Your code says where data goes. Your cloud says where it rests.

The same personal data your repository hands off has to land somewhere. Scrutora grades the account it actually lands in, against the same clauses it used on the code.

3Providers
73Posture rules
Read-onlyAccess we ask for
01 · One registerNOT TWO TOOLS

A bucket policy and a Java file, in the same language.

Posture tools speak in benchmarks; code scanners speak in rule ids; nobody speaks the language of the obligation. These rules cite the exact clause, which is the same clause the code scanner cites, so both halves of a finding arrive in one place.

CSPM-S3-MFA-DELETE-001
Object deletion is not protected by MFA
DPDP §8(5) · HIPAA §164.312(a)(2)(iv) · PCI 3.5.1
CSPM-IAM-ROOT-MFA-001
The root account has no MFA
DPDP §8(5) · PCI 8.3
CSPM-CLOUDTRAIL-001
Activity is not being recorded
RBI IT Annex B · PCI 10.5 · HIPAA §164.312(b)
CSPM-EBS-ENCRYPTION-001
Volumes are unencrypted at rest
HIPAA §164.312(a)(2)(iv) · DPDP §8(3) · PCI 3.5
CSPM-BACKUP-VAULT-001
No recovery point for a regulated store
HIPAA §164.308(a)(7)(ii)(A) · DPDP §8(5)
02 · What it reads

Twenty-seven services across three providers.

AWS
9 services
s3iamkmslambdabackupcloudwatchinspectorsecretsmanagersecurity services
Azure
11 services
storageaadaksapp servicecosmosdefenderkey vaultmonitornetworkpostgressql
GCP
7 services
storageiamkmsgkefirewallsqlscc
03 · DriftSNAPSHOT DIFF

What passed on Monday can drift by Friday.

A posture report is true for the minute it was produced. Scrutora keeps the snapshot and diffs the next one against it, so what you see is not just today’s state but what somebody changed since the last look, and when.

The differ refuses to compare two different accounts. A drift report built from mismatched estates would be confidently wrong, which is worse than absent, so it raises rather than guesses.

daily snapshot · one account1 drift finding
Mon
baseline
Tue
no change
Wed
no change
Thu
bucket policy widened
Fri
still open
04 · The access we ask for

A read-only role. We never hold your keys.

NO STORED CREDENTIALS

For AWS you create a read-only role and we assume it. There is no access key of yours sitting in our database to leak.

AN EXTERNAL ID YOU PIN

We generate a unique, unguessable id per connection and you pin it in the role's trust policy. It stops anyone talking us into assuming a role that is not theirs.

READ, NEVER WRITE

The collectors call list and describe operations only. Nothing in the posture path can modify your account, by construction.

Azure and GCP use a service principal and a service account respectively, scoped the same way, and every stored secret is envelope-encrypted.