ScrutoraCode, cloud & consent

It runs on your runner. Not on ours.

The scan happens inside your pipeline and returns SARIF, so findings land in the tools your engineers already have open and your source never has to leave the build.

01 · The same everywhere

One container, whatever your CI is called.

NO API KEY FOR CI

Scanning in a pipeline is free and needs no account. The gate works before anyone has decided to buy anything.

SARIF 2.1.0

Findings appear as annotations on the pull request that introduced them, next to the diff, while the author still has context.

WORKS OFFLINE

The scan runs entirely inside the step, so restricted build pools with no outbound access are fine.

02 · Try itPUBLIC REPOSITORIES

Add it to a pipeline.

A public repository, read once and not kept. You get the data map: every personal-data field, where it lands, and who receives it. Or run the container on your own runner, and the source never reaches us.