CircleCI

Add the certified orb, call the scan job with your frameworks, and gate builds on compliance findings. Offline, no API key, and your code never leaves the executor.

01 · Setup

3 steps.

01Add the scan job

CircleCI runs the scanner image directly as the job's executor, there is nothing to install.

version: 2.1
jobs:
  scrutora-scan:
    docker:
      - image: ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461
    steps:
      - checkout
      - run:
          name: Scrutora compliance scan
          command: |
            scan . --no-ai \
              --frameworks dpdpa,hipaa \
              --fail-on high \
              --sarif-output /tmp/scrutora.sarif
      - store_artifacts:
          path: /tmp/scrutora.sarif
workflows:
  compliance:
    jobs:
      - scrutora-scan
02Run the workflow

The job scans offline and stores the SARIF report as a build artifact. fail-on fails the job when a finding at or above your chosen severity is present.

03Optional: keep the results in Scrutora

By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.

docker run --rm -v "$PWD:/src" -w /src \
  -e SCRUTORA_API_KEY \
  ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
  scan . --no-ai \
    --frameworks dpdpa,hipaa \
    --json-output scrutora.json \
    --output scrutora-report.pdf \
    --upload

# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.

# ── GitHub Actions: use the action's own inputs instead ─────────────────────
#   - id: scan
#     uses: scrutora/scrutora-scan@v1
#     with:
#       upload: true
#       api-key: ${{ secrets.SCRUTORA_API_KEY }}
#   - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"
02 · What you get

After the first run.

Build gating

fail-on fails the job on high/critical findings, or run report-only.

SARIF artifact

The report is stored as a CircleCI artifact for download and review.

Obligation citations

Every finding cites the exact obligation, not a generic rule id.

No plugin

It's a standard orb, with nothing to install on your executors.

03 · Questions

The ones people actually ask.

Where do the results appear?

In the job output, and as a stored SARIF artifact on the build for download.

Which frameworks are supported?

DPDPA, HIPAA, GDPR, PCI-DSS, RBI and more, set the frameworks parameter.

Is it free?

Yes, the CI scanning is free with no API key or account.

CircleCI Orb Registry