Announcement

A beta cohort of 10 testers. 14 days of everything.

A closed beta: our top plan on both products for 14 days, no card, nothing to cancel. In exchange, honest feedback on real pull requests. Applications close Tuesday, October 6.

Tristan Roth,

Aevral is a security reviewer for GitHub pull requests: a Check on the head commit, inline comments pinned to the added lines when there is a grounded finding, and a suggested fix your coding agent can apply. It also scans whole repositories on the default branch and hands your agent a fix prompt for what it finds.

Today we are opening a beta cohort, and we are keeping it small: 10 testers. This is the announcement. The application form is open through Tuesday, October 6.

What you get

14 days of everything, on us. Our top plan on both products: 6,500 pull-request reviews a month and 100 whole-repo scans a month. No card, nothing to cancel. The 14 days are counted per tester from onboarding, not from a fixed calendar date. After the window, your organization falls back to its plan or the free tier, and public repositories are free either way: 500 reviews per organization per month.

Standard terms apply: security and data handling. Aevral runs on open-source models, processed in the US today, with an EU-only option announced..

What the review looks for

PR review reads the changes on each pull request for access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks. The whole-repo scan reads authorization, IDOR, and business-logic access control in the code you already have. A finding is a lead with evidence, and a suggestion, not a blocker. You decide what merges.

Who we are looking for

  • You own or run engineering on a GitHub organization with real pull-request flow. A toy repository or a two-PR sample org does not qualify.
  • You ship with coding agents (Claude Code, Cursor, Codex, OpenCode, and the rest) several times a week.
  • You will install the Aevral GitHub App on your real repositories, not a demo repository.
  • Big plus: you already run another automated reviewer, so you can tell us honestly where we are better and where we are not.
  • You will tell us what is broken, not what is nice.

The one ask: real feedback

A short form at day 7, an honest email at day 14, and an open line in between. If you would rather talk it through on a call, we can do that too, but no one will push one on you. We want the criticism we can act on. Selection is human: the founder reads every application and picks the 10 testers himself.

How to apply

Apply with the beta application form. It asks for your GitHub profile, the organization you would install on, the coding agents you use, and what you want from Aevral. Applications close Tuesday, October 6. If you would rather try Aevral without applying, public repositories are free: install the GitHub App, open a pull request, and read what comes back.

Sources

The GitHub App; Pricing (PR review and scans); Security and data; The receipts page.

Read next

The PR security review product; Why review bots get ignored, and what a grounded review does instead; How Aevral reviews a pull request; The transparency report.


Security review, handled.

One GitHub App. Reviews start when the App is installed. A Check on each pull request it reviews, with inline comments when there is a grounded finding. Free tier live: public repos free, 500/org/month, 25 private reviews a month. Paid plans are live in the console.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.