AevralDocs

Aevral docs

Aevral is an AI security reviewer for GitHub pull requests. Built by Better ISMS, the company behind ISMS Copilot, in Paris, France. Whole-repo scans read authorization, IDOR, and business-logic access control only.

Aevral is an AI security reviewer for GitHub pull requests. Built by Better ISMS, the company behind ISMS Copilot, in Paris, France. Same jobs as Claude Security and Codex Security. The one we lead with is the review.

  1. Review pull requests. Reviews look for security flaws across access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks. Advisory: a review never blocks a merge. Reviews start at install. You can turn them off. Free and paid review allowances are separate from scan plans.
  2. Scan the repository you already have. Scans read authorization, IDOR, and business-logic access control. Start with a selected first scan during Setup, press Scan later, or configure recurring scans on a paid scan plan. You get a GitHub Check, a report with evidence, and a suggested fix.
  3. Suggested fixes. Apply them in Claude Code, Cursor, or Codex. Nothing merges without you.

Open-source models, not a lab. Inference runs in the US today; an EU-only processing option is announced. Details on aevral.com/security.

Aevral is self-serve: install the GitHub App, then sign in to the console with GitHub; it connects the install automatically. Turn reviews off in Setup if you want. PR review: public repositories are free (500 reviews per organization per month) and 25 private reviews a month are free; connecting the install in the console starts a 14-day trial (up to 500 private reviews), no card. Scans: free organizations get two private scans in 14 days; paid organizations use their included scan allowance. Both products are priced per organization, never per seat.

Start here

How Aevral runs

Questions: contact form. Security and legal corpus: trust center.

On this page