Your code says where data goes. Your cloud says where it rests.
The same personal data your repository hands off has to land somewhere. Scrutora grades the account it actually lands in, against the same clauses it used on the code.
A bucket policy and a Java file, in the same language.
Posture tools speak in benchmarks; code scanners speak in rule ids; nobody speaks the language of the obligation. These rules cite the exact clause, which is the same clause the code scanner cites, so both halves of a finding arrive in one place.
Twenty-seven services across three providers.
What passed on Monday can drift by Friday.
A posture report is true for the minute it was produced. Scrutora keeps the snapshot and diffs the next one against it, so what you see is not just today’s state but what somebody changed since the last look, and when.
The differ refuses to compare two different accounts. A drift report built from mismatched estates would be confidently wrong, which is worse than absent, so it raises rather than guesses.
A read-only role. We never hold your keys.
For AWS you create a read-only role and we assume it. There is no access key of yours sitting in our database to leak.
We generate a unique, unguessable id per connection and you pin it in the role's trust policy. It stops anyone talking us into assuming a role that is not theirs.
The collectors call list and describe operations only. Nothing in the posture path can modify your account, by construction.
Azure and GCP use a service principal and a service account respectively, scoped the same way, and every stored secret is envelope-encrypted.