Skip to content
Code audit · DPDP & GDPR · Security

Find the privacy and security leaks in your code.

Aadhaar numbers stored in plain text, phone numbers in log files, an account nobody can delete, a payment key committed by mistake. Connect your repository with a read-only key and get every gap — mapped to India's DPDP Rules, with the fix — in minutes.

  • Nothing to install
  • Read-only access
  • Code copy deleted after each scan
  • Works with GitHub and Bitbucket

A scan, as it happens. The repository is illustrative; the checks and their wording are real.

13

DPDP obligations

each finding is mapped to one

44

built-in checks

15 privacy, 29 security

0

things to install

connect with a read-only key

221

days left

until 13 May 2027

How it works

Four steps. About five minutes of your time.

No agent, no pipeline changes, nothing for your developers to install. If you can copy and paste, you can start a scan — and if you can't, send the ready-made message in the help guide to whoever looks after your code.

  1. 1 Connect Create a read-only key on GitHub or Bitbucket and paste it in. The page opens the right screen for you.
  2. 2 Choose Tick the repository, link it to the website it runs (or keep it code-only), pick the branches.
  3. 3 Scan We read the code on our own server. Nothing runs, nothing is changed, and the copy is deleted at the end.
  4. 4 Fix Read the report, download it, hand it to your developer. Every scan after that shows what is new and what got fixed.

What it checks

Everything a website check cannot see.

Our free website check reads your pages the way a visitor does. The code audit reads what happens after the form is submitted — where the data goes, how it is kept, and whether it can be taken back out.

Personal data — DPDP & GDPR

15 privacy checks, plus a map of every personal-data field

  • Data inventoryAadhaar, PAN, phone, email, bank, health, biometric and location fields — in database tables, models and forms.
  • Stored unencryptedSensitive fields kept as plain text instead of encrypted.
  • LeaksPersonal data written to logs, put in URLs or sent over plain HTTP.
  • Real data in the repoCustomer exports and seed files with real numbers (Aadhaar checked with its check digit).
  • ConsentForms with no notice, pre-ticked boxes, trackers loaded without consent.
  • ChildrenAge or date of birth collected with no parental-consent step.
  • People's rightsNo way to see, export or delete an account and its data.
  • Retention & logsLogs deleted before a year, no record of who accessed personal data.

Security — the breaches behind the fines

29 rules, plus known-vulnerable packages

  • InjectionSQL, command and code injection — following input from the request to where it is used.
  • Cross-site scriptingInput printed into a page without escaping.
  • Files & URLsPath traversal, open redirects, server-side request forgery.
  • Secrets in codeAPI keys, passwords and payment-gateway keys committed to the repository.
  • Vulnerable packagesComposer and npm packages with published security advisories, and the version that fixes them.
  • Forgotten toolsAdminer, phpMyAdmin, file managers and phpinfo pages left in the web root.
  • Risky settingsDebug mode left on, CSRF protection switched off, md5 passwords, unchecked uploads.
  • Deep analysisOptional Semgrep and Gitleaks engines for wider coverage.

Languages: PHP (Laravel, WordPress and plain PHP), JavaScript and Node.js, Blade and HTML templates, configuration files — and secrets in any file. Composer and npm dependencies.

The report

Organised the way the law is.

Next to the list of findings, every scan builds a DPDP report: the 13 obligations of the Act and Rules, what your code shows for each one, and the maximum penalty if it goes wrong.

  • Fix in code — Findings we can point to, file and line, with the change to make.
  • Evidence found — Something in the code that shows the obligation is handled — a delete-account route, a consent record.
  • Check by hand — What no scanner can know — contracts, staff training, where backups go. Listed so it is not forgotten.

Download it as CSV, JSON or a printable PDF for your board, auditor or client.

DPDP report · yourcompany/web-app

Sample · main · 7 gaps to fix in code

Download PDF
  • Reasonable security safeguards Section 8(5) · Rule 6(1)(a), (b), (g) · up to ₹250 crore 4 gaps Fix in code
  • Logs, monitoring and one-year retention Rule 6(1)(c), (e) · Rule 8(3) · up to ₹250 crore 2 gaps Fix in code
  • Access, correction and erasure requests Sections 11–14 · Rule 14 · up to ₹50 crore Evidence found
  • Tell people before you collect Section 5 · Rule 3 · up to ₹50 crore Evidence found
  • Children (under 18) and persons with disability Section 9 · Rules 10–12 · up to ₹200 crore Check by hand
  • Processors and transfers outside India Section 8(1)–(2), 16 · Rules 6(1)(f), 15 · up to ₹50 crore Check by hand
  • Breach notification within 72 hours Section 8(6) · Rule 7 · up to ₹200 crore Check by hand

A sample with illustrative results. Real reports show all 13 obligations.

Who uses it

Founders & owners

A plain list of what to fix before May 2027, without hiring a consultant to find it.

Developers & CTOs

File, line, why and the fix. Rescan on every push and watch the list shrink.

Agencies

A report per client site — a new retainer line you can deliver in an afternoon.

Compliance & DPOs

Evidence organised by obligation, with what still needs a manual check.

Your code is safe with us

We built it the way we tell you to build yours.

Read-only key It can read the repository and nothing else. We never push, comment or open pull requests.
No copy kept The code is cloned for the scan and deleted when it ends. We keep the findings, not your code.
Masked results Secrets and personal data in the lines we show are masked — never the full number or key.
Nothing runs The scan reads files. Your code, build scripts and install hooks are never executed.
Separate scanner Scans run as their own locked-down user, apart from the rest of the platform. Keys are encrypted at rest.
Proof of ownership Results only show once the repository is confirmed as yours — nobody can scan code that is not theirs.

More in our security page, privacy notice and data processing agreement.

Help guide

Your first scan, step by step.

Once you have an account, this is all there is to it. The console walks you through the same steps with pictures.

1. Create a read-only key where your code lives

  1. On GitHub: your picture → Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token.
  2. Resource owner: the organisation that owns the repository. Repository access: Only select repositories → pick it.
  3. Permissions → Repository permissions → Contents: Read-only. (Metadata turns on by itself.) Leave everything else.
  4. Choose an expiry, press Generate token and copy it — GitHub shows it once.
  1. On Bitbucket: your Atlassian account → Security → Create and manage API tokens.
  2. Press Create API token with scopes (not the plain "Create API token"), name it, choose an expiry, app Bitbucket.
  3. Scopes: read:repository:bitbucket and read:user:bitbucket. Nothing else.
  4. Copy the token. In Servertorch you will enter it with the email you sign in to Bitbucket with.

Not technical? Send this to your developer:

Hi, we use Servertorch to check our website's code for privacy and security problems. Could you create a READ-ONLY access token for the repository (GitHub: fine-grained token with Contents: Read-only; Bitbucket: API token with read:repository:bitbucket and read:user:bitbucket) and send it to me? It only lets Servertorch read the code, never change it. Thanks!

2. Connect it

In Servertorch: Code audit → Add connection → choose GitHub or Bitbucket → paste the key → Connect. We check it works and that it can only read.

3. Add the repository

Add repository → tick it → link it to the website it runs (or choose No website — code only) → pick the branches and how often to scan → Add and scan.

4. Confirm it is yours

If the Servertorch agent is on that website, this happens on its own — we compare files. Otherwise commit the one-line .servertorch-verify file the page gives you (copy, paste, push). Results show as soon as it is confirmed.

5. Read and share the report

Open the scan: findings by severity with the fix, a DPDP report button for the obligation view, and Download for CSV, JSON or PDF. Mark a finding accepted or dismissed with a reason and it will not alert again.

6. Keep it current

Turn on Scan on every push (a webhook the page sets up with you) or a daily/weekly schedule. New high or critical findings arrive by email; fixed ones close by themselves.

FAQ

Questions people ask first.

Do you keep a copy of my code?

No. The repository is cloned on our server for the scan and deleted when the scan ends. We keep the findings and a few lines around each one, with secrets and personal data masked.

Can it change my code or push anything?

No. The key you create is read-only, and Servertorch never writes to your repository — no commits, comments or pull requests.

Does it run my code?

No. It reads files. Dependency checks read your lock files (composer.lock, package-lock.json); install scripts are never run.

Which code hosts are supported?

GitHub and Bitbucket Cloud, public or private repositories. GitLab and self-hosted Git are not supported yet — tell us if you need them.

Which languages?

PHP (Laravel, WordPress, plain PHP), JavaScript and Node.js, Blade and HTML templates and configuration files, plus secrets in any file and Composer/npm dependencies. Deep analysis adds Semgrep and Gitleaks.

How long does a scan take?

Most repositories finish in a few minutes; very large ones take longer. You can close the page — new high or critical findings come to you by email.

Does a clean report mean we are DPDP compliant?

No, and nobody honest will tell you a scan does. Compliance also covers contracts, processes, staff and your vendors. The report shows what the code does, and lists what has to be checked by hand.

Does it cover the GDPR too?

Yes, in substance. The report is organised by India's DPDP Rules, but the same gaps — security of processing, storage limits, erasure and access, consent — matter equally under the GDPR.

What if a finding is wrong, or intended?

Dismiss it or accept it as a risk, with a reason. It will not alert again, and the decision is kept in the audit log.

Why do I have to confirm the repository is mine?

So nobody can connect someone else's code and read its weaknesses. It is automatic when our agent is on the website; otherwise you commit a one-line file.

Who can see the results?

Only people in your Servertorch account, by role. Viewers can read; owners and managers can change settings.

What does it cost?

Code audit is part of Servertorch plans; scheduled scans, scan-on-push and deep analysis depend on the plan. We size it with you on a short call — see the plans page or ask us.

221 days until 13 May 2027

Website fixes take an afternoon. Code fixes take sprints.

Penalties under the DPDP Act reach ₹250 crore for failing to protect personal data. Start with the list — the earlier you have it, the calmer May will be.

No tracking cookies here

We only use the cookies needed to sign you in and keep forms safe — no analytics, no ads, nothing to accept.

Cookie notice