Skip to main content

Use case · Salesforce consultancies and SIs

The same security review for every client org.

Each client org is a different shape, and each review starts from a blank page. Vulkro gives your team one method for all of them: the same checks, a baseline on day one, and evidence the client can read.

Vulkro Cloud · Vulkro for Salesforce

acme.vulkro.comWorkspace · 4 orgs
Posture81/100+9 since last scan
Open issues376 fixed · 2 new
Attack paths31 reaches personal data
Fix firstranked by reach and severity
  1. 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
  2. 2VK-188Integration user holds Modify All DataIdentityHigh
  3. 3VK-231Connected app allows all users, no IP rangeExposureHigh
  4. 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
Changes5 Oct compared with 28 Sep: 6 fixed, 2 new, 1 reopened

01The problem

Each client review uses a different method

The work is skilled. The method is usually a spreadsheet and the memory of whoever ran the last review.

  • Reviews do not repeat

    Two consultants on two orgs check different things, and the client cannot compare one review with the next.

  • No before and after

    At the end of the engagement it is hard to show what you fixed, and what was already broken when you arrived.

  • Evidence is screenshots

    A finding with no file, no setting and no path is an opinion. Clients and their auditors want the trail.

03The workflow

Steps from first scan to fix

  1. 01

    Scan on day one

    Run Vulkro for Salesforce over the client project and, with access, the live org. Nothing is installed in the org and nothing is changed.

    Vulkro for Salesforce
  2. 02

    Freeze the baseline

    Write the day-one findings as a baseline. From now on every scan separates what you found from what is new.

    Vulkro for Salesforce
  3. 03

    Hand the client the list

    Connect the org to the workspace, assign issues to the client team and route them to their Jira or chat.

    Vulkro Cloud
  4. 04

    Rescan as fixes land

    Issues a scan no longer finds are marked fixed on their own, so progress is measured, not reported.

    Vulkro Cloud
  5. 05

    Close with evidence

    Net-new against net-fixed, and a report per org the client can keep.

    Vulkro for Salesforce

04What you get

What you get

Repeatable
The same checks on every org, so one review compares with the next.
Measured
A day-one baseline, and net-new against net-fixed at the end of the engagement.
Traceable
Every finding names the file, the setting or the grant behind it.
Shareable
A guest-exposure summary edition with counts and verdicts only, safe to send outside the team (Pro).

Questions

Common questions

Is there a partner plan with a workspace per client?
Not as a self-serve plan today. Talk to us about how many client orgs you run and we will set it up with you.
Does anything get installed in the client org?
No. Vulkro for Salesforce reads the org through your own sf CLI login, read-only. Code and metadata scans run on your machine.
Can each consultant work offline at a client site?
Source scans run fully offline. Live-org reads need a route to the org, so they are refused under the offline switch.

One method for every client org.