Skip to main content

Use case · Air-gapped and regulated networks

Security scans for air-gapped networks, with no outbound network calls.

Most scanners assume a route to the internet. Vulkro was built offline first: the whole analysis runs on the machine, one switch refuses every outbound call, and vulnerability data arrives as a file you carry in.

Vulkro Core · Vulkro for Salesforce

vulkro · orders-apijs-taint-sql-001
CriticalProven

Anyone can run their own SQL through the order search

  1. Entry pointsrc/routes/orders.ts:4
    router.get('/api/orders', async (req, res) => {Express route · no sign-in needed
  2. Callsrc/routes/orders.ts:5
    const rows = await searchOrders(req.query.q)the search term passed straight on
  3. Sinksrc/services/orders.ts:4
    pool.query("SELECT * FROM orders WHERE customer_name LIKE '%" + term + "%'")SQL built from the request, no binding
Who can reach it
Anyone, no sign-in
What is at stake
Every customer's data
Guards on the path
None. The value is never bound
Disposition
Proven: traced from the request to the query
Fix
Bind the value: pool.query('... LIKE $1', [`%${term}%`])

01The problem

Most security tools need the internet

Regulated and classified environments hold the code that most needs review, and they rule out tools that upload it.

  • Tools that upload code are not allowed

    A scanner that sends source, paths or findings to a service cannot be approved for the network at all.

  • Stale data

    A tool that refreshes vulnerability data over the internet goes quietly out of date once the internet is gone.

  • Licence checks that need the network

    An entitlement check that needs the network breaks the moment the machine has none.

03The workflow

Steps from first scan to fix

  1. 01

    Bring in the binaries

    Copy vulkro and vulkro-sf across the gap with the rest of your approved tooling.

    Vulkro Core
  2. 02

    Switch off the network

    Set VULKRO_OFFLINE=1. Every outbound call is refused, and the scan does not need one.

    Vulkro Core
  3. 03

    Carry in vulnerability data

    Apply the bundle file. Each file is checked against its SHA-256 before anything is written, and a failed check changes nothing.

    Vulkro Core
  4. 04

    Activate Pro, if you use it

    Install the offline licence file on the machine. Free scanning needs nothing.

    Vulkro for Salesforce
  5. 05

    Scan

    Code and Salesforce projects, with the same findings and proof as a connected machine.

    Vulkro Core

04What you get

What you get

No egress
Source, paths and findings stay on the machine. You can check it by running the scan with the network removed.
Current data
Vulnerability data refreshes by file, on your schedule, and stays free.
Integrity
Every file in the bundle is re-checked by SHA-256 on apply.
Licensing
An offline licence file for Pro. No sign-in and no heartbeat.
Optional AI
A model on the same machine is allowed offline. Cloud endpoints are refused.

Questions

Common questions

How does vulnerability data reach the machine?
As a bundle file you download on a connected machine and carry in. Five manifest formats are parsed. The default published bundle currently ships npm and PyPI; the wider checksummed bundle covers Go modules, crates.io and Maven.
Is the analysis shallower offline?
No, it is the same engine. Its depth varies by language: data flow is followed across files in JavaScript, TypeScript, Python and Go, within one file in Java, and within one function in PHP, C and C++.
Can we audit a live Salesforce org from inside the network?
Live-org reads need a route to the org, so they are refused under the offline switch. Source and retrieved metadata scan fully offline.
How do we get an offline licence?
Our team issues offline licence files. You install the file on the machine with activate, and no network call is made.

The full analysis, with no outbound network calls.