Compliance platform

Drata's Test 8 checks that reviews are required on the branch. Aevral reads what the pull request changes.

Drata's Test 8, Formal Code Review Process, reads branch settings to see that reviews are required before merging. Aevral adds a security reading of the diff.

There is no native integration between Aevral and this platform today, and Aevral has no findings file to hand over. What exists is the pull request itself. Aevral is not affiliated with or endorsed by this platform.

This page covers one documented GitHub test or data feed of Drata. Drata offers other products and integrations not described here.

What Drata reads or records

Drata's Test 8, Formal Code Review Process, reads branch configurations for all in-scope repos to ensure reviews are required before merging code. It fails when a branch lets the same user merge a change into main without any other user interaction. That is a setting on the branch: a rule about who must review, separate from what a given change does.

What Aevral reads

Aevral reads the change behind the gate and looks for security flaws, for example a route that went from a role check to a login check, an object fetched by an ID from the request with no owner filter, or a template that renders user input raw. It posts at most two findings per review as comments on the added lines, and the reviewer Drata requires decides.

Drata looks at, per its docs

  • Branch configurations of every in-scope repository.
  • Whether a review by another user is required before code merges into main.
  • A failed test when the same user can merge without another person's interaction.

Aevral on the same pull request

  • Aevral is an AI security reviewer for GitHub pull requests, live on install: installing the App starts reviews, and the owner can turn them off.
  • On each supported pull request it posts a GitHub Check named Aevral review. The Check is advisory: it always concludes neutral and never blocks a merge.
  • At most two findings per review, as inline comments on the added lines. A finding is a lead with evidence (the file, the lines, the reason to look), not a verdict. A human decides.
  • Those comments stay on the pull request, in your own GitHub history, next to the approval.

Run them together

Keep Drata's code review test on the branch; let Aevral add a security reading of the same pull requests.

Aevral PR security review; everything Aevral works alongside.

Sources

Quoted from Drata's public documentation. Drata may change its product; check the page for the current wording.

  1. Drata reads branch configurations for all in-scope repos in your version control system to ensure reviews are required before merging code help.drata.com, retrieved 2026-09-29.
  2. If Drata finds that branch configurations allow code changes merged by the same user into the main branch of your version control system, without any other user interaction, the test will fail. help.drata.com, retrieved 2026-09-29.

Other compliance platforms


Security review, handled.

Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.