All posts

Tutorial · July 9, 2026 · 8 min read

How to Add DPDPA & HIPAA Compliance Scanning to Your CI/CD Pipeline

Compliance shouldn't be a scramble the week before an audit. Here's how to catch DPDPA, HIPAA, GDPR and PCI-DSS problems on every pull request, offline, with no API key, in whatever pipeline you already run.

Shift compliance left

India's DPDP Act made data protection a board-level concern, and it joins HIPAA, GDPR and PCI-DSS as things your code is already accountable to. Yet most teams still discover compliance gaps in a pre-audit spreadsheet, long after the risky code shipped.

The fix is the same one that worked for security: move the check into the pipeline, so a problem is caught on the pull request that introduced it. Scrutora does exactly that, but instead of a generic “possible hardcoded secret,” it tells you which obligation the finding maps to (for example DPDPA §8(5)), with the severity and remediation an auditor will accept.

What makes it pipeline-friendly

  • Offline. The scan runs in a container on your own runner. No code, findings or telemetry leave; it even works in air-gapped or VPC-restricted pools.
  • No API key, no account. Nothing to provision.
  • Standard SARIF. Results render in GitHub Code Scanning, Azure DevOps, the VS Code SARIF viewer and any SARIF-aware tool.
  • One flag to gate a build. fail-on blocks a merge on high/critical findings, or you can run report-only.

The 5-minute version: GitHub Actions

Add .github/workflows/compliance.yml. Every pull request now gets a scan, and findings upload to the Security → Code scanning tab.

name: Compliance
on: [pull_request]
permissions:
  contents: read
  security-events: write   # required to upload SARIF
jobs:
  scrutora-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - id: scan
        uses: Scrutora/scrutora-scan@v1
        with:
          frameworks: dpdpa,hipaa
          fail-on: high        # none|low|medium|high|critical
      - if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: ${{ steps.scan.outputs.sarif-file }}

That's the whole thing. The GitHub Actions setup guide covers private-repo behaviour and PR annotations.

GitLab CI/CD

Add the CI/CD Catalog component to your pipeline:

include:
  - component: gitlab.com/scrutora-group/scrutora-scan/scan@~latest
    inputs:
      frameworks: dpdpa,hipaa
      fail_on: high

CircleCI

CircleCI runs the image directly as the job's executor:

jobs:
  scrutora-scan:
    docker:
      - image: ghcr.io/nirvahana/dpdp-scan:latest
    steps:
      - checkout
      - run: scan . --no-ai --frameworks dpdpa,hipaa --fail-on high
workflows:
  compliance:
    jobs:
      - scrutora-scan

Bitbucket Pipelines

Reference the pipe (no plugin install required):

- pipe: docker://nirvahana/scrutora-scan-pipe:1.1.1
  variables:
    FRAMEWORKS: dpdpa,hipaa
    FAIL_ON: high

Azure Pipelines

Install the Scrutora Scan extension for your organization, then add the task. SARIF renders on a build tab via the CodeAnalysisLogs artifact.

- task: ScrutoraScan@1
  inputs:
    frameworks: dpdpa,hipaa
    failOn: high

Full walkthrough in the Azure Pipelines setup guide.

Google Cloud Build

Cloud Build runs the image directly as a build step (no plugin, no Docker-in-Docker):

steps:
  - name: "ghcr.io/nirvahana/dpdp-scan:latest"
    args: ["scan", ".", "--no-ai",
           "--frameworks", "dpdpa,hipaa",
           "--fail-on", "high",
           "--sarif-output", "scrutora.sarif"]

Before it even reaches CI: pre-commit, Docker, VS Code

Block non-compliant code at commit time with a pre-commit hook:

repos:
  - repo: https://github.com/Scrutora/scrutora-scan
    rev: v1.0.0
    hooks:
      - id: scrutora-scan

Run it anywhere with plain Docker:

docker run --rm -v "$PWD:/src" -w /src \
  nirvahana/scrutora-scan scan . \
  --frameworks dpdpa,hipaa --fail-on high

Or catch findings while you type: the Scrutora VS Code extension scans your workspace and shows compliance findings inline in the Problems panel, before you push.

Reading the results

Every integration writes the same SARIF v2.1.0 report. Each finding carries the file and line, a severity, and the exact obligation it maps to, so the conversation with your security and compliance teams starts from the same evidence. Set fail-on: none while you triage the backlog, then tighten to high or critical to keep new violations out.

Pick your pipeline

Every one of these runs the same scanner, so you get identical findings whether they surface in a pull request, a build tab, or your editor. See all of them, with copy-paste snippets, on the integrations page.

Try it on your repo, free

No API key, no account, and your code never leaves your runner. Add one step and see what your pipeline has been missing.