Supported and not supported
Aevral is an AI security reviewer for GitHub pull requests. GitHub only. Which source files each product reads, what Aevral does not look for, and who it is not for.
Aevral is an AI security reviewer for GitHub pull requests. This page states the limits plainly, so you can tell in a minute whether it fits.
Code hosts
- Supported: GitHub, through the public GitHub App, on personal accounts and organizations.
- Not supported: GitLab, Bitbucket, Azure DevOps, and self-hosted Git servers.
Languages
These lists come from the product code, not from a marketing matrix. No per-language accuracy figure is published.
- PR security review reads the changed files of a pull request. When a pull request is large, it reads these source files first: TypeScript, JavaScript, Python, Go, Ruby, Java, Rust, PHP, and Elixir. The review says which files it covered.
- Whole-repo scan reads only these source files and drops everything else on purpose: TypeScript and JavaScript (including
.mjs,.cjs, Vue, and Svelte files), Python, Go, Ruby, PHP, Java, Kotlin, Rust, C#, Swift, Scala, SQL, and GraphQL. Vendor and build folders such asnode_modules,vendor, anddistare skipped.
What Aevral looks for
- PR security review: access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks. Advisory, never blocks a merge, at most two findings per review.
- Whole-repo scan: authorization, IDOR, and business-logic access control only.
A finding is a lead with evidence, not a confirmation. Details: What a PR review looks like and What a scan looks like.
What Aevral does not do
- Not secret scanning.
- Not dependency, SCA, or supply-chain scanning.
- Not memory-corruption analysis.
- Not a general SAST, and not a replacement for one. See Works alongside.
- It never applies or merges a fix. Suggested fixes are for you or your coding agent to apply.
Who it is not for
- Teams with no pull-request workflow. Aevral reviews GitHub pull requests; if code lands without one, the review has nothing to read.
- Enterprise AppSec buyers who need demos, SSO, and a procurement process first. Aevral is self-serve. The Enterprise console features (SSO / SAML, RBAC, audit log, multiple GitHub organizations, invoice and PO tooling) are not shipped yet. Enterprise scan volume is by quote: Pricing and plans.
- Buyers who need audit evidence for a certification framework, or control mapping on pull requests. Aevral is a security reviewer; its findings are leads for engineers, not audit evidence. Ask through the contact form and we will point you to the right product from the same company.
Open-source maintainers are welcome: public repositories get PR review free (500 reviews per organization per month) and one authorized public-repo scan per calendar month.
Questions: contact form.