VS Code
Scan the open workspace and see compliance findings inline in the Problems panel, before you push. Runs locally via Docker; nothing leaves your machine.
4 steps.
Install Scrutora Scan from the VS Code Marketplace (or search “Scrutora” in the Extensions view).
The scan runs in a container, so Docker Desktop (macOS/Windows) or Docker Engine (Linux) must be available. The extension prompts you with a link if it isn't detected.
Run “Scrutora: Scan Workspace” from the Command Palette, or click the 🛡 Scrutora status-bar button. Findings appear in the Problems panel and inline in your files. Enable scan-on-save to re-scan as you work.
By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.
docker run --rm -v "$PWD:/src" -w /src \
-e SCRUTORA_API_KEY \
ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
scan . --no-ai \
--frameworks dpdpa,hipaa \
--json-output scrutora.json \
--output scrutora-report.pdf \
--upload
# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.
# ── GitHub Actions: use the action's own inputs instead ─────────────────────
# - id: scan
# uses: scrutora/scrutora-scan@v1
# with:
# upload: true
# api-key: ${{ secrets.SCRUTORA_API_KEY }}
# - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"After the first run.
Every finding with file, line and the obligation it maps to: navigable like any diagnostic.
See compliance issues on the exact line, in context, as you edit.
Optional automatic re-scan whenever you save a file.
The scan runs on your machine via Docker. No code, findings or telemetry leave.