Use case · Salesforce consultancies and SIs
The same security review for every client org.
Each client org is a different shape, and each review starts from a blank page. Vulkro gives your team one method for all of them: the same checks, a baseline on day one, and evidence the client can read.
Vulkro Cloud · Vulkro for Salesforce
- 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
- 2VK-188Integration user holds Modify All DataIdentityHigh
- 3VK-231Connected app allows all users, no IP rangeExposureHigh
- 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
01The problem
Each client review uses a different method
The work is skilled. The method is usually a spreadsheet and the memory of whoever ran the last review.
Reviews do not repeat
Two consultants on two orgs check different things, and the client cannot compare one review with the next.
No before and after
At the end of the engagement it is hard to show what you fixed, and what was already broken when you arrived.
Evidence is screenshots
A finding with no file, no setting and no path is an opinion. Clients and their auditors want the trail.
02How Vulkro handles it
What each part of Vulkro does
- Each client org connected, scanned on its own schedule and kept across scans
- Roles scoped per org, so each consultant and each client stakeholder sees only their orgs
- Triage with approval: an accepted risk stays counted until someone else approves it
- A printable Security Report per org, under Reports & exports
- 753 checks, 147 on the live org and 606 on code and metadata, the same on every engagement
- A baseline on day one, then net-new against net-fixed at the end
- A live-org posture report through your own sf CLI login, read-only (Pro)
- Every client org rolled up into one portfolio view (Pro)
03The workflow
Steps from first scan to fix
- 01Vulkro for Salesforce
Scan on day one
Run Vulkro for Salesforce over the client project and, with access, the live org. Nothing is installed in the org and nothing is changed.
- 02Vulkro for Salesforce
Freeze the baseline
Write the day-one findings as a baseline. From now on every scan separates what you found from what is new.
- 03Vulkro Cloud
Hand the client the list
Connect the org to the workspace, assign issues to the client team and route them to their Jira or chat.
- 04Vulkro Cloud
Rescan as fixes land
Issues a scan no longer finds are marked fixed on their own, so progress is measured, not reported.
- 05Vulkro for Salesforce
Close with evidence
Net-new against net-fixed, and a report per org the client can keep.
04What you get
What you get
- Repeatable
- The same checks on every org, so one review compares with the next.
- Measured
- A day-one baseline, and net-new against net-fixed at the end of the engagement.
- Traceable
- Every finding names the file, the setting or the grant behind it.
- Shareable
- A guest-exposure summary edition with counts and verdicts only, safe to send outside the team (Pro).
Questions
Common questions
- Is there a partner plan with a workspace per client?
- Not as a self-serve plan today. Talk to us about how many client orgs you run and we will set it up with you.
- Does anything get installed in the client org?
- No. Vulkro for Salesforce reads the org through your own sf CLI login, read-only. Code and metadata scans run on your machine.
- Can each consultant work offline at a client site?
- Source scans run fully offline. Live-org reads need a route to the org, so they are refused under the offline switch.