Aevral docs
Aevral is a security researcher on your whole repository, plus a live PR security reviewer, opt-in per organization. Start here.
Aevral is two products from the Better ISMS family:
- A whole-repo scan. You start with a selected first scan during Setup, press Scan later, or configure recurring scans on a paid scan plan, and a security researcher goes through the default-branch snapshot of your repository the way a human would: cross-file context, authorization rules, the business logic behind who has access to what. Today it reads authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST.
- A PR security reviewer. A security reviewer on your pull requests. Claiming a new organization starts PR reviews on. Setup Complete can turn them off. Free and paid review allowances are separate from scan plans.
Aevral is self-serve: install the GitHub App and log in to the console to claim your install. Complete Setup to pick the first scan, or to turn reviews off. Free organizations have one lifetime private baseline when available; paid organizations use their included scan allowance.
Start here
- Set up with your agent: the setup steps in order, install to first report.
- What a scan looks like: console trigger, GitHub Check, report, fix prompt. No patches.
- The findings worklist: remembered leads across scans, human archive, fix prompt on a SHA.
- What a PR review looks like: the per-organization opt-in PR review posts a Check plus inline comments, max two findings, on added lines. Free tier live; paid plans are live in the console.
- Pricing and plans: both SKUs, the EUR scan ladder (now with the Scale rung) and the USD PR review add-on, opt-in per organization.
- Works alongside: Semgrep, Snyk Code, CodeQL, Aikido, GitHub Copilot code review, Bugbot, Socket. Aevral reads authorization, IDOR, and business-logic access control. Aikido's Code Security Audit is on aevral.com/compare/aikido.
- For AI agents: machine-readable hub.
What Aevral does not do
- No patch generation. A scan hands you a fix prompt for Claude Code, Cursor, or Codex. A human reviews before merge.
- No confirmation pass. A finding is a lead, not a clean bill of health.
- The GitHub App is public. Install it on any account or organization: https://github.com/apps/aevral.
How Aevral runs
- Open-source models, hosted in the US or the EU. Details on Security and data.
Questions: contact form. Security and legal corpus: trust center.