ScrutoraCode, cloud & consent

The output, before you hand over anything.

A real scan of a public core-banking platform. Not a mock-up, and not behind a form.

01 · The queue

Findings, grouped by the obligation they touch.

The findings list grouped by framework, with severity and status filters.
Grouping by obligation rather than by file is what turns a backlog into a plan.
02 · One finding

Why it matters, the path, and the fix.

A finding with the reason it matters, the data-flow trace, a concrete fix, and the clauses it maps to.
The trace is the part that matters: parameter, use, and the line that logs it unmasked.
03 · The map

Every field, and where it ends up.

The exposure view: tracked fields flowing to database stores, application logs and encrypted stores.
Red is an unprotected path. The ratio is usually the first thing people react to.
04 · The record

Pre-filled from the code.

The Record of Processing overview with data categories, recipients and policy field completion.
Categories and recipients are derived. The policy fields stay yours.
Run one on your repoHow the scan works