Skip to main content

For Salesforce partners

A security review for every client, with evidence you can hand over.

Vulkro for Salesforce gives a consultancy one way to review every client org: the code and the org read together, the attack paths behind the findings, and a report the client can keep.

The partner programme is set up with each partner directly.

UserGuest user

Anyone on the internet is this user.

The Customer Portal site is active and serves unauthenticated visitors as its guest user. There is no login between a stranger and everything this user can reach.

Read fromSite metadataLive org
Evidencesites/CustomerPortal.site-meta.xml
<CustomSite>  <active>true</active>  <guestProfile>Customer Portal Profile</guestProfile>  <siteType>ChatterNetwork</siteType></CustomSite>
CriticalProvenFix first

Break the path at the hop that carries it. Declare with sharing on InvoiceController and query WITH USER_MODE: one change in one class closes all five hops.

01Review every client

Run the same review on every client org

753 checks, 147 of them on the live org and 606 on code and metadata. The same engine and the same answer for every client, so two engagements are comparable.

  • Code

    The client’s project, on your machine

    Apex, LWC, Aura, Visualforce, Flows and metadata from the DX project. Nothing is uploaded.

  • Org

    The live org, read only

    Users, permissions, MFA, sessions, sharing, connected apps and guest access, through your own Salesforce login. Settings and definitions, never records.

  • Result

    Attack paths, ranked

    The findings joined into the paths that reach data, ranked, with the one hop that breaks each path.

  • Honesty

    Checks that could not run are marked

    A check your login could not run reads "not evaluated", with what to grant. It is never counted as a pass in front of a client.

02Hand over evidence

Give clients the evidence behind each finding

Every finding carries its evidence: the file and line, the path behind it, and whether it is proven, unproven or not checked. The deliverables are built from the same results.

Org posture report
One self-contained HTML or Markdown report of the live org’s posture, from one command.
AppExchange readiness
The review categories scored pass, gap or not evaluated, as a report the client can hand to the review team.
Compliance evidence
Auditor packages mapped to SOC 2, HIPAA and PCI controls, and a GDPR record of processing activities.
Machine-readable
SARIF and JSON for the client’s own pipeline and tools.
Plan
Live-org scanning, the reports and the compliance evidence are part of Pro.

03ISV clients

Get ISV clients through Security Review in one round.

The review’s own scanners run after submission. Vulkro scores the same requirement categories before it, so the first submission is the one that passes.

AgentExchange Security Review
  • First submissions

    About half

    Salesforce publishes no first-pass failure rate. About half is the figure partners cite most often for first submissions: an industry estimate, not an official one.

  • Paid solutions

    A fee for every attempt

    On a paid solution Salesforce charges a $999 fee for the initial submission and for every later attempt (Salesforce). Missing CRUD and field-level checks are the most common reason a round fails.

  • Each round

    Four to five weeks a round

    Salesforce says a solution typically takes four to five weeks to get through review, and every fix and resubmit is another attempt. Fixing the issues during development is how a client avoids the second round.

The readiness checklist is free. The report for the reviewer, the submission packet and the presubmit gate that fails a build before submission are part of Pro.

04Vulkro Cloud for Salesforce

Each client gets its own workspace, scanned on a schedule

For clients you look after month to month, Vulkro Cloud keeps their orgs scanned on a schedule and shows what changed. Available by invitation, and set up with you directly.

Request access
Isolation
Each workspace has its own address, database, storage and keys. Nothing is shared between clients.
Continuous
Orgs scanned on a schedule, each scan in its own container, every result kept.
What changed
Changes since the last scan: new admins, permission sets, connected apps, relaxed settings and guest access.
Fix first
The overview leads with the issues to fix first, each with its attack path.
Client access
Roles from Owner to Viewer and Auditor, scoped per org.
Hand-off
Notifications to Slack, Microsoft Teams, Jira, PagerDuty, Google Chat, Discord, email and webhooks.

05The partner programme

Priced by client workspace, agreed with you directly.

We are setting the partner programme up with each partner directly. Partner accounts are not self-serve yet.

Partner 5
Up to 5 client workspaces. Talk to us about pricing.
Partner 15
Up to 15 client workspaces. Talk to us about pricing.
Partner 30
Up to 30 client workspaces. Talk to us about pricing.

Questions

What partners ask first.

Does client code or data leave our machines?
Not with Vulkro for Salesforce: it scans locally and works offline. Org checks read settings and definitions through your own Salesforce login, never records. Vulkro Cloud, if you use it, keeps each client in its own workspace.
Can the client see the results themselves?
In Vulkro Cloud, yes: give them a Viewer or Auditor role in their own workspace. From the command line, hand over the HTML report or the SARIF and JSON output.
Do our consultants each need a licence?
Each licence belongs to one person. How seats work for a partner team is part of what we agree with you directly.
Can we sign up as a partner online today?
Not yet. Partner accounts are not self-serve: we set the programme up with each partner directly. Talk to us and we will work out the shape that fits your practice.

Bring Vulkro to every client org you look after.