Skip to main content

Vulkro Cloud data processing

Last updated: October 6, 2026

Vulkro Cloud for Salesforce is the hosted part of Vulkro. It connects to your Salesforce orgs, scans them on a schedule and when someone starts a scan, and keeps the results for your team in a workspace of its own. This page says exactly what it reads, what it stores, who can see it, how long it is kept and how to remove it.

The command line tools and the VS Code extension work differently: they run on your own machine and do not use Vulkro Cloud unless you connect them to a workspace. See the Privacy Policy for the product as a whole.

1. Who is who​

You (the company that holds the workspace) are the controller of the data Vulkro Cloud processes for you: the data read from your Salesforce orgs, the issues and decisions your team records, and the names and email addresses of the people you add to the workspace. Vulkro is a product of Reveriext, and Reveriext acts as a processor of that data. It handles it only to provide Vulkro Cloud to you, on your instructions, which are your configuration of the workspace and these terms.

You are responsible for having a lawful basis to let Vulkro Cloud read your org, including the data it holds about your own users, and for telling them where your own rules require it.

2. How it connects to your org​

  • You connect each org yourself, with a Salesforce External Client App that you create and control in that org. The connection uses the Salesforce OAuth web-server flow with PKCE.
  • The OAuth scopes requested are api and refresh_token. The api scope is not limited to reading: what it allows is set by the permissions of the Salesforce user who authorises the connection. Vulkro Cloud is built to read only: it issues read requests and metadata retrieves, and it has no code path that creates, changes, deletes or deploys anything in your org.
  • An org can also be connected with a Salesforce session token that you paste. That token is never refreshed and expires on Salesforce's schedule.
  • Fixes are shown as instructions and patches. Vulkro Cloud never applies them. Anything you download and run against your org runs under your control.
  • You can revoke the connection at any time, either from Vulkro Cloud or in Salesforce Setup.

3. What it reads from your org​

Settings and metadata. Permissions, profiles, permission sets and their assignments, object and field permissions, sharing settings, connected apps and External Client Apps, named and external credentials (their configuration, never their secret values), remote site, CORS and CSP settings, authentication providers, single sign-on settings, installed packages, Health Check, session and domain settings, sites and guest user access, sandboxes, licence usage and Apex test coverage.

Code. Apex classes and triggers, Visualforce, Lightning Web Components, Aura, Flows, static resources and similar metadata, retrieved through the Salesforce Metadata API. If you add a git repository as a code source, Vulkro Cloud clones it for the scan instead.

Users and activity. For each active user: name, username, email address, user type, profile, role, licence, whether they are active, when they last logged in and when they were created. Also MFA registration, permission assignments, login history (including source IP address, browser, platform, application and country), the Setup Audit Trail, the OAuth tokens users have granted to apps (which app and when it was used, never the token itself) and, where your org has Event Monitoring, its event log files.

Field names, not field values. To find where personal data lives, Vulkro Cloud reads the definitions of your objects and fields. It does not read the values stored in them.

4. What it does not read​

  • Your business records: accounts, contacts, leads, opportunities, cases, and the records of your custom objects. Vulkro Cloud does not query them.
  • Passwords, OAuth token values, or the secret values of named and external credentials.

5. What it stores​

Each scan produces a result set that Vulkro Cloud stores in your workspace:

  • the findings, with the rule, severity, location (a file path or a setting name) and the evidence behind each one
  • the user and activity data listed in section 3, including users' email addresses and login IP addresses
  • code excerpts from your Apex, Visualforce and other retrieved files, and suggested patches. This is on by default; a workspace admin can turn off code excerpts in the workspace's data settings, which removes them from new and stored results
  • the issues your team works on, their status, assignee, comments and approvals, and the custom rules and suppressions you create
  • an activity log of what members did in the workspace

It also stores the connection details for each org, a git access token if you add a code source, and the secrets of your notification destinations. These are encrypted by Vulkro Cloud with your workspace's own key (see section 7).

The retrieved metadata and any cloned repository exist only inside the scan job and are deleted when it ends. Only the result set is kept.

Masking. List views and CSV exports show users' email addresses and usernames masked (for example j***@example.com). A workspace setting masks emails, usernames, phone numbers and IP addresses everywhere they are shown or exported. Masking applies when data is shown; the stored result set keeps the values as Salesforce reported them.

6. Where it is stored​

Vulkro Cloud runs on Cloudflare. Each workspace has its own database, its own storage for scan results, its own application and scan environment, and its own encryption key. Each scan runs in a container of its own, which is destroyed when the scan ends.

The location of a workspace's database and stored results is chosen by Cloudflare when the workspace is created, normally close to where it was set up. It is not pinned to a jurisdiction such as the EU or the US, and scans run on Cloudflare's network. Your workspace settings show the current position. If you need data kept in a particular jurisdiction, contact us before you connect an org.

Sign-in is provided by Clerk, which holds members' names, email addresses and sign-in sessions in the United States.

7. How it is protected​

  • Isolated tenant. A workspace's database, results storage, application and encryption key are not shared with any other customer.
  • Encryption. Salesforce tokens, the External Client App secret, git tokens and notification secrets are encrypted by Vulkro Cloud with AES-256-GCM, using a key held only for your workspace. Cloudflare encrypts the databases and stored files at rest and in transit as part of its platform.
  • Access inside your team. Roles (Owner, Admin, Security analyst, Developer admin, Developer, Auditor, Viewer and your own) decide who can connect orgs, scan, export and change settings. Marking an issue a false positive or an accepted risk needs a second person's approval.
  • Workspace security. You can require MFA, limit sign-in to your email domains, set an IP allowlist and set session timeouts.
  • Activity log. Connections, scans, exports, role and member changes, triage decisions, rule changes, data settings and support access are recorded with who did it and when.

8. Who at Vulkro can see it​

  • Support access is yours to grant. Our support team can enter your workspace only while a member of your workspace has granted access, for a period you choose between one hour and seven days. You can end it at any time, and each visit is recorded in your activity log.
  • Account recovery. If your team is locked out, support can reset your workspace's MFA, IP allowlist and session settings. The reset is recorded in your activity log with the name of the person who did it.
  • Operations. Our staff tools show workspace status, plan, usage counts and the names and email addresses of members, not your findings. Engineers who operate the platform can reach a workspace's database to apply updates and to carry out a deletion you request. We limit this to operating the service.

9. Notifications you configure​

If you add a notification destination, Vulkro Cloud sends messages to it over HTTPS: Slack, Microsoft Teams, Jira, PagerDuty, Google Chat, Discord, email through your own mail server, or a webhook (signed with HMAC-SHA256 so you can verify it came from your workspace).

A message carries the workspace and org names, scan status, counts and score, and up to 20 issues with their key, rule, severity, title, location and a link back to the workspace. An issue title can include the name of a Salesforce user (for example on a suspicious-activity issue), and an approval request carries the requester's name and reason. Messages never carry record data, code excerpts or secrets.

Once a message reaches a tool you chose, that tool's own terms and privacy policy govern it. Those services are yours, not our sub-processors.

10. AI​

Vulkro Cloud does not send your data to any AI model. Its findings, triage and scoring are rule-based. If you connect vulkro-sf or an AI assistant to your workspace, what that assistant does with the data it reads is governed by the assistant you chose.

11. Retention​

  • Scan results. Each workspace chooses how long scan results are kept: 180 days unless you choose otherwise, between 7 days and the most your plan allows. When a result passes that window its stored result files are deleted.
  • Issues and the activity log are kept for the life of the workspace, so that the history of each issue and each decision stays intact.
  • Sign-in locations. For each Salesforce user, Vulkro Cloud keeps a record of each IP address they signed in from, with the first and last time it was seen and a count, for the life of the workspace. This is what lets it tell a new sign-in location from a known one. Detailed suspicious-activity events follow the scan-result window above.
  • A plan change never deletes anything. If a trial ends or a plan is cancelled, the workspace becomes read-only: scans and new connections stop, and everything stays readable and exportable.

12. Disconnecting and deleting​

  • Disconnect an org. Vulkro Cloud revokes its Salesforce token and deletes the stored copy. The org's past results stay readable until your retention window removes them. For a session-token connection, the token is deleted but not revoked; it expires on Salesforce's schedule.
  • Delete an org. Also deletes that org's stored scan results. The activity log, and the issues already raised for that org, stay in the workspace until the workspace itself is deleted.
  • Delete the workspace. An owner can request deletion in the workspace settings. There is a 14-day grace period, during which any owner can cancel. After it we delete the workspace's application, scan environment, database, results storage, encryption key and sign-in organisation. Before deleting, we take a final copy of the workspace's data; because the encryption key is destroyed, the encrypted secrets in that copy can no longer be read. We keep a minimal record that the workspace existed (the company name and the admin contact).
  • Remove a member. Their access to the workspace and their command line tokens are removed.

13. Export​

You can export every scan's results as HTML, Markdown, SARIF, JSON, a CycloneDX SBOM, CSV and OCSF, and an owner can export the whole workspace (every record, with secrets removed) as one file. A workspace export is available to download for 7 days. Export stays available while a workspace is read-only.

14. Sub-processors​

Sub-processorWhat it does for Vulkro CloudLocation
CloudflareHosts every workspace: the application, databases, stored results, scan containers and encryption keysNot pinned; see section 6
ClerkSign-in: members' names, email addresses and sessionsUnited States
StripeBilling for a paid workspace, when you pay by cardStripe's regions
ResendEmail notifications for destinations set to be sent by Vulkro rather than by your own mail serverResend's regions

Salesforce, your git host and the notification tools you add are services you choose and contract with directly; they are not our sub-processors. We will update this list before adding a sub-processor that handles your workspace data.

15. A signed agreement​

If your procurement process needs a countersigned data-processing agreement, a security questionnaire, or a record of processing, write to contact@vulkro.com.

16. Changes​

If what Vulkro Cloud reads or stores changes, this page changes with it before the change takes effect.

Contact​

Questions about this page or about your workspace data: support@vulkro.com. Data-processing agreements: contact@vulkro.com.