VulTech — Enterprise Application Security for VS Code & Cursor
VulTech brings unified SAST, software composition analysis (SCA), and compliance mapping into your IDE — the same detection engine as the VulTech platform.
Works with VS Code, Cursor, cloud SSO, and air-gapped on-prem deployments.
Features
SAST — Rule and taint-based findings with CWE/OWASP metadata, inline diagnostics, and quick actions
SCA — Dependency manifests (package.json, lockfiles, requirements.txt, etc.) sent with unified scans; CVE details in the Dependencies sidebar
Compliance — Maps findings to frameworks (OWASP, NIST, etc.) when enabled on your deployment
Deployment profiles — cloud, on-prem, or custom API URL
Auth — SSO Sign In, password login (on-prem), or paste JWT (stored in SecretStorage)
Quick start
Install the extension from the Marketplace (or install from VSIX).
Open Settings → search vultech:
Cloud: default — click Authenticate in the VulTech sidebar or run VulTech: Sign In