Pillar 02 · Security & Compliance
Petika scans your codebase for vulnerabilities and secrets, then maps every finding to the exact compliance control it affects, DPDP, SOC 2, ISO 27001, PCI-DSS.
Sanskrit: “vault / casket”

A compliance-aware scan sweeps your code, surfacing what puts you at risk.
The problem
Security scanners produce findings a developer understands but a compliance officer can’t act on, and none map those findings to India’s DPDP Act. Teams are left translating raw vulnerabilities into audit evidence by hand.
Runs industry-standard scanners: static analysis (SAST), dependency/CVE, container, and history-aware secrets detection.
A language-model layer adds plain-language remediation guidance to each finding.
Every finding is mapped to a specific control, DPDP, SOC 2, ISO 27001, PCI-DSS.
Produces an audit-ready assessment a compliance officer can act on, not just a developer.
Static code analysis catches insecure patterns before they ship.
Flags known vulnerabilities across your dependency tree and containers.
History-aware scanning finds leaked keys and tokens across your git history.
DPDP-first, plus SOC 2 / ISO 27001 / PCI, the layer that makes a scan audit-ready.