ScrutoraCode, cloud & consent

What it covers, and what it does not.

Every figure here is generated from the scanner rather than written by hand, and a test fails the build if anyone types one back in.

270+Rules
26Frameworks
12Languages
11IaC formats
31Cloud rules
01 · The limits

Stated first, not in a footnote.

DEPTH VARIES BY LANGUAGE

Java, Python and JavaScript get the deepest analysis. Others are supported and detect less. A language on the list is not a promise of equal depth.

RUNTIME DESTINATIONS

A call whose target the program computes at runtime cannot be followed. The scan reports how many it could not resolve rather than omitting them.

ORGANISATIONAL DUTIES

Training, minutes, appointments, assessments. No scanner evidences these and we do not imply otherwise.

NOT A PENETRATION TEST

This reads code and configuration. It does not attack a running system, and it is not a substitute for something that does.

02 · Languages and formats

12 languages, 11 infrastructure formats.

Source
JavaPythonJavaScript / TypeScriptGoRubyPHPC#RustSwiftKotlinScalaPL/SQL
Infrastructure
TerraformKubernetesHelmDockerfileDocker ComposeCloudFormationBicepAnsibleGitHub ActionsGitLab CIJenkins

JavaScript and TypeScript share a parser and count once. PL/SQL is counted separately because it is a distinct grammar rather than a dialect.

03 · FrameworksCODE + CLOUD

By how many rules cite them.

All 26, with the distinct-rule calculator →

04 · Try itPUBLIC REPOSITORIES

See what it finds in yours.

A public repository, read once and not kept. You get the data map: every personal-data field, where it lands, and who receives it. Or run the container on your own runner, and the source never reaches us.