For Salesforce partners
A security review for every client, with evidence you can hand over.
Vulkro for Salesforce gives a consultancy one way to review every client org: the code and the org read together, the attack paths behind the findings, and a report the client can keep.
The partner programme is set up with each partner directly.
UserGuest user
Anyone on the internet is this user.
The Customer Portal site is active and serves unauthenticated visitors as its guest user. There is no login between a stranger and everything this user can reach.
<CustomSite><active>true</active><guestProfile>Customer Portal Profile</guestProfile><siteType>ChatterNetwork</siteType></CustomSite>
Break the path at the hop that carries it. Declare with sharing on InvoiceController and query WITH USER_MODE: one change in one class closes all five hops.
01Review every client
Run the same review on every client org
753 checks, 147 of them on the live org and 606 on code and metadata. The same engine and the same answer for every client, so two engagements are comparable.
Code
The client’s project, on your machine
Apex, LWC, Aura, Visualforce, Flows and metadata from the DX project. Nothing is uploaded.
Org
The live org, read only
Users, permissions, MFA, sessions, sharing, connected apps and guest access, through your own Salesforce login. Settings and definitions, never records.
Result
Attack paths, ranked
The findings joined into the paths that reach data, ranked, with the one hop that breaks each path.
Honesty
Checks that could not run are marked
A check your login could not run reads "not evaluated", with what to grant. It is never counted as a pass in front of a client.
02Hand over evidence
Give clients the evidence behind each finding
Every finding carries its evidence: the file and line, the path behind it, and whether it is proven, unproven or not checked. The deliverables are built from the same results.
- Org posture report
- One self-contained HTML or Markdown report of the live org’s posture, from one command.
- AppExchange readiness
- The review categories scored pass, gap or not evaluated, as a report the client can hand to the review team.
- Compliance evidence
- Auditor packages mapped to SOC 2, HIPAA and PCI controls, and a GDPR record of processing activities.
- Machine-readable
- SARIF and JSON for the client’s own pipeline and tools.
- Plan
- Live-org scanning, the reports and the compliance evidence are part of Pro.
03ISV clients
Get ISV clients through Security Review in one round.
The review’s own scanners run after submission. Vulkro scores the same requirement categories before it, so the first submission is the one that passes.
AgentExchange Security ReviewFirst submissions
About half
Salesforce publishes no first-pass failure rate. About half is the figure partners cite most often for first submissions: an industry estimate, not an official one.
Paid solutions
A fee for every attempt
On a paid solution Salesforce charges a $999 fee for the initial submission and for every later attempt (Salesforce). Missing CRUD and field-level checks are the most common reason a round fails.
Each round
Four to five weeks a round
Salesforce says a solution typically takes four to five weeks to get through review, and every fix and resubmit is another attempt. Fixing the issues during development is how a client avoids the second round.
The readiness checklist is free. The report for the reviewer, the submission packet and the presubmit gate that fails a build before submission are part of Pro.
04Vulkro Cloud for Salesforce
Each client gets its own workspace, scanned on a schedule
For clients you look after month to month, Vulkro Cloud keeps their orgs scanned on a schedule and shows what changed. Available by invitation, and set up with you directly.
Request access- Isolation
- Each workspace has its own address, database, storage and keys. Nothing is shared between clients.
- Continuous
- Orgs scanned on a schedule, each scan in its own container, every result kept.
- What changed
- Changes since the last scan: new admins, permission sets, connected apps, relaxed settings and guest access.
- Fix first
- The overview leads with the issues to fix first, each with its attack path.
- Client access
- Roles from Owner to Viewer and Auditor, scoped per org.
- Hand-off
- Notifications to Slack, Microsoft Teams, Jira, PagerDuty, Google Chat, Discord, email and webhooks.
05The partner programme
Priced by client workspace, agreed with you directly.
We are setting the partner programme up with each partner directly. Partner accounts are not self-serve yet.
- Partner 5
- Up to 5 client workspaces. Talk to us about pricing.
- Partner 15
- Up to 15 client workspaces. Talk to us about pricing.
- Partner 30
- Up to 30 client workspaces. Talk to us about pricing.
Questions
What partners ask first.
- Does client code or data leave our machines?
- Not with Vulkro for Salesforce: it scans locally and works offline. Org checks read settings and definitions through your own Salesforce login, never records. Vulkro Cloud, if you use it, keeps each client in its own workspace.
- Can the client see the results themselves?
- In Vulkro Cloud, yes: give them a Viewer or Auditor role in their own workspace. From the command line, hand over the HTML report or the SARIF and JSON output.
- Do our consultants each need a licence?
- Each licence belongs to one person. How seats work for a partner team is part of what we agree with you directly.
- Can we sign up as a partner online today?
- Not yet. Partner accounts are not self-serve: we set the programme up with each partner directly. Talk to us and we will work out the shape that fits your practice.