[Roundup]

IDOR and broken access control scanners in 2026

Access control is the bug class where the code looks fine and the rule is wrong: an object another tenant owns, a route that lost its gate, a role list that grew by one. Each tool below publishes a security scope that names this surface, and the published shapes differ: rule and dataflow matching with AI detection, agentic source audits, PR review bots, and remediation agents, per each tool's own site. Every entry is described by its own stated job and links to a deeper comparison where the split with Aevral is stated on the page.

Aevral appears on this map in its own lane: its whole-repo scan reads the repository snapshot for authorization, IDOR, and business-logic access control with cross-file context, priced by organization, and its PR review rides the same App as an opt-in add-on. Aevral is self-serve today: install https://github.com/apps/aevral and log in to the console. The one like-for-like comparison on the map is Aevral and Claude Security, two products built for the same job; it has its own page.

The field

Aevral

Aevral reads the repository snapshot for authorization, IDOR, and business-logic access control, with cross-file context, on your trigger from the console. Open-source models, hosted in the US or the EU. Priced by organization. PR review is live as an opt-in add-on per organization; paid PR plans are live in the console. Aevral is self-serve today. Findings are leads with evidence, a human decides, and nothing here is a catch-rate claim.


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.