Features
Find, prove and fix vulnerabilities. Every feature, by product and plan.
capabilities that ship today. Free finds and fixes, with the proof behind every finding and no account. Pro maps the whole application and the live org. Vulkro Cloud runs it for a team.
Free 49 Pro 41 Cloud 21
The local console. Every finding, the proof behind it and its fix, in your browser. Everything runs on this machine, for application code and for Salesforce.
01What sets Vulkro apart
Attack paths, proof and checked fixes on your machine
Four things the catalogue below adds up to. Open one to see the evidence behind it.
Why VulkroVulkro joins who can reach the code, the entry point they use, the permission that allows it, the mode the code runs in and the data it touches. On Salesforce that means org configuration, permissions and code in one path, each step citing a file and line.
Evidence Attack graph in every vulkro-sf scan since 0.18.0; live-org facts added with an org alias (Pro)
Each finding is proven, unproven or not checked, with the data-flow steps behind it. The proof is never gated: Free shows the evidence for every finding, and Pro adds the whole-application map.
Evidence Capability registry: finding proof, prove and explain are Free
A proposed fix, deterministic or AI-drafted, is applied to a copy and scanned again. Only a patch that removes the finding without adding a new one is offered for you to apply.
Evidence Verified fixes in vulkro 0.30.0; verify_fix MCP tool; editor AI fixes re-scanned before they are offered
Analysis runs on your machine. One switch blocks every outbound call, vulnerability data updates from an offline file, and live-org reads use your own Salesforce CLI login, so no vendor holds a token.
Evidence Offline flag and VULKRO_OFFLINE; offline update files for air-gapped installs
02The catalogue
Search every feature that ships today
Filter by product, plan or category, or search. Press / to jump to the search box.
Find vulnerabilities 12
Detection across application code, Salesforce code and metadata, infrastructure files and AI tooling.
Application code scan
Finds injection, broken access control, leaked secrets and unsafe configuration in JavaScript, TypeScript, Python, Go, Java, PHP, C and C++.
One engine covers the languages most product teams ship, with the same results on a laptop and in CI.
CoreFreeAuthorization checks
Decides for each route whether it is authenticated, scoped to the caller and role-checked, and reports lookups by id with no ownership check.
Broken access control needs the route, the guard and the record together; a pattern match on one line cannot see it.
CoreFreeRoute inventory
Lists every endpoint, including MCP and AI agent tools, with its handler, full path and the guards that protect it.
You cannot secure a surface you have not listed, and this list comes from the code, not from documentation.
CoreFreeInfrastructure files
Checks Terraform, Kubernetes manifests, Helm charts and Dockerfiles in the same scan as the application code.
Misconfiguration in deployment files is often how a code flaw becomes reachable from outside.
CoreFreeDepth options
Opt-in packs for business logic, money handling, state machines and concurrency, a deep preset, and import of private rule packs.
Application-specific flaws and in-house rules run when you ask for them, in the same results and gate.
CoreProSalesforce code scan
Scans Apex, LWC, Aura, Visualforce, Flows and metadata in an SFDX project, or metadata alone from a retrieved org.
Security review starts before a change reaches an org, including in orgs built with clicks rather than code.
SalesforceFreeEffective sharing and access mode
Works out how each Apex class and method really runs, user or system mode, with or without sharing, along the call stack.
Record exposure depends on the mode code actually runs in, which inheritance and API version change.
SalesforceFreeCRUD and field-level security
Reports queries and DML that skip object and field checks, and recognises user mode, stripped fields and your own security helpers.
CRUD and FLS enforcement is a core Security Review requirement, and false alarms waste review cycles.
SalesforceFreeAgentforce review
Checks agent actions that take record ids from user input, act without confirmation, or pass model output into queries and DML.
An agent action is a new entry point, and prompt injection turns it into a data exfiltration path.
SalesforceFreeCustom rules
Write, scaffold, validate and test your own rules over Apex syntax, XML metadata or text, and load them in every scan.
Each org has its own policies, and they belong in the same scan as the built-in checks.
SalesforceFreeWell-Architected anti-patterns
Finds queries and DML in loops, hardcoded record ids, empty catch blocks and other Well-Architected anti-patterns in Apex.
Governor-limit and reliability problems cause production failures that look like security incidents.
SalesforceProCode findings and code health
Connects a git repository read-only and shows code findings, anti-patterns, flows, test coverage gaps on attack paths and release readiness.
Code risk sits next to org posture, so a path through untested Apex is visible in the same workspace.
CloudCloud
Attack paths and reach 11
Who can reach a flaw, through which entry point, with which permission, and what it touches.
Reachability
Tags each finding with whether an entry point reaches it, and can limit results or the build gate to reachable findings.
Unreachable code is real debt but rarely urgent; reach is what separates the two.
CoreFreeAttack paths
Maps every entry point to every sensitive sink across the whole application, in the console and the editor.
A list of findings says what is wrong; the map says which ones an attacker can actually chain.
CoreProImpact and code structure
Scores what a finding reaches, lists every entry point that leads to it, and maps modules, calls and layering.
Fixes that close the most exposure go first, and you see what depends on code before changing it.
CoreProData-flow map
Shows where outside data enters, what it passes through and where it ends up, including calls between your repositories.
Reviewers follow personal and untrusted data end to end, even when it crosses a service boundary.
CoreProAPI contract and access matrix
Generates an OpenAPI specification from the code and prints every endpoint against the login level it requires.
An accurate contract and one access table make an outlier endpoint visible in a single read.
CoreProExposure report
Summarises one application's entry points by authentication state, unauthenticated reach to sensitive code and proven Critical and High findings.
It answers what an anonymous attacker can reach, in a document you can hand to a reviewer.
CoreProSalesforce attack paths
Joins who can reach the code, the door they use, the grant, the access mode and the data touched, with an entry-point inventory.
A Critical finding comes with a path from a person to your data, each step citing a file and line.
SalesforceFreePaths checked against the live org
Reads who holds each profile and permission set, connected-app token use and what Salesforce ships, and re-ranks the paths.
A dangerous grant nobody holds is lowered and one held widely is raised, so priority matches the real org.
SalesforceProGuest exposure report
Per public site, shows what an unauthenticated visitor can read and run, with a verdict and fixes as Setup steps.
Guest access settings decide what anyone on the internet can read from the org.
SalesforceProBlast radius and org maps
Shows where a component is used, what breaks if it changes, deployment and merge risk, and maps automations, roles and personal data.
Deployments fail and leak through dependencies nobody remembered; this lists them before the deploy.
SalesforceProOrg attack paths
Paths, a graph, the attack surface, entry points, an access graph and per-site guest exposure, joining configuration, permissions and code.
The issues that form a path from an outsider to sensitive data are the ones to fix first.
CloudCloud
Salesforce org posture 13
Read-only audits of a live org: identity, permissions, integrations, sessions, sharing and activity.
Permissions and least privilege
Audits profiles, permission sets, groups and integration users for over-privilege, with per-user least-privilege recommendations.
Over-privileged users and integrations turn one compromised login into full data access.
SalesforceProConnected app and OAuth risk
Rates every connected app and External Client App by scope, policy and who authorised it, and lists recommended revocations.
A connected app holds a standing token into the org; the list is advice and nothing is revoked without you.
SalesforceProSessions, MFA and sharing
Checks MFA, long-lived sessions, login anomalies, IP restrictions, session timeouts and over-broad sharing rules.
Stolen sessions, weak login policy and wide sharing bypass every permission review.
SalesforceProThreat detection and forensics
Reads free event logs, login history and audit trails for activity to investigate, and captures a forensic snapshot for offline analysis.
Suspicious exports and logins are visible in logs most orgs never read, and incident evidence disappears if not taken.
SalesforceProGovernance checks
Checks backup configuration, Einstein Trust Layer settings, agent running users, folders open to portal users and credential rotation age.
These are the questions an auditor asks, answered from the org rather than from memory.
SalesforceProHealth Check, packages and configuration
Reads the Health Check score, installed packages, named credentials, domain, mail, limits, sandbox lag and trust status.
Configuration drift and unverified packages are quiet ways for an org to fall out of policy.
SalesforceProRecertification and trends
Produces access recertification worksheets, limits and coverage risk reports, masking rules, and posture trends between audits.
Periodic access reviews are a control requirement, and a generated worksheet makes them repeatable.
SalesforceProSandbox and production drift
Compares two orgs' metadata and reports components that differ or exist in only one, with finding ids a CI job can gate on.
A permission set that drifted between sandbox and production is where testing stops matching reality.
SalesforceFreeUsers, data and licences
Every user and what an attacker could do as them, sensitive fields and who can read them, login IPs and licence usage.
Access and data questions from auditors and responders get answered from one place.
CloudCloudAccess review campaigns
Least-privilege suggestions per user, review campaigns with assigned reviewers, keep, reduce or remove decisions and a CSV evidence export.
Periodic access reviews become a tracked process with evidence, and Salesforce is never changed by the tool.
CloudCloudApps and integrations
Connected and External Client Apps, OAuth tokens and risk, API usage, Agentforce, credentials, remote sites, CORS, packages and single sign-on.
Everything that connects into or out of the org is reviewed together, where token theft starts.
CloudCloudSuspicious activity
Keeps each scan's normalised event history, runs baseline rules over it, files detections as issues and alerts on new ones.
Spotting what is unusual needs history across scans; a single snapshot cannot show what is unusual.
CloudCloudPermission-set audit from the editor
Audits the configured org's permission sets for powers such as Modify All Data, through your own Salesforce CLI login.
A developer can check the org a change targets without opening another tool or sharing a token.
VS CodePro
Proof and accuracy 7
Evidence behind every finding, an honest account of what was not checked, and less noise.
Proof per finding
Every finding is proven, unproven or not checked, with the data-flow steps behind it and a severity set by who can reach it.
Reviewers spend time on findings with evidence, and that evidence is never behind a paywall.
CoreFreeExplain and proof tests
Explains a finding in your framework, and writes runnable test cases that demonstrate eligible injection and authorization findings.
The explanation matches your stack, and a failing test ends the argument about whether a finding is real.
CoreFreeCheck other tools' results
Takes another tool's SARIF results and marks each one proven, not provable with the reason, or not checked.
Teams with an existing scanner can sort its output by evidence instead of re-triaging every alert.
CoreFreeCoverage and why-not
Output says what the scan read and did not, and you can ask why nothing was reported at a file and line.
A clean result on code the scanner could not read is the most dangerous false negative.
CoreFreeFindings in Salesforce terms
Each finding says who can trigger it, the door, the access mode, the data flow and the fix in Salesforce idiom.
Admins and developers act on a sentence about their org, not on a generic rule name.
SalesforceFreePublished check catalogue
Lists every check with its id, category, default severity, what it looks for and why, and explains suspected misses.
Buyers and auditors see exactly what is covered before they rely on a clean result.
SalesforceFreeOrg read coverage
Org audits report whether each check read all, part or none of the org, instead of turning a failed read into no findings.
A clean audit you cannot trust is worse than no audit; the read coverage tells you which one you have.
SalesforcePro
Fixing 7
Concrete changes for each finding, checked by the detector before you accept them.
Fix patches
Prints a concrete patch and remedy per finding for common vulnerability classes, and applies a strict set of safe rewrites.
A ready patch in your own code turns a finding into a reviewable change instead of a ticket.
CoreFreeVerified fixes
Applies each proposed patch to a copy, scans again and keeps only patches that remove the finding without adding one.
The detector, not a model, decides whether a fix worked, and your working tree is untouched until you apply.
CoreFreeAI recommendations
Ask, hunt, explain and triage with a model you choose, local by default; every AI answer is labelled advisory.
AI helps with judgement calls while the deterministic result, its severity and the exit code stay unchanged.
CoreFreeReviewable fixes, verified AI drafts
Generates patches, Setup links and deploy scripts, and local-model Apex patches applied only when the detector confirms them.
Admins get the exact change to review, and nothing touches an org without a person deploying it.
SalesforceFreeHow to fix, per issue
Each issue shows the Setup link, the steps and a patch to download; a fix bundle covers many issues at once.
Admins without write access to a repository still get a precise, reviewable fix, and the org is never changed by Vulkro.
CloudCloudQuick fixes
The lightbulb offers suppress, explain and, for clear-cut patterns, a deterministic one-line fix you accept or reject.
Small, certain fixes take one keystroke, and nothing edits your file without your accept.
VS CodeFreeVerified AI fixes in the editor
A local model drafts a fix, offered only after a fresh scan confirms the finding is gone and the file parses.
You review a diff the detector has already checked, instead of trusting a model's claim.
VS CodeFree
Editor, CI and gates 16
Findings where developers work, and gates that fail a build on the right things.
CI gate and git hooks
Fails a build at a chosen severity with a fixed exit-code contract, writes SARIF and JSON, and installs commit and push hooks.
A gate that separates findings from tool errors never turns an infrastructure problem into a silent pass.
CoreFreeBaseline and shared triage
Saves today's findings as a baseline and keeps false-positive and accepted-risk decisions in one file the CLI, console and editor all read.
Triage decisions are reviewed in pull requests like code and never have to be made twice.
CoreFreeLocal console
The local console, in your browser on this machine, for browsing findings, proof and fixes on the active repository.
Not everyone who triages lives in a terminal, and nothing leaves the machine to get a visual view.
CoreFreeRelease gate on new findings
Fails a build only on findings new since a branch or commit, with a ratchet that never lets the count grow.
Teams can gate every pull request from day one without first paying down every existing finding.
CoreProPull-request comments
Posts findings as inline review comments and CI annotations on GitHub, GitLab, Bitbucket and Azure DevOps.
The finding appears on the changed line, where the author is already looking.
CoreProChange review and API diff
Shows findings on the lines a change touched, and which endpoints were added, removed or lost protection since a ref.
Reviewers see what this change introduced, including a new public endpoint that no rule fires on.
CoreProHistory, trends and hotspots
Keeps every scan, compares any two, shows how findings moved and which files the risk keeps returning to.
Leaders see whether risk is falling, and effort goes where findings keep recurring.
CoreProVulkro Cloud from the terminal
Connects the Salesforce CLI to your Vulkro Cloud workspace to work the ranked queue, triage, start cloud scans and confirm an issue is fixed.
Developers clear the team queue without leaving the terminal, and CI can gate on open issues in the workspace.
SalesforceCloudSalesforce local console
A local console that opens on exposure, review readiness, changes and findings, with a data access matrix and an Apex run-mode view.
Admins who do not live in a terminal get the same results, running on their own machine.
SalesforceFreePresubmit gate and metadata review
Fails a build only on new findings, and reports what a metadata change grants and to whom, on the pull request.
Teams gate every change without blocking on old debt, and permission changes get read as access.
SalesforceProChanges, history and compare
Keeps every scan, compares any two, shows what changed in each org, accepts a baseline and sends daily and weekly digests.
Seeing a risky change the next day beats finding it in a quarterly review.
CloudCloudVS Code, Cursor, Windsurf and VSCodium
One command installs the extension into VS Code, Cursor, Windsurf or VSCodium, in one edition for Vulkro Core and one for Vulkro for Salesforce.
Developers get findings in the editor they already use, from the same engine as CI.
VS CodeFreeFindings on the line
Shows findings on open and save, or, in watch mode, on every file change, with the proof tier and proof steps on hover.
A finding fixed while the code is still open costs minutes, not a review cycle.
VS CodeFreeReport export and CI parity
Exports the same whole-project scan CI runs as SARIF or JSON, and checks that the editor view matches your CI settings.
What a developer sees locally is what the pipeline will fail on.
VS CodeFreeSalesforce in the editor
Apex, LWC, Aura, Visualforce, Flow and metadata findings inline, with how each class runs and which profiles can call it.
Salesforce developers see sharing and access mode while they write the class, not after deployment.
VS CodeFreeChanges, history and impact views
Sidebar views for changes, history, impact, the code graph and trends, next to the default findings views.
Developers review their change and its reach without switching to another tool.
VS CodePro
AI coding agents 11
The same engine as tools for AI coding agents, with evidence an agent can check.
MCP server for code
Gives Claude Code, Cursor, Windsurf and other MCP clients tools to scan, explain, prove and fix, with the proof chain per finding.
Agents get ranked findings with evidence instead of reading the codebase to search for issues themselves.
AI coding agentsFreeFix verification for agents
An agent submits the diff it proposes; Vulkro applies it to a copy, rescans and reports whether the finding is gone.
The detector, not the agent, decides whether a fix worked, before anything is applied.
AI coding agentsFreeCheck the agent's own change
Scans the whole project but returns only findings on the lines a change added or modified.
An agent checks its own work in one call, with answers small enough to act on.
AI coding agentsProCode graph, change assessment and evidence graph
Ranked call graph, blast radius before an edit, a stack trace mapped onto code, and a stable evidence document for any agent.
Agents navigate and change code with ranked, capped answers instead of reading files to find callers.
AI coding agentsProWrite-time guard
Hooks into Claude Code and Cursor to scan every file the agent writes, asking it to regenerate on a proven or High finding.
Scanning becomes part of the agent's write loop, whether or not it decides to ask.
AI coding agentsFreeAgent skill
Installs a Vulkro skill for Claude Code, Cursor and Codex CLI so the agent knows when and how to run a security review.
The agent reaches for the scanner at the right moments without a long prompt each time.
AI coding agentsFreeChecks for MCP and cloned repositories
Audits MCP configuration and MCP server source for risky setups and tool poisoning, and inspects a cloned repository before it runs.
Assistant tooling runs with a developer's access, and it is rarely reviewed before it is trusted.
AI coding agentsFreeTools for Copilot Chat agent mode
The extension registers scan-file and explain-finding tools that GitHub Copilot Chat agent mode can call and you can reference.
Teams on GitHub Copilot get the same engine inside their existing chat.
AI coding agentsFreeMCP server for Salesforce
Lets an agent scan an SFDX project or metadata and list every check, offline.
Salesforce developers using agents get platform-aware findings instead of generic code advice.
AI coding agentsFreeOrg and change tools for agents
Agents read permissions, sessions, MFA and Health Check through your Salesforce CLI login, and assess a change's blast radius.
An agent can answer what a change will touch and who holds a power, from the real org.
AI coding agentsProVulkro Cloud tools for agents
An agent lists what to fix, triages, assigns, plans a fix against your local project and verifies it in your Vulkro Cloud workspace.
Agents work the team queue, and their triage proposals still wait for a person to approve.
AI coding agentsCloud
Team and Cloud 12
Shared issue lists, triage, roles, notifications and history for a security team.
Portfolio and shared console
Rolls many repositories into one portfolio, and serves the console on a network address with a token for the team.
A security lead responsible for many services works from one view the whole team can read.
CoreProNotifications
Sends scan summaries to Slack, Microsoft Teams, Jira, PagerDuty and webhooks, updating Jira issues instead of duplicating them.
Findings reach the channel the team already uses, without a ticket flood on every rerun.
CoreProClient workspaces and portfolio
Groups projects and orgs under a named client, rolls up risk across orgs, and exports one client-ready report per client.
Consultancies and partners manage many orgs, and each client needs its own clean deliverable.
SalesforceProDedicated workspace, isolated scans
Each company gets its own workspace with its own database, storage and keys; every scan runs in parallel in its own container.
Your org data is separated from other customers by design, and many orgs never queue behind each other.
CloudCloudScheduled scans
Scans each live org daily, weekly or monthly at a time and time zone you choose, or on demand.
Posture changes every week; a schedule catches drift without anyone remembering to run a scan.
CloudCloudOne issue list with stable keys
Every finding of every kind in one list per org, each with a key, status and assignee, closed on rescan when fixed.
Work is tracked once across scans, and a fix is confirmed by the next scan, not by a checkbox.
CloudCloudFix first
The org overview leads with the most severe open issues to work on next.
A team with limited hours starts with the issues that matter most.
CloudCloudTriage with approval
Developers mark issues in progress or fixed at once; a false positive or accepted risk waits for someone else to approve it.
Risk is never waved away by one person, and the decision and approver are on record.
CloudCloudRules, suppressions and custom rules
Make any rule advisory or off for some orgs or files, and write custom org and Apex rules tested on the latest scan.
Policy is visible and accountable, and company rules are proven against real data before they go live.
CloudCloudRoles and sign-in rules
Built-in roles from Owner to Viewer plus your own, per-org scope, required MFA, domain and network limits and session timeouts.
Auditors, contractors and developers see only what they need, in a workspace locked down like the org.
CloudCloudNotifications
Sends events to Slack, Microsoft Teams, Google Chat, Discord, PagerDuty, your mail server, signed webhooks and Jira with status read back.
Alerts reach the people on call, and a closed Jira ticket marks an issue ready to close, never closed.
CloudCloudWorkspace data controls
Set result retention, mask personal data, export the workspace, delete it, grant time-limited support access and export the activity log.
Security and privacy teams can answer how long data is kept, who saw it and how to get it back.
CloudCloud
Reports and compliance 9
Reports, audit evidence and standard formats you hand to someone else.
Executive report
Builds an HTML report you can open in a browser or save as PDF, worst findings first.
Clients, managers and auditors get a readable document instead of raw scanner output.
CoreProCompliance mapping and evidence packs
Maps findings to controls in ASVS, PCI DSS, SOC 2, HIPAA, ISO 27001, NIST and GDPR, and builds audit and CRA bundles.
Security findings become structured audit evidence without a manual spreadsheet mapping.
CoreProEvidence formats
Writes CycloneDX and SPDX bills of materials, VEX, a cryptography inventory, an AI bill of materials, PDF, CSV and JUnit.
Procurement, auditors and downstream customers each ask for a specific standard file.
CoreProAppExchange readiness checklist
Maps findings to the Security Review categories and pre-submit checklist, and attests Apex test coverage against the bar.
ISVs see where the package stands before submitting, instead of after a failed review.
SalesforceFreeAppExchange submission packet
Builds the readiness report and packet: blocking fixes by effort, drafted false-positive justifications and a bill of materials.
A failed Security Review means another round; a complete, evidenced packet reduces the back and forth.
SalesforceProSalesforce compliance evidence
Builds auditor packages for SOC 2, HIPAA and PCI, a GDPR record of processing, a HIPAA safeguard matrix and hashed attestations.
Compliance teams get evidence generated from the org and code, with a hash to show it was not edited.
SalesforceProOrg posture report and SIEM events
Generates a shareable posture report for a live org, and writes audit findings as OCSF events with MITRE ATT&CK techniques.
Leadership gets one document, and Salesforce posture joins the rest of your security reporting.
SalesforceProCompliance, reports and exports
Control status with the issues behind it, hashed PDF and CSV evidence packs, a security report, masked CSV and OCSF exports.
Auditors see which open issue fails which control, and results leave in the shape each audience needs.
CloudCloudReview readiness
An internal review view plus the AppExchange checklist, report and packet, from the latest scan.
ISVs track Security Review readiness on every scan instead of in a rush before submission.
CloudCloud
Supply chain and secrets 9
Dependencies, bills of materials, containers, credentials and what enters a project.
Dependency CVEs with reachability
Matches dependencies against offline vulnerability data, tags whether your code reaches each one, and raises known-exploited ones.
A vulnerable library you never call is a scheduled upgrade; an exploited one on a live path is an incident.
CoreFreeSecrets in the working tree
Finds credentials committed in the files on disk, with optional live validation that is off by default.
A leaked key can bypass every other control, and it is cheapest to catch before the push.
CoreFreeMalicious-code checks
Flags malicious install scripts in every scan, and surfaces credential theft, reverse shells and obfuscation in source you have not run.
Supply-chain attacks run at install time, before review. Vulkro never certifies code as safe.
CoreFreePackage and extension vetting
Checks dependency lists for malicious, hallucinated and typosquatted names, and installed extensions for risky permissions.
An invented package name is a name an attacker can register, and extensions run with a developer's access.
CoreFreeSecrets in git history
Finds credentials that were committed and later removed, still recoverable from the repository history.
Deleting a key from the latest commit does not revoke it; anyone with the history still has it.
CoreProBill of materials and matching
Lists every dependency in standard bill-of-materials formats, and checks an external one against local vulnerability data.
A current inventory is the first thing asked for when a new advisory lands, including for vendor components.
CoreProContainer scanning
Checks the operating-system and application packages inside a built image against local vulnerability data, without pulling from a registry.
The image is what runs in production, and it carries packages the source manifests never list.
CoreProAdvisory response
Answers whether a named package or advisory is anywhere in the project, across lockfiles and imports, in seconds.
When an advisory drops, the first question is whether you are exposed, and it needs a fast, exact answer.
CoreProPackage and static-resource CVEs
Checks managed packages and JavaScript in static resources against offline vulnerability and end-of-life data, and builds a data dictionary.
Old JavaScript in a static resource is a common, overlooked way to ship a known vulnerability.
SalesforceFree
Offline and privacy 4
Local analysis, an air-gap switch, and no model in the scan.
Air-gap switch
One flag or environment variable blocks every outbound network call for a run; a local model is still allowed.
Regulated and classified environments need a guarantee, not a setting buried in a config file.
CoreFreeAir-gapped vulnerability data
Keeps vulnerability data current on Free, and applies updates from an offline file on machines with no internet.
An offline scanner that goes stale is a liability; this one can be updated without a network.
CoreFreeNo model in the scan
The scan engine calls no model and sends no code anywhere, and the optional AI layer is local by default.
Results can be reproduced, audited and gated on, and detection costs no model tokens.
CoreFreeLocal analysis, your own org login
Source, paths and findings stay on your machine; live-org reads go through your own Salesforce CLI login and change nothing.
No new integration user, no token held by a vendor, and no org data sent anywhere for analysis.
SalesforceFree
03Languages
Language coverage and analysis depth
Where data flow crosses files and where it stops at one function, said plainly.
Vulkro Core| Language | Route mappingentry points | Data flow, same filesource to sink | Data flow, across filesvia the call graph | Framework awarenessrouters, ORMs | Dedicated checkslanguage rules |
|---|---|---|---|---|---|
| PythonDjango, Flask, FastAPI | |||||
| JavaScriptExpress, Koa, Next.js | |||||
| TypeScriptExpress, NestJS, Next.js | |||||
| Gonet/http, Gin, Echo, chi | |||||
| Javasame-file data flow only | |||||
| PHPsingle function; Laravel, Symfony sources | |||||
| Csingle function | |||||
| C++the C rules run here too | |||||
| Apexentry points, not URL routes · Vulkro for Salesforce | |||||
| Terraform, Dockerfileconfiguration, not data flow |