Security review for AI-written code.

Install it once. Aevral reviews the pull requests in your repositories, flags security problems in plain words, and suggests the fix.

Install the GitHub App

1,530+ pull requests security-reviewed. Updated daily. See review activity

Agents build what you ask for. Security is what nobody asked for.

So it gets skipped. Aevral asks the question on your pull requests, so you don't have to remember to, and tells you in plain words when it finds something.

Aevral commented on your agent's pull request

Any logged-in user could open other customers' invoices

Your agent built the invoice page and forgot to check who is asking. Suggested fix: only show invoices that belong to the user's company.

Suggested fix included

A suggestion, not a blocker. You decide what ships.

Set it up once. It runs on its own.

No new tool to open and no dashboard to check. The review shows up where your team already works.

  1. Your agent writes the feature

    Claude Code, Cursor or Codex.

  2. GitHub opens a pull request

    From your agent or from you.

  3. Aevral reviews it for security

    Automatically, in the background.

  4. You apply the fix

    Or hand it to your agent.

What changes after you install it

Before

Your agents ship faster than you can read.

You hope someone looked at security.

You find out when a customer does.

With Aevral

Pull requests get a security review on their own.

At most five findings per review, each with the reason.

Each one comes with a suggested fix.

Tested in public, misses included.

We run Aevral on pull requests with planted security bugs and publish the results, the bad runs too. And we use it on our own code every day.

See the public runs

When a customer asks how you secure AI-written code, you'll have an answer.

Aevral is built by Better ISMS, the team behind ISMS Copilot. Its founder, Tristan Roth, is an ISO 27001 lead auditor whose course on working safely with AI has 58,000+ learners.

Security and trust
Customer security questionnaireExample

11. Do you encrypt customer data?

Answered

12. How do you review AI-generated code for security?

Pull requests are reviewed by Aevral, an automated security reviewer. Findings and suggested fixes stay on each pull request.

13. Who approves changes to production?

Not started

Who it's for

A good fit

Teams on GitHub building with Claude Code, Cursor, Codex or any coding agent.

Any size, from a solo founder to a large organization.

Teams that want security looked at on their pull requests without hiring for it.

Not a fit

Teams not on GitHub. GitLab and Bitbucket are not supported.

Buyers who need a pentest, secret scanning or a full SAST suite.

Buyers who need demos, SSO and a procurement process first.

A security reviewer for $49 a month. Not a security hire.

Priced per organization, never per seat. Your agents don't need seats.

  • Free

    $0

    Public repositories, plus 25 private reviews a month.

  • Starter

    $49 / month

    100 PR reviews a month.

  • Pro

    $199 / month

    500 PR reviews a month.

  • Business

    $999 / month

    3,000 PR reviews a month, plus a monthly export of your reviews for audits.

14-day free trial, no card. Cancel any time. Prices exclude VAT and other taxes. All plans, including Scale and Enterprise

Questions

How is Aevral different from other tools?
It reviews the code no matter which agent wrote it, runs on open-source models, publishes its misses, and is priced per organization, never per seat. Side-by-side comparisons are on the compare page.
Do I need to know security?
No. Each finding explains the problem in plain words and comes with a fix you or your agent can apply.
Will it slow my team down?
No. It never blocks a pull request. It comments, and you decide.
Doesn't my coding agent already check security?
It can, when you ask it to. Aevral runs on its own from install, with open-source models, not the model inside Claude Code, Cursor or Codex.
Where does my code go?
It is reviewed by open-source AI models, processed in the US today; an EU-only option is announced. What is read, stored and for how long is on the security page.

Keep building with your agents. We'll keep an eye on security.

Install the GitHub App