Compliance platform

Scrut's pull request import collects your data into its Code Review Results task. Aevral reads what the pull request changes.

Scrut imports pull request data from version control systems and organizes it in a task called Code Review Results. Aevral adds a security reading of the diff.

There is no native integration between Aevral and this platform today, and Aevral has no findings file to hand over. What exists is the pull request itself. Aevral is not affiliated with or endorsed by this platform.

This page covers one documented GitHub test or data feed of Scrut. Scrut offers other products and integrations not described here.

What Scrut reads or records

Scrut's help center says it imports pull request data from version control systems and organizes it in an evidence task called Code Review Results.

What Aevral reads

Aevral adds a security reading of the change itself and looks for flaws such as an endpoint that returns another tenant's records when the ID changes, a deserializer fed from a request body, or a prompt that lets user text choose which tool runs. The findings are comments on the pull request, so they live where the review happened.

Scrut looks at, per its docs

  • Pull request data from version control systems.
  • A Code Review Results task built from that data.

Aevral on the same pull request

  • Aevral is an AI security reviewer for GitHub pull requests, live on install: installing the App starts reviews, and the owner can turn them off.
  • On each supported pull request it posts a GitHub Check named Aevral review. The Check is advisory: it always concludes neutral and never blocks a merge.
  • At most two findings per review, as inline comments on the added lines. A finding is a lead with evidence (the file, the lines, the reason to look), not a verdict. A human decides.
  • Those comments stay on the pull request, in your own GitHub history, next to the approval.

Run them together

Keep Scrut collecting your code review results; let Aevral add a security reading of the same pull requests.

Aevral PR security review; everything Aevral works alongside.

Sources

Quoted from Scrut's public documentation. Scrut may change its product; check the page for the current wording.

  1. various version control systems to import pull request data. It then organizes this data in an Evidence Task called Code Review Results help.scrut.io, retrieved 2026-09-29.
  2. Azure DevOps Bitbucket GitHub GitLab help.scrut.io, retrieved 2026-09-29.

Other compliance platforms


Security review, handled.

Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.