[Developer security platform]

Aikido and Aevral, at a glance

Aikido is a developer security platform (SAST, dependencies, secrets, IaC, pentest) and publishes Code Security Audit and Deep Review. Aevral is built for authorization, IDOR, and business-logic reading. Keep the platform.

Aikido is built as one platform for SAST, dependencies, secrets, IaC, and pentest. Keep that. It also publishes Code Security Audit and Deep Review: agentic reading of source for authorization, IDOR, and business-logic access control. Aevral's whole-repo scan is built for that reading; the same reading on the diff is its opt-in PR review add-on.

Aikido focuses on

  • SAST, dependencies, secrets, IaC, and pentest on the platform.
  • Code Security Audit and Deep Review, as Aikido publishes them.
  • Bringing those findings into one platform.

Aevral adds alongside

  • The authorization, IDOR, and business-logic reading, across files, on the whole repository.
  • The same reading on every pull request, as an opt-in add-on.
  • A fix prompt you hand to the coding agent you already use, with a human reviewing before merge.

Run them together

Keep Aikido for SAST, dependencies, secrets, IaC, and the live pentest; run Aevral for the authorization and business-logic reading of the repository.

Aikido and Aevral, in depth; Aevral whole-repo scan.

Also alongside


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.