exportSet result retention, mask personal data, export the workspace or delete it, and export the activity log.
- Support accessTime-limited, and only when you grant it.
05How your team works issues
Issues go to Slack, Jira and the tools your team already uses
An issue found in production reaches its owner in the channel they already watch, is fixed where code is written, and is closed by the next scan. Follow one issue through.
Your Salesforce
- acme-prodProduction
- acme-uatSandbox
- acme-partnerExperience Cloud
Read-only. Settings, metadata, code.
Vulkro Cloud
acme.vulkro.com
- Posture and Fix first
- Issues, kept across scans
- Attack paths
- Identity & access, exposure
- Changes and history
Editor
VS Code extension
Findings on the line, as you write Apex, LWC, Aura, Visualforce and Flow.
VS Code · Cursor · Windsurf
Terminal and CI
vulkro-sf
Scan the project, audit an org, gate the deploy, work the workspace list.
macOS · Linux · Windows
MCP and skill
AI coding agents
Assistants ask for a check, read the path, fix and verify.
Claude Code · Cursor · Codex · Copilot
Your team's tools
- Slack
- Microsoft Teams
- Jira
- PagerDuty
- Google Chat
- Discord
- Webhooks
One issue, end to end
Production, sandboxes and Experience Cloud orgs are scanned in parallel, read-only: settings, metadata and code, never records.
Where alerts and tickets go
Posts to a Slack channel through an incoming webhook.
From the terminal and your assistant
# connect once, approved in the browser $ vulkro-sf cloud connect https://<name>.vulkro.com # what to fix, ranked $ vulkro-sf cloud todo # let your assistant work the same list $ claude mcp add vulkro-sf -- vulkro-sf mcp serve
06Questions
Common questions about connecting a production org
Running scans on one machine instead? Vulkro for Salesforce has its own local console.
Vulkro for Salesforce