Skip to main content

How it works

What happens when Vulkro scans.

It reads what you ship, follows the data, checks who can reach each weak spot, proves the path and hands you the fix guidance. Your AI agent or your team makes the change, and Vulkro checks it again.

An example finding from an example project. The steps are the same for every scan.
* Vulkro's code search (Pro): one answer is 1.3 to 1.6% of the source a grep-and-read pass must load to answer the same question about a symbol (vulkro 0.27.0).

01The five steps

From your code to a proven path.

Each step narrows what you see, so the findings at the end are the ones an attacker could actually use, with the evidence to show it.

How the path is built
  1. 01 · Read

    It reads everything you ship.

    Your code, the packages it pulls in, any keys left in it and the settings it runs with. For Salesforce it also reads the org: who can sign in, what each person may do and what a site visitor can reach.

    Languages: JavaScript, TypeScript, Python, Go, Java, PHP, C and C++. Salesforce: Apex, LWC, Aura, Visualforce, Flows and org settings. Records are never read.

    Reading

    • Your coderoutes, services, queries
    • Packageslockfiles, known vulnerabilities
    • Secrets124 key and token patterns
    • ConfigDockerfiles, infrastructure files
    • Salesforce orgprofiles, permission sets, sharing, guests
  2. 02 · Follow

    It follows the data across files.

    From the place a request comes in, through every function it passes, to the line where it is used. A value that moves to another file is still followed.

    Across files in JavaScript, TypeScript, Python and Go. Within one file in Java, and within one function in PHP, C and C++.

    The search text, followed

    1. routes/orders.tsThe request comes in4router.get('/api/orders', (req, res) => …
    2. routes/orders.tsPassed to a service5searchOrders(req.query.q)
    3. services/orders.tsUsed in a database query4pool.query("… LIKE '%" + term + …)
  3. 03 · Reach

    It checks who can reach each weak spot.

    A weak spot anyone online can reach ranks above one only an admin can. In a Salesforce org it checks who actually holds each profile and permission set, so a grant nobody holds is not reported as a live risk.

    Ways into the app, by who can use them

    1. 1GET /api/ordersWeak spotAnyone
    2. 2POST /api/loginAnyone
    3. 3GET /api/invoices/:idSigned in
    4. 4POST /webhooksSigned in
    5. 5POST /admin/jobsAdmins
  4. 04 · Prove

    It proves the path, hop by hop.

    Each finding says how sure Vulkro is. Proven means every hop is traced to its file and line. Unproven means one is missing, and it says so. Code it could not check reads Not checked, and is never counted as a pass.

    CriticalProvenevery hop traced
    1. Entry pointsrc/routes/orders.ts:4No sign-in needed
    2. Callsrc/routes/orders.ts:5The search text passed straight on
    3. Querysrc/services/orders.ts:4Built from the request, no binding
    Proven: every hop tracedUnproven: one hop missingNot checked: never a pass
  5. 05 · Hand off

    Your agent or your team fixes it. Vulkro checks it again.

    Vulkro says what to change and where, often as a suggested patch. Hand it to your AI agent or a developer to make the change. Vulkro then scans again and tells you if it is fixed, not fixed, or made worse.

    The guidance is ready for Claude Code, Cursor, Codex and GitHub Copilot, or for anyone on your team.

    1. 1Vulkroproposes the fixsrc/services/orders.ts · suggested change
      - pool.query("… LIKE '%" + term + "%'")
      + pool.query('… LIKE $1', [`%${term}%`])
    2. 2Your agent or developermakes the changeClaude CodeCursorCodexGitHub CopilotDeveloper
    3. 3Vulkroscans againFixedNot fixedMade it worse

02Where it runs

It runs where you already work.

The same checks give the same answer on your laptop, in your pipeline, in your editor and for your AI assistant. Vulkro Cloud runs them on your Salesforce orgs.

One engineSame checks, same answer, in every place
  • Your machineA command-line scanner, and a local console that opens in your browser.macOSLinuxWindowsInstall
  • Your pipelineFails a build on the problems that matter, with a report your code host can show.GitHub ActionsGitLab CIBitbucket PipelinesJenkinsCircleCISet up CI
  • Your editorThe problem on the line that causes it, while you write it.VS CodeCursorWindsurfVSCodiumThe extension
  • Your AI assistantYour assistant asks Vulkro instead of reading the whole codebase, searches the code with it while it builds, makes the fix, then has Vulkro check it again.Claude CodeCursorCodexGitHub CopilotFor AI assistants
  • Vulkro CloudBy invitationYour Salesforce orgs, scanned read-only on a schedule, in a tenant of your own.SalesforceVulkro Cloud

03What you can rely on

Three facts, stated plainly.

The first three questions a security team asks, each answered on its own.

How accurate it is, misses included
  • No AI in scansScans use no AI. The same code gets the same answer.Detection is analysis of your code, not a prompt. Run it on Monday and on Friday and you get the same findings, so a change in the list means a change in the code.Whoever writes the fix, a person or an AI agent, the scan checks the change the same way.
  • Runs offlineRuns offline. Your code stays on your machine.The command line and the editor scan without a network connection, air-gapped included. Vulnerability data arrives as a checksummed bundle, so an offline scanner does not go stale.Vulkro Cloud is the exception: it reads your Salesforce orgs read-only, from a tenant of your own.
  • For AI assistants98% fewer tokens.Your AI assistant (Claude Code, Cursor, Codex, GitHub Copilot) asks Vulkro instead of reading your whole codebase to find the same problems.Compared with an AI assistant reading the codebase itself to find the same problems (vulkro 0.28.0, measured 2026-09-19).

See the five steps on your own code.