Use case · Regulated companies
Audit evidence from the scan you already run.
Auditors ask how each control is met, and the answer usually lives in a spreadsheet someone fills in by hand. Vulkro maps every finding to the controls it affects and hands you the evidence, control by control, with the file, setting or grant behind each one.
Vulkro Cloud · Vulkro Core · Vulkro for Salesforce
01The problem
Audit evidence is usually collected by hand, once a year
Security findings and audit controls describe the same risks in two languages, and someone translates between them every cycle.
Findings and controls are not linked
The scanner reports a missing field-level check. The auditor asks about access control. Nobody connects the two.
Evidence covers only the audit window
Evidence gathered for the audit window says nothing about the eleven months either side of it.
Unchecked controls look like passes
A control no tool checked looks the same as a control that passed, until an auditor asks for proof.
02How Vulkro handles it
What each part of Vulkro does
- SOC 2, ISO 27001, HIPAA, PCI DSS 4.0 and NIST 800-53, computed from the open issues of each org
- Each control marked Pass, Partial, Fail, Needs Evidence or Not Assessed, never passed by default
- Evidence packs as PDF and CSV, each file with its SHA-256 checksum
- An Auditor role among the workspace roles, scoped per org
- Control evaluation for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, OWASP ASVS, NIST SSDF, NIST 800-53, CIS Controls v8 and more
- A compliance pack per framework: a manifest, findings as CSV and evidence per control with file and line
- GDPR Article 30 records of processing, and an SBOM in CycloneDX or SPDX
- Control reports for SOX, PCI, HIPAA and GDPR from a Salesforce scan
- Evidence exports for SOC 2, HIPAA, ISO and FedRAMP assessment workflows
- A HIPAA safeguard matrix and a GDPR record of processing
03The workflow
Steps from first scan to fix
- 01Vulkro Cloud
Scan as usual
Your orgs on their Vulkro Cloud schedule, your code in CI. No separate compliance run to remember.
- 02Vulkro Cloud
Read the control view
Every framework, every control, with the issues that fail it and the controls nothing could check.
- 03Vulkro Cloud
Fix what fails several controls
One finding often affects controls in several frameworks. Fixing it moves all of them.
- 04Vulkro Core
Generate the pack for code
A compliance pack per framework for each application repository, with file and line for every control.
- 05Vulkro Cloud
Hand it to the auditor
PDF for reading, CSV for the spreadsheet, checksums for integrity.
04What you get
What you get
- Same source
- Evidence comes from the scan engineers already run, not a separate questionnaire.
- Honest gaps
- A control no check covers says Needs Evidence. A control the scan could not assess says Not Assessed.
- Traceable
- Each failing control cites the issues behind it, down to the file, setting or grant.
- Continuous
- Rescans update the control view, so the evidence is as current as the last scan.
Questions
Common questions
- Does Vulkro make us compliant?
- No tool does. Vulkro gives you evidence for the controls your code and orgs can speak to, and says plainly which controls need evidence from elsewhere.
- Which frameworks are covered?
- For Salesforce orgs in Vulkro Cloud: SOC 2, ISO 27001, HIPAA, PCI DSS 4.0 and NIST 800-53. For application code, the frameworks listed in the compliance documentation, from SOC 2 and ISO 27001 to OWASP ASVS and CIS Controls.
- How is the mapping built?
- By hand, per finding category, so one finding can cite controls in several frameworks at once. A mechanical CWE-to-control table misses what each control is for.