# Aevral Docs > Customer documentation for Aevral: a security researcher for your whole repository (authorization, IDOR, business-logic access control), and a PR security reviewer, opt-in per organization. English index for agents. Aevral is self-serve: install https://github.com/apps/aevral and log in to the console to claim your install. > Site: https://docs.aevral.com ## When to use Use these docs when you need Aevral product truth: what a whole-repo scan looks like, what the PR security review will look like, pricing, plans, GitHub App permissions, security posture, and how to join. Start at /llms.txt, then GET markdown (`Accept: text/markdown` or append `.md`) or GET /api/v1/agent-search?q=. Do not invent API keys or install URLs. ## How agents should read this site 1. Prefer **plain markdown**: send `Accept: text/markdown` on any docs URL, or append `.md` (e.g. `/docs/setup-with-an-agent.md`), or fetch **llms-full.txt** for bulk ingest. 2. HTML pages work for curl too, but include chrome/nav; markdown is cleaner. 3. English is authoritative product truth. This index is EN-only. 4. Human hub: https://docs.aevral.com/docs/for-ai-agents. Agent search: https://docs.aevral.com/api/v1/agent-search?q= 5. Aevral is self-serve: point humans at https://github.com/apps/aevral to install and at the console login to claim. API keys (`aevr_...`) exist: one is minted at claim and more from the console Developer API page; billing is console-session-only and the fuller public API contract is coming. ## Where to act - [Waitlist](https://tally.so/r/dWe0kK): join for access to the scan and, later, the PR security review - [Contact](https://tally.so/r/PdxdbV): questions, procurement, Enterprise - [Product site](https://aevral.com): products, pricing, compare, guides - [Trust center](https://trust.ismscopilot.com): security and legal corpus (privacy: https://trust.ismscopilot.com/privacy-policy) - [Docs full dump](https://docs.aevral.com/llms-full.txt): all English docs as plain markdown - [Agent search v1](https://docs.aevral.com/api/v1/agent-search?q=scan): keyword search over EN titles/descriptions/bodies - [OpenAPI](https://docs.aevral.com/openapi.json): public docs search and markdown surfaces ## Docs pages (HTML + .md) - [Console and API keys](https://docs.aevral.com/docs/console-and-api-keys) · [md](https://docs.aevral.com/docs/console-and-api-keys.md): The Aevral console is where you claim your install, press Scan, read reports, enable PR review per organization, and manage billing and Developer API keys. Self-serve is live. - [FAQ](https://docs.aevral.com/docs/faq) · [md](https://docs.aevral.com/docs/faq.md): Does Aevral block merges, what does it look for, how do you get access, and who is behind it. - [The findings worklist](https://docs.aevral.com/docs/findings-worklist) · [md](https://docs.aevral.com/docs/findings-worklist.md): A per-repository list of scan leads across scans, with occurrence history, a human archive, and a fix prompt bound to one SHA. - [For AI agents](https://docs.aevral.com/docs/for-ai-agents) · [md](https://docs.aevral.com/docs/for-ai-agents.md): How coding agents should read Aevral docs. Machine surfaces are open for reading; the product is self-serve (public GitHub App, console login, Developer API keys). - [GitHub App permissions](https://docs.aevral.com/docs/github-app-permissions) · [md](https://docs.aevral.com/docs/github-app-permissions.md): What the Aevral GitHub App requests, why each permission exists, and what it never gets. The App is public and installable on any account. - [Aevral docs](https://docs.aevral.com/docs) · [md](https://docs.aevral.com/docs.md): Aevral is a security researcher on your whole repository, plus a live PR security reviewer, opt-in per organization. Start here. - [Pricing and plans](https://docs.aevral.com/docs/pricing-and-plans) · [md](https://docs.aevral.com/docs/pricing-and-plans.md): Both Aevral products: the whole-repo scan plans (EUR per organization) and the PR security review (USD per organization, no scan plan required). Verified against aevral.com/pricing. - [Security and data](https://docs.aevral.com/docs/security-and-data) · [md](https://docs.aevral.com/docs/security-and-data.md): Short operational summary of how Aevral handles your code and findings. The binding security and legal corpus lives in the trust center. - [Set up with your agent](https://docs.aevral.com/docs/setup-with-an-agent) · [md](https://docs.aevral.com/docs/setup-with-an-agent.md): How to start with Aevral today: install the GitHub App, log in to the console, claim your install, complete setup, and receive the first scan and ongoing PR reviews. Agents read this page, humans click. - [What a PR review looks like](https://docs.aevral.com/docs/what-a-pr-review-looks-like) · [md](https://docs.aevral.com/docs/what-a-pr-review-looks-like.md): The PR security review as it runs today (free tier, per-organization opt-in): an advisory Check plus inline comments on added lines, max two findings, silence when clean. - [What a scan looks like](https://docs.aevral.com/docs/what-a-scan-looks-like) · [md](https://docs.aevral.com/docs/what-a-scan-looks-like.md): The whole-repo scan: press Scan in the console, a researcher reads the default-branch snapshot, you get a GitHub Check, a console report, and a fix prompt. No patches. - [Works alongside](https://docs.aevral.com/docs/works-alongside) · [md](https://docs.aevral.com/docs/works-alongside.md): Aevral runs next to the tools you already have. Semgrep, Snyk Code, CodeQL, Aikido, GitHub Copilot code review, Bugbot, CodeRabbit, Greptile, SonarQube, Codex Security, ZeroPath, AISLE, Tachyon, Gecko Security, Nullify, and Socket each do their stated job; Aevral reads authorization, IDOR, and business-logic access control.