We ask you to trust us with less than you think.
The strongest security posture available to a code scanner is not needing your code. Where that is possible, we made it possible.
01 · What is true today
Six properties, each checkable.
Your source is not retained
The working copy is discarded when a scan ends. What persists is findings, which carry a path and a line number, not the file.
It can run entirely on your infrastructure
The scan is a container. In your pipeline, the analysis happens on your runner and the source never leaves the build.
No cloud keys are stored for AWS
You create a read-only role and pin an external id we generate. There is no access key of yours in our database to leak.
Secrets are envelope-encrypted
Cloud credentials and consent configuration are encrypted at rest, and the API never returns a stored secret, even to its owner.
Consent records are tamper-evident
Each record is hashed together with the one before it. Altering any record after capture breaks every hash downstream, and the chain check names which.
Scanning in CI needs no account
Pipeline scanning requires no API key, so a security team can evaluate the gate before anyone has an account to worry about.
02 · What we do not have
Said here rather than left for you to discover.
We are a small company and we do not hold a SOC 2 report or an ISO 27001 certificate. If your process requires one, we would rather you knew that from this page than from question forty of a questionnaire. What we can give you is the architecture above, the option to run the scan without sending us anything, and a direct answer to any question you want to ask.
03 · Reporting something
Tell us and we will fix it.
If you find a vulnerability in Scrutora, email security@scrutora.com. We will confirm receipt, keep you updated, and credit you if you want to be credited. We will not threaten you.