Skip to main content

Use case · AppExchange ISVs

Pass AgentExchange Security Review in fewer rounds.

The review (formerly AppExchange Security Review) takes weeks a round. Vulkro moves it into development: the issues reviewers fail packages for are caught in the editor and the pipeline, so far fewer of them ever reach the review.

Vulkro for Salesforce · VS Code extension · Vulkro Core

01The problem

Each failed review round costs weeks

The scanners the review runs execute inside Salesforce’s pipeline, after you have already submitted. Three facts about that round, from Salesforce where Salesforce publishes them.

  • About half fail first time

    Salesforce publishes no first-pass failure rate. About half is the figure partners cite most often: an industry estimate, not an official one.

  • A $999 fee per attempt

    On a paid solution Salesforce charges $999 for the initial submission and again for every later attempt. Missing CRUD and field-level checks are the most common reason a round fails.

  • Four to five weeks a round

    Salesforce says a solution typically takes four to five weeks to get through review, and every fix and resubmit is another attempt. The way to save that time is to fix it while you develop.

03The workflow

Steps from first scan to fix

  1. 01

    Catch it while you write it

    The extension flags missing CRUD, FLS and sharing on the line as you develop, months before the review would.

    VS Code extension
  2. 02

    Scan the package

    Run Vulkro for Salesforce over your Salesforce DX project. Nothing is uploaded.

    Vulkro for Salesforce
  3. 03

    Read the readiness checklist

    Every requirement category scored pass, gap or not evaluated. Not evaluated is never counted as a pass.

    Vulkro for Salesforce
  4. 04

    Gate the build

    A presubmit gate fails the pipeline while a gap remains, so nothing goes out half fixed.

    Vulkro for Salesforce
  5. 05

    Submit with the report

    Hand the reviewer the readiness report alongside your submission.

    Vulkro for Salesforce

04What you get

What you get

Before submission
The same requirement categories the review scores, on your machine.
Honest gaps
A category Vulkro could not evaluate says so, with what to check by hand.
In the editor
CRUD, FLS and sharing findings on the line, with the fix.
In CI
A presubmit gate and SARIF on the pull request.
Free and Pro
The readiness checklist is free. The reviewer report and the presubmit gate are Pro.

Questions

Common questions

Does this replace the Security Review?
No. Salesforce still runs the review. Vulkro tells you, before you submit, where your package stands against what the review looks for.
Does my code leave my machine?
No. Vulkro for Salesforce scans locally, and works offline.
What about the parts a scanner cannot judge?
They are marked not evaluated, never passed, so you know what to review by hand.

Fix review issues during development and resubmit less often.