Gecko analyzes code, logic, and infrastructure for exploitable vulnerabilities, with threat modelling, natural-language rules, and a pull-request review bot with one-click autofix, per Gecko's site.
Gecko builds a semantic graph of the application and scans across repositories and microservices for issues that surface between trust boundaries, with a pull-request review bot with one-click autofix, per Gecko's site. Aevral is built for a reading of its own: does this diff widen who has access to what. Both read pull requests for security: Gecko with its bot, and Aevral's PR review, live and opt-in, on the same pull request.
Gecko Security focuses on
Aevral adds alongside
Let Gecko run its semantic scans and PR bot; let Aevral add the authorization and business-logic reading of the same pull requests, with the opt-in add-on.
Gecko Security and Aevral, in depth; Aevral PR security review.
Also alongside
One GitHub App. A report with evidence. A prompt for the agent you already use.