Shift compliance left
India's DPDP Act made data protection a board-level concern, and it joins HIPAA, GDPR and PCI-DSS as things your code is already accountable to. Yet most teams still discover compliance gaps in a pre-audit spreadsheet, long after the risky code shipped.
The fix is the same one that worked for security: move the check into the pipeline, so a problem is caught on the pull request that introduced it. Scrutora does exactly that, but instead of a generic “possible hardcoded secret,” it tells you which obligation the finding maps to (for example DPDPA §8(5)), with the severity and remediation an auditor will accept.
What makes it pipeline-friendly
- Offline. The scan runs in a container on your own runner. No code, findings or telemetry leave; it even works in air-gapped or VPC-restricted pools.
- No API key, no account. Nothing to provision.
- Standard SARIF. Results render in GitHub Code Scanning, Azure DevOps, the VS Code SARIF viewer and any SARIF-aware tool.
- One flag to gate a build.
fail-onblocks a merge on high/critical findings, or you can run report-only.
The 5-minute version: GitHub Actions
Add .github/workflows/compliance.yml. Every pull request now gets a scan, and findings upload to the Security → Code scanning tab.
name: Compliance
on: [pull_request]
permissions:
contents: read
security-events: write # required to upload SARIF
jobs:
scrutora-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- id: scan
uses: Scrutora/scrutora-scan@v1
with:
frameworks: dpdpa,hipaa
fail-on: high # none|low|medium|high|critical
- if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ steps.scan.outputs.sarif-file }}That's the whole thing. The GitHub Actions setup guide covers private-repo behaviour and PR annotations.
GitLab CI/CD
Add the CI/CD Catalog component to your pipeline:
include:
- component: gitlab.com/scrutora-group/scrutora-scan/scan@~latest
inputs:
frameworks: dpdpa,hipaa
fail_on: highCircleCI
CircleCI runs the image directly as the job's executor:
jobs:
scrutora-scan:
docker:
- image: ghcr.io/nirvahana/dpdp-scan:latest
steps:
- checkout
- run: scan . --no-ai --frameworks dpdpa,hipaa --fail-on high
workflows:
compliance:
jobs:
- scrutora-scanBitbucket Pipelines
Reference the pipe (no plugin install required):
- pipe: docker://nirvahana/scrutora-scan-pipe:1.1.1
variables:
FRAMEWORKS: dpdpa,hipaa
FAIL_ON: highAzure Pipelines
Install the Scrutora Scan extension for your organization, then add the task. SARIF renders on a build tab via the CodeAnalysisLogs artifact.
- task: ScrutoraScan@1
inputs:
frameworks: dpdpa,hipaa
failOn: highFull walkthrough in the Azure Pipelines setup guide.
Google Cloud Build
Cloud Build runs the image directly as a build step (no plugin, no Docker-in-Docker):
steps:
- name: "ghcr.io/nirvahana/dpdp-scan:latest"
args: ["scan", ".", "--no-ai",
"--frameworks", "dpdpa,hipaa",
"--fail-on", "high",
"--sarif-output", "scrutora.sarif"]Before it even reaches CI: pre-commit, Docker, VS Code
Block non-compliant code at commit time with a pre-commit hook:
repos:
- repo: https://github.com/Scrutora/scrutora-scan
rev: v1.0.0
hooks:
- id: scrutora-scanRun it anywhere with plain Docker:
docker run --rm -v "$PWD:/src" -w /src \
nirvahana/scrutora-scan scan . \
--frameworks dpdpa,hipaa --fail-on highOr catch findings while you type: the Scrutora VS Code extension scans your workspace and shows compliance findings inline in the Problems panel, before you push.
Reading the results
Every integration writes the same SARIF v2.1.0 report. Each finding carries the file and line, a severity, and the exact obligation it maps to, so the conversation with your security and compliance teams starts from the same evidence. Set fail-on: none while you triage the backlog, then tighten to high or critical to keep new violations out.
Pick your pipeline
Every one of these runs the same scanner, so you get identical findings whether they surface in a pull request, a build tab, or your editor. See all of them, with copy-paste snippets, on the integrations page.