AevralDocs

Pricing and plans

Both Aevral products: the whole-repo scan plans (EUR per organization) and the PR security review (USD per organization, no scan plan required). Verified against aevral.com/pricing.

Aevral has two products, each priced by organization, never by seat. Whole-repo scans are priced in EUR with included scans per month. PR security review is priced in USD with included private reviews per month; its free tier is live (per-organization opt-in) and its paid plans are live in the console. One GitHub App and one console for both. Neither product requires the other, and the free PR review tier needs no subscription at all.

Access is self-serve: log in to the console with your GitHub account and claim your install.

The canonical marketing source is aevral.com/pricing. These numbers and rules were reconciled against it and against the billing implementation on 2026-09-06.

Whole-repo scan plans, EUR per organization per month, excluding VAT

PlanPriceIncludedExtra scanAvailability
Public repositories€01 authorized public-repo scan per calendar monthNone; a second public scan that month is refusedFree
Team€994 default-branch scans per month€29 per scan, opt-inSelf-serve
Business€39916 default-branch scans per month€19 per scan, opt-inSelf-serve
Scale€1,699100 default-branch scans per month€17 per scan, opt-inSelf-serve
EnterpriseBy quote, from €3,300 per month equivalent200 scans and up, annual commitment, invoice billing€16.50 per scan minimumBy quote

Team, Business and Scale can be bought in the console. Private repositories start at Team. Team, Business and Scale differ by included volume and by the price of an extra scan; every plan carries the same product. Team, Business and Scale all support recurring repository scans, sharing the included scan allowance with manual scans.

What every scan plan carries:

  • Whole-repo authorization / IDOR / business-logic scan on a default branch you authorized and triggered
  • GitHub Check and console report with evidence
  • Fix prompt for Claude Code, Cursor, or Codex
  • Open-source models, hosted in the US or the EU
  • Priced by organization, not by seat

Public repositories here means authorized public repositories, not that the Aevral service is open source. Authorization is required to scan. Findings are not auto-published.

Enterprise is sold by quote, not self-serve: a quote is a conversation with us through the Aevral contact form. The Enterprise console features (SSO / SAML, RBAC, audit log, multiple GitHub organizations, invoice / PO tooling) are not shipped yet. Extras coming soon on Business and Scale: directory scope, Slack or webhook, CSV / Markdown export, documented dismissals.

What counts as a scan, and when it resets

A scan counts when it is newly admitted: you press Scan on a commit that has not been scanned in the period and it is accepted. Pressing Scan again on the same commit in the same period returns the existing scan and counts nothing. A scan that ran counts whether or not it found anything and whether or not it completed; only a scan that never ran is refunded.

Included scans reset with the plan's billing period on Team, Business and Scale, and with the calendar month on Public repositories. No rollover.

Recurring scans and quota

Choose repositories once in the console. Each schedule checks at up to four checkpoints per billing month: the subscription period start plus 0, 7, 14 and 21 days. Enabling a schedule picks the next future checkpoint; it does not replay missed ones. After the fourth checkpoint, the next opportunity is the next billing period. This is not a weekly guarantee in five-week months.

Automatic scans use the same included allowance as manual scans. An unchanged commit reuses the existing report for that period, without consuming another scan. If included quota is exhausted, recurring scans pause until renewal. They never authorize extra charges or consume the free private baseline. An owner or admin can pause a schedule, including after cancellation or removal of the GitHub installation. The console shows the next checkpoint and latest actual outcome.

A new free organization can receive one lifetime private baseline scan when available; Setup shows eligibility. A paid organization's first scan uses its included allowance. There is no permanent free weekly private scan plan.

Monthly cap on extra-scan spend

Every paid organization can set a hard monthly cap on extra-scan spend, in the console under Billing. Only the organization owner can change or remove it. An extra scan that would push the period's extra-scan spend past the cap is refused with the exact numbers named; included scans and the free public-repo scan never touch the cap. Billing also shows the extra-scan amount billed so far in the period and alerts at 50, 75, 90, and 100 percent of the included allowance. The cap covers extra scans only; PR review has separate paid allowances and excess-review authorization.

PR security review, USD per organization per month, excluding VAT

PR security review is Aevral's second product. It needs no scan plan. Claiming a new organization starts PR reviews on. Installing the App without claiming does not authorize processing. Existing opt-outs remain off. Setup Complete or the Reviews page can turn them off. The App install must have accepted Pull-requests write. Reviews are never counted as scans, and scans are never counted as reviews: a review is never one of the included whole-repo scans of a scan plan.

PlanPriceIncluded private reviewsExtra reviewAvailability
Free$025 private pull-request reviews per monthNone; private reviews pause until next monthLive
Starter$19100 included private reviews$0.49 per extra review, opt-in onlyLive
Pro$99500 included private reviews$0.49 per extra review, opt-in onlyLive
Business$2492000 included private reviews$0.49 per extra review, opt-in onlyLive

Public repositories are always free. Enabling PR review starts a 14-day trial with the first pull request Aevral processes after opt-in: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first. After the trial, 25 private reviews a month are free (trial-covered reviews do not consume the subsequent Free allowance); past that, a pull request gets a neutral Check and no review until the next month. No card. Paid plans are purchasable in the console. The billable-review definition and overage opt-in are shown before purchase, and $0.49 per extra review applies on every paid tier. The paid tiers are volume allowances of the same review; they differ by included reviews, not by features.

What counts as a review: one pull request head (repository, pull request number, head commit). A new push is a new head and, if it is processed, a new review; the same head is never counted twice. A pending review for an older head is skipped without charge when a newer push arrives. A review holds its slot while it is pending or running and releases it if it is skipped, oversized or fails before posting; a posted review counts whether or not it found anything. The free allowance resets on the first day of each calendar month (UTC).

What an opt-in review does: What a PR review looks like.

Common terms

  • Two currencies: scans bill in EUR; PR review bills in USD on its paid plans. Both per organization.
  • VAT: all prices exclude VAT. B2B.
  • Extra scans: manual extra scans need explicit confirmation and respect the scan spend cap. Excess private reviews require separate owner authorization. Scheduled scans never incur overage.
  • Enterprise: quoted from €3,300 per month equivalent (200 scans and up, €16.50 per scan minimum), annual commitment, invoice billing, via the Aevral contact form; there is no separate sales mailbox.

Questions: Aevral contact form.

On this page