Aevral docs
Aevral is an AI security reviewer for GitHub pull requests. Built by Better ISMS, the company behind ISMS Copilot, in Paris, France. Whole-repo scans read authorization, IDOR, and business-logic access control only.
Aevral is an AI security reviewer for GitHub pull requests. Built by Better ISMS, the company behind ISMS Copilot, in Paris, France. Same jobs as Claude Security and Codex Security. The one we lead with is the review.
- Review pull requests. Reviews look for security flaws across access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks. Advisory: a review never blocks a merge. Reviews start at install. You can turn them off. Free and paid review allowances are separate from scan plans.
- Scan the repository you already have. Scans read authorization, IDOR, and business-logic access control. Start with a selected first scan during Setup, press Scan later, or configure recurring scans on a paid scan plan. You get a GitHub Check, a report with evidence, and a suggested fix.
- Suggested fixes. Apply them in Claude Code, Cursor, or Codex. Nothing merges without you.
Open-source models, not a lab. Inference runs in the US today; an EU-only processing option is announced. Details on aevral.com/security.
Aevral is self-serve: install the GitHub App, then sign in to the console with GitHub; it connects the install automatically. Turn reviews off in Setup if you want. PR review: public repositories are free (500 reviews per organization per month) and 25 private reviews a month are free; connecting the install in the console starts a 14-day trial (up to 500 private reviews), no card. Scans: free organizations get two private scans in 14 days; paid organizations use their included scan allowance. Both products are priced per organization, never per seat.
Start here
- Set up with your agent: the setup steps in order, install to first report.
- What a scan looks like: console trigger, GitHub Check, report, suggested fix.
- The findings worklist: remembered findings across scans, human archive, suggested fix on a SHA.
- What a PR review looks like: reviews start at install, Check plus comments, up to five findings, on added lines. Free tier live from install; paid plans live in the console.
- Supported and not supported: GitHub only, which languages each product reads, what Aevral does not do, and who it is not for.
- Pricing and plans: both products. PR review is priced in USD. The scan is priced in USD. Neither requires the other.
- Works alongside: SAST, SCA, and general review tools Aevral does not replace. Claude Security and Codex Security are named competitors on aevral.com/compare.
- For AI agents: machine-readable hub.
- Changelog: what has shipped in the product.
How Aevral runs
- Open-source models, run in the US today; EU-only processing announced. Details on aevral.com/security and Security and data.
- The GitHub App is public. Install it on any account or organization: https://github.com/apps/aevral.
Questions: contact form. Security and legal corpus: trust center.