PDPL data scanner
Reads every file for Saudi National IDs, IBANs, and phone numbers left in code or config — the exact exposure a PDPL audit looks for, before it ships.
Five scanning engines run on every commit and turn into one live compliance score — the same score your dashboard shows and your auditor can verify, with nothing re-typed in between.
Already have an account? Sign in
Built for Saudi engineering teams shipping under NCA, SAMA, and PDPL requirements
The scan
Reads every file for Saudi National IDs, IBANs, and phone numbers left in code or config — the exact exposure a PDPL audit looks for, before it ships.
SQL injection, hardcoded secrets, insecure deserialization — caught on the line they were written, mapped straight to the NCA control they violate.
Every package, every known CVE, tracked individually — not collapsed into a single “vulnerabilities found” number that tells you nothing about what to fix first.
Terraform and Kubernetes misconfiguration, hardcoded credentials, and exposed keys — caught before the pipeline runs, not after the breach.
Every finding ships with a suggested fix. A human reviewer approves, edits, or rejects it before anything reaches your repository.
Compliance, not just security
Your NCA and SAMA scores update from the same scan, the same finding set, the same source of truth — so the number your CISO sees and the number your auditor asks about are never two different stories.
How it runs
GitHub, GitLab, or a ZIP upload. No agent to install on your infrastructure.
Code, dependencies, infrastructure, secrets, and PDPL exposure — in one pass.
Your CI/CD gate enforces the policy you set — critical findings stop the merge.
A signed, tamper-proof link your auditor can open — no login required.
Free for your first repository. No credit card, no sales call to start.