Get started
Create your account. Run your first scan in minutes.
Sign up, install the command line and sign in on your machine: your first sign-in starts 14 days of the full product. When it ends you keep every check for free, and Vulkro keeps scanning.
No credit card. Your code never leaves your machine.
01Start here
Install and run your first scan in five steps
Pick what you are securing, then follow the steps in order.
- 01
Create your account
One account holds your trial and, later, your Pro licence.
- 02
Install vulkro
For JavaScript, TypeScript, Python, Go, Java, PHP, C and C++.
macOS · Linux$ curl -fsSL https://dist.vulkro.com/install.sh | bash - 03
Sign in on your machine
Opens your browser to approve the device. Your first sign-in starts 14 days of the full product.
terminal$ vulkro login - 04
Run your first scan
From the root of a repository. Findings come with the path behind them.
terminal$ vulkro scan . - 05
Add the editor and your agent
The extension finds VS Code, Cursor, Windsurf or VSCodium. The skill and MCP server work with Claude Code, Cursor and Codex.
terminal$ vulkro install-extension $ curl -fsSL https://dist.vulkro.com/skill-install.sh | bash -s -- --agent claude-code,cursor $ claude mcp add vulkro -- vulkro mcp serve
02For Salesforce teams
Vulkro Cloud. We set up your workspace.
Every org scanned on a schedule, in your own isolated tenant, with one list for the team. The form takes about two minutes, and we reply within two business days.
Request access- 01
Request access
Tell us about your orgs and your team.
- 02
Get your workspace
Your own workspace at your-company.vulkro.com, with its own database, storage and keys.
- 03
Connect your orgs, read-only
Production, sandboxes and Experience Cloud. Settings, metadata and code, never records.
- 04
Fix issues as a team
Fix first, issues, attack paths and changes, for the whole team. How Vulkro Cloud works