Every misconfiguration, cited to the clause it breaks.
Checkov and tfsec are good at this and free. The difference here is not detection, it is that every finding lands in the same register as your code and cloud findings, citing the same clause.
11 formats, read as configuration rather than as text.
A benchmark id tells you nothing about your exposure.
CKV_AWS_21: ensure versioning is enabled. True, generic, and identical for every organisation on earth.
This store holds personal data classified in your own scan, and losing it breaches the safeguards clause you are actually subject to.
Priority comes from what the resource holds. Two identical misconfigurations are not equally urgent if only one is on a path to personal data.
Indian regulation, not an afterthought.
The established IaC scanners map to CIS, SOC 2 and PCI. Almost none map to DPDP or the RBI IT framework, which are the two that matter if you are shipping from India into finance or health. Those mappings are the reason this exists alongside the free tools rather than instead of them.
Run both. Checkov in your pipeline for breadth of Terraform checks, and Scrutora for the obligation mapping and the join to what your code actually stores. They are not the same job.
SARIF, so it lands where your team already looks.
Findings arrive as SARIF 2.1.0 and appear as annotations on the pull request that introduced them, next to the diff, while the author still has the context. A misconfiguration caught at review is a comment; the same one caught after deploy is an incident.