Skip to main content

Use case · Regulated companies

Audit evidence from the scan you already run.

Auditors ask how each control is met, and the answer usually lives in a spreadsheet someone fills in by hand. Vulkro maps every finding to the controls it affects and hands you the evidence, control by control, with the file, setting or grant behind each one.

Vulkro Cloud · Vulkro Core · Vulkro for Salesforce

01The problem

Audit evidence is usually collected by hand, once a year

Security findings and audit controls describe the same risks in two languages, and someone translates between them every cycle.

  • Findings and controls are not linked

    The scanner reports a missing field-level check. The auditor asks about access control. Nobody connects the two.

  • Evidence covers only the audit window

    Evidence gathered for the audit window says nothing about the eleven months either side of it.

  • Unchecked controls look like passes

    A control no tool checked looks the same as a control that passed, until an auditor asks for proof.

03The workflow

Steps from first scan to fix

  1. 01

    Scan as usual

    Your orgs on their Vulkro Cloud schedule, your code in CI. No separate compliance run to remember.

    Vulkro Cloud
  2. 02

    Read the control view

    Every framework, every control, with the issues that fail it and the controls nothing could check.

    Vulkro Cloud
  3. 03

    Fix what fails several controls

    One finding often affects controls in several frameworks. Fixing it moves all of them.

    Vulkro Cloud
  4. 04

    Generate the pack for code

    A compliance pack per framework for each application repository, with file and line for every control.

    Vulkro Core
  5. 05

    Hand it to the auditor

    PDF for reading, CSV for the spreadsheet, checksums for integrity.

    Vulkro Cloud

04What you get

What you get

Same source
Evidence comes from the scan engineers already run, not a separate questionnaire.
Honest gaps
A control no check covers says Needs Evidence. A control the scan could not assess says Not Assessed.
Traceable
Each failing control cites the issues behind it, down to the file, setting or grant.
Continuous
Rescans update the control view, so the evidence is as current as the last scan.

Questions

Common questions

Does Vulkro make us compliant?
No tool does. Vulkro gives you evidence for the controls your code and orgs can speak to, and says plainly which controls need evidence from elsewhere.
Which frameworks are covered?
For Salesforce orgs in Vulkro Cloud: SOC 2, ISO 27001, HIPAA, PCI DSS 4.0 and NIST 800-53. For application code, the frameworks listed in the compliance documentation, from SOC 2 and ISO 27001 to OWASP ASVS and CIS Controls.
How is the mapping built?
By hand, per finding category, so one finding can cite controls in several frameworks at once. A mechanical CWE-to-control table misses what each control is for.

Evidence that stays current between audits.