VS Code

Scan the open workspace and see compliance findings inline in the Problems panel, before you push. Runs locally via Docker; nothing leaves your machine.

01 · Setup

4 steps.

01Install the extension

Install Scrutora Scan from the VS Code Marketplace (or search “Scrutora” in the Extensions view).

02Make sure Docker is running

The scan runs in a container, so Docker Desktop (macOS/Windows) or Docker Engine (Linux) must be available. The extension prompts you with a link if it isn't detected.

03Scan your workspace

Run “Scrutora: Scan Workspace” from the Command Palette, or click the 🛡 Scrutora status-bar button. Findings appear in the Problems panel and inline in your files. Enable scan-on-save to re-scan as you work.

04Optional: keep the results in Scrutora

By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.

docker run --rm -v "$PWD:/src" -w /src \
  -e SCRUTORA_API_KEY \
  ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
  scan . --no-ai \
    --frameworks dpdpa,hipaa \
    --json-output scrutora.json \
    --output scrutora-report.pdf \
    --upload

# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.

# ── GitHub Actions: use the action's own inputs instead ─────────────────────
#   - id: scan
#     uses: scrutora/scrutora-scan@v1
#     with:
#       upload: true
#       api-key: ${{ secrets.SCRUTORA_API_KEY }}
#   - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"
02 · What you get

After the first run.

Problems panel findings

Every finding with file, line and the obligation it maps to: navigable like any diagnostic.

Inline squiggles

See compliance issues on the exact line, in context, as you edit.

Scan on save

Optional automatic re-scan whenever you save a file.

Fully local

The scan runs on your machine via Docker. No code, findings or telemetry leave.

03 · Questions

The ones people actually ask.

Do I need Docker?

Yes. The extension runs the scanner container locally, so Docker Desktop or Docker Engine must be installed and running.

Does my code leave my machine?

No. Everything runs locally in the container; nothing is uploaded to Scrutora or any third party.

Which frameworks does it check?

DPDPA, HIPAA, GDPR, PCI-DSS and more, configurable in the extension settings.

VS Code Marketplace