Every misconfiguration, cited to the clause it breaks.

Checkov and tfsec are good at this and free. The difference here is not detection, it is that every finding lands in the same register as your code and cloud findings, citing the same clause.

terraformkuberneteshelmdockerfilecomposecloudformationbicepansiblegithub actionsgitlab cijenkins

11 formats, read as configuration rather than as text.

01 · The difference

A benchmark id tells you nothing about your exposure.

A BENCHMARK SAYS

CKV_AWS_21: ensure versioning is enabled. True, generic, and identical for every organisation on earth.

THIS SAYS

This store holds personal data classified in your own scan, and losing it breaches the safeguards clause you are actually subject to.

WHICH MATTERS BECAUSE

Priority comes from what the resource holds. Two identical misconfigurations are not equally urgent if only one is on a path to personal data.

02 · The gap in the fieldDPDP · RBI IT

Indian regulation, not an afterthought.

The established IaC scanners map to CIS, SOC 2 and PCI. Almost none map to DPDP or the RBI IT framework, which are the two that matter if you are shipping from India into finance or health. Those mappings are the reason this exists alongside the free tools rather than instead of them.

Run both. Checkov in your pipeline for breadth of Terraform checks, and Scrutora for the obligation mapping and the join to what your code actually stores. They are not the same job.

03 · In the pipeline

SARIF, so it lands where your team already looks.

Findings arrive as SARIF 2.1.0 and appear as annotations on the pull request that introduced them, next to the diff, while the author still has the context. A misconfiguration caught at review is a comment; the same one caught after deploy is an incident.