Aevral
GitHub app that scans repos and reviews PRs for authorization, IDOR, and logic flaws
Overview
Aevral is a GitHub security app built as an alternative to Claude Security. Two products, one install, neither requires the other.
Whole-repo scans: deep at-rest scans of your repository for authorization, IDOR, and business-logic flaws. Every finding is a lead with evidence from your own code. Coverage verdicts are honest: an incomplete scan says so. You get a fix prompt for Claude Code, Cursor, or Codex.
PR review: a reviewer on every pull request, opt-in per organization. A Check plus inline comments on the added lines, for authorization and business-logic flaws. Nothing merges without you.
- Public repositories scan free
- 25 free private PR reviews every month, no card
- Open-source models, hosted in the US or the EU
- Priced per organization, never per seat
Scan plans (EUR per organization per month, excluding VAT):
- Public repositories: 0, 1 authorized public-repo scan per calendar month
- Team: 99, 4 scans then 29 per extra scan
- Business: 399, 16 scans then 19
- Scale: 1,699, 100 scans then 17
- Enterprise: by quote
PR review plans (USD per organization per month, excluding VAT):
- Free: 0, 25 private reviews per month
- Starter: 19, 100 included then 0.49 per extra review
- Pro: 99, 500 included then 0.49
- Business: 249, 2,000 included then 0.49
Built by ISMS Copilot.
Aevral in a Nutshell
Who is it for?
Developers and security engineers who manage GitHub repos and want automated reviews for authorization, IDOR, and business-logic flaws.
Problem
Teams struggle to detect authorization and logic flaws across large codebases, often relying on manual reviews that miss issues. PR reviews can be slow or inconsistent, and open-source or free-tier scans may miss deeper, in-repo vulnerabilities.
Solution
Aevral integrates as a GitHub app to perform whole-repo at-rest scans and provide a PR reviewer for added lines, delivering evidence-backed findings and fix prompts tailored to Claude Code, Cursor, or Codex. It offers configurable scans by organization and opt-in PR reviews to prevent merges without validation.
What makes it unique
It combines deep at-rest repo scans with an opt-in PR review system that inspects each added line for authorization and business-logic flaws, backed by evidence from your own code. It also differentiates itself with open public repo scans, a generous free tier, and open-source models hosted in the US or EU, all under per-organization pricing rather than per-seat.
Use Cases
Scan entire repository for flaws
Review pull requests for security issues
Provide inline comments on new code
Receive fix prompts from AI models
Enable per-organization security checks
Open public repo scanning
Frequently Asked Questions
What is Aevral?
Who is Aevral for?
Does Aevral offer a free plan or free scans?
How does Aevral work with PR reviews?
What features does Aevral provide?
Which platforms or integrations does Aevral support?
How is Aevral priced?
How does Aevral compare to typical security scanners?
What about data and security for Aevral?
How do I get started with Aevral?
Does Aevral require Claude Security or other tools?
Ask AI about Aevral
Get an instant rundown of what Aevral does, who it is for, and how it compares to alternatives.
Discussion
0Ctrl + Enter to post ยท 0/2000
No comments yet. Be the first to start the discussion.

