Skip to main content
New: Vulkro Cloud for Salesforce, a hosted workspace for your team. Available by invitation: register your interestView docs

vulkro compliance

Run a compliance evaluation against a profile. Each finding the security engine produced is mapped to the relevant control(s); unmet controls are listed with the citation that flags them, ready for an audit handoff.

Usage​

vulkro compliance . --profile soc2
vulkro compliance . --profile pci --format json

Flags​

FlagDescriptionDefault
--profile <NAME>One of owasp-asvs, pci, soc2, hipaa, nist-ssdf, iso27001, cis, cwe-top25.owasp-asvs
--format <FMT>Output format.table

What's mapped​

Every finding category emits a compliance_controls list. The same finding typically satisfies multiple frameworks - e.g. a CSRF detection maps to ASVS V13, OWASP A05:2021, PCI 6.5.9, and CIS 16.10 simultaneously.

The desktop console's Compliance tab renders pass/fail per control with direct links to the underlying findings, so an auditor can ask "show me how you meet PCI 6.5.7" and you can answer in one click.

Profiles​

ProfileCoverage
owasp-asvsASVS L1 + L2 chapters V1-V14
owasp-top10OWASP Top 10:2021 categories A01-A10
pciPCI-DSS 4.0 requirements 6, 11
soc2Trust Services Criteria CC6 (Logical Access), CC7 (System Operations)
hipaaSecurity Rule Sec.164.312
nist-ssdfSP 800-218 PS, PW, RV practices
iso27001Annex A.5, A.8, A.14
cisCIS Critical Security Controls v8
cwe-top25CWE Top 25 Most Dangerous

Vulkro is a product of Reveriext.

reveriext.com

Visit Reveriext