AevralDocs

Security and data

Short operational summary of how Aevral handles your code and findings. The binding security and legal corpus lives in the trust center.

This page is a short operational summary. The binding security and legal documents live in the trust center: trust.ismscopilot.com. Privacy: privacy policy. If anything here reads differently from the trust center, the trust center wins.

How your code is processed

  • At rest, on your trigger. A scan reads the default-branch snapshot of a repository you explicitly authorized, when you press Scan in the console. Not on every push.
  • Authorization required. Nothing is scanned that you did not authorize. Findings are not auto-published; they stay in your console and your Checks.
  • Minimal GitHub permissions. The App holds Contents read and Metadata read for the scan product; it never writes your code. The opt-in PR security review adds Pull requests read and write, used only to read the diff and post the advisory Check and inline comments. See GitHub App permissions.

Models and hosting

Aevral uses open-source models, hosted in the US or the EU. Claiming a new organization starts PR reviews on; Setup shows the processing disclosure and can turn reviews off. The trust center lists current subprocessors. No model provider trains on your code.

  • Scan worker: Fly.io.
  • Data store: Supabase (Postgres).
  • Frontends (site, docs, console): Vercel.
  • Payments: Stripe.
  • Repository access: GitHub App, install-scoped tokens.

PR review data

PR review requires organization authorization. Claiming a new organization starts PR reviews on. Installing the App without claiming does not process reviews. Setup Complete or Reviews can turn them off; existing opt-outs stay off. An authorized review reads the pull-request diff plus up to 40 changed files at head, and posts an advisory Check plus inline comments. It never blocks a merge.

Free organizations can use one lifetime private baseline when available; paid first scans use the included scan allowance.

What Aevral does with findings

  • Each finding carries its evidence and a fix prompt you hand to Claude Code, Cursor, or Codex.
  • Aevral does not generate patches, does not commit, and does not open pull requests.
  • A finding is a lead, not a confirmation; there is no confirmation pass.

Family

Aevral is a Better ISMS product, by ISMS Copilot. The company behind it is Better ISMS EURL (Paris, France). Aevral runs on Fly.io, Supabase, Vercel, Stripe, GitHub, and hosted open-source models, alongside the family stack; the trust center carries the authoritative, current subprocessor list. B2B; prices exclude VAT. Better ISMS is getting ISO 27001 certified. We are not certified today. The intended scope includes Aevral. Read the intended scope at trust.ismscopilot.com/en/iso-27001.

Questions or concerns: contact form. Report a security issue: the trust center carries the disclosure path.

On this page