Skip to main content
New: Vulkro Cloud for Salesforce, a hosted workspace for your team. Available by invitation: register your interestView docs

Terms of Service

Last updated: July 14, 2026

These Terms of Service ("Terms") govern your use of Vulkro (the "Service"), the application security scanner distributed at vulkro.com, the binary distributed at dist.vulkro.com, and any related software, documentation, or services. The Service is provided by Vulkro ("we", "us", "our").

By installing, running, or otherwise using Vulkro, you ("you", "your", "Customer") agree to these Terms. If you do not agree, do not install or use the Service.

1. License grant​

Subject to your compliance with these Terms and payment of any applicable fees, we grant you a non-exclusive, non-transferable, non-sublicensable, revocable license to install and run the Vulkro binary on the machine(s) authorised by your account entitlement (obtained by signing in with vulkro login) or by your license file (.lic).

Each commercial license is bound to a single machine identifier generated from your hardware (see vulkro machine-id). You may not share, redistribute, or attempt to bypass the license enforcement mechanism.

A free license is available for personal use and bona-fide open-source maintenance. Email license@vulkro.com to request one.

2. Permitted use​

You may use Vulkro to:

  • Scan source code, configuration files, dependencies, container images, and infrastructure definitions that you own or are authorised to scan.
  • Integrate Vulkro into your own development, build, or CI/CD workflows.
  • Generate and use reports, evidence packs, and SARIF/JUnit/CycloneDX exports produced by Vulkro for any purpose, including sharing with auditors, customers, and regulators.

You may not:

  • Reverse-engineer, decompile, or attempt to extract the source code, signing keys, or rule logic of Vulkro, except to the extent expressly permitted by applicable law.
  • Use Vulkro to scan systems or codebases that you do not own and are not authorised to scan.
  • Redistribute the Vulkro binary, the CVE bundle, or any rule pack without our express written permission.
  • Use Vulkro to develop a competing product or service.

3. Customer data​

Vulkro is designed to run scans entirely on your own infrastructure. When you scan, we do not receive your source code, your scan results, your endpoint inventory, or any data about the systems you scan. Your source code is never transmitted to us in any mode.

The one exception is the optional, paid organisation dashboard. It is off unless you run vulkro publish or vulkro-sf publish and accept the publishing terms, and it does upload a posture snapshot for the repository you publish, including file and module names, API routes, the file and line behind each finding, your dependency inventory and contributor names. It never uploads source code or secret values. What it sends, how long it is kept and how to withdraw are set out in Organisation dashboard data processing.

Apart from that, Vulkro makes a small, documented set of outbound network calls:

  1. Fetching the binary on install, from our content delivery network at dist.vulkro.com.
  2. Fetching signed CVE bundles when you run vulkro update, from the same content delivery network.
  3. Signing in with vulkro login and periodically refreshing your account entitlement. The entitlement refresh transmits only the following usage fields: product, installation identifier, version, operating system, timestamp, and a count of scans run, plus a device token while you are signed in and a short set of language slugs after a scan. It never transmits source code, file names, file paths, or findings.

The update calls can be disabled, and air-gapped deployments may use a license file in place of the entitlement refresh, in which case no network calls are made. See the Privacy Policy for the full list of what we do and do not collect.

4. Fees and payment​

Vulkro is licensed per seat, and there are two ways to buy. You may subscribe from your account, self-serve, on a monthly auto-renewing subscription that you can cancel at any time; or you may ask our team for a quote (license@vulkro.com) and be licensed on terms agreed in writing before any fee is payable. Teams, air-gapped machines and volume purchases go through the second route. Use of the Service requires an account; a 14-day trial of the full product begins on your first device login and requires no payment instrument.

All licenses are issued for a fixed term and are payable in advance. Nothing renews on its own and there is no recurring charge. When your license or trial expires, the CLI prompts you to request a new license; reports, scan history, and configuration already on your machine remain yours. There is nothing to "cancel" because every license is a fixed-term grant that simply lapses at the end of its term.

All fees are exclusive of any applicable taxes, which are stated in your agreed license terms or invoice and remitted by us where applicable.

5. Refunds​

We do not offer refunds. Once a license file is issued it cannot technically be revoked, so a refund would leave the customer with an operational copy of the software for free.

6. Updates and support​

Every paid plan receives all updates released during its active window, including new detectors, rule pack updates, CVE bundles, and bug fixes. There is no feature gating between tiers; only the license duration varies.

Support is provided via email, without tiering. All paying customers get the same response queue. Custom arrangements (SLAs, dedicated channels, named contacts) are available on request; email contact@vulkro.com.

7. Intellectual property​

Vulkro, including the binary, the rule packs, the CVE bundles, the documentation, the brand name, and the logo, is the intellectual property of Vulkro. These Terms do not transfer any ownership rights to you. Findings, reports, and other output produced by Vulkro when run against your code belong to you.

8. Warranties and limitation of liability​

The Service is provided "AS IS" without warranty of any kind, express or implied, including but not limited to merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will identify every security vulnerability in your code or that its findings are free of false positives or false negatives.

To the maximum extent permitted by law, our total aggregate liability for any claim arising out of or relating to these Terms or the Service is limited to the amount you paid us in the twelve months preceding the claim, or one hundred United States dollars (USD 100), whichever is greater.

In no event shall we be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to lost profits, lost revenue, lost data, or business interruption, even if advised of the possibility of such damages.

9. Termination​

We may suspend or terminate your license if you materially breach these Terms. Because all purchases are one-time, there is no subscription to cancel. License files already in your possession continue to validate until their expiry date regardless of any relationship change between us and you.

10. Governing law​

These Terms are governed by the laws of India, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to these Terms shall be subject to the exclusive jurisdiction of the courts located in India.

11. Changes to these Terms​

We may update these Terms from time to time. Material changes will be announced on our website at least 30 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms.

12. Contact​

Questions about these Terms: contact@vulkro.com.

Vulkro is a product of Reveriext.

reveriext.com

Visit Reveriext