Skip to main content
New: Vulkro Cloud for Salesforce, a hosted workspace for your team. Available by invitation: register your interestView docs

SOC 2

Profile name: soc2

Vulkro covers the Trust Services Criteria that relate to application security:

  • CC6 - Logical and Physical Access Controls (subset relevant to apps)
  • CC7 - System Operations (subset relevant to apps)

Other TSCs (CC1 control environment, CC3 risk assessment, CC9 risk mitigation, A1 availability, and others) need organisational evidence that a static scanner cannot reach.

Run it​

vulkro compliance . --profile soc2

High-traffic mappings​

Vulkro finding categorySOC 2
BrokenAuthenticationCC6.1, CC6.6
BrokenObjectLevelAuthCC6.1, CC6.3
BrokenFunctionLevelAuthCC6.3
Hardcoded secretCC6.1
SecurityMisconfigurationCC6.6, CC7.1
Vulnerable dependencyCC7.1
Insecure loggingCC7.2
XSS / InjectionCC6.6

Audit-trail expectations​

SOC 2 reviewers will ask "how do you know this was true on the date of the report?". Vulkro's --save flag answers that: it persists every scan to ~/.vulkro/scans.db with timestamps and signed bundle versions. Pair vulkro scan --save with a daily cron job or a CI workflow.

Vulkro is a product of Reveriext.

reveriext.com

Visit Reveriext