Compliance platform
Secureframe pulls the required approval count for pull requests from GitHub rulesets and branch protection. Aevral adds a security reading of the diff.
There is no native integration between Aevral and this platform today, and Aevral has no findings file to hand over. What exists is the pull request itself. Aevral is not affiliated with or endorsed by this platform.
This page covers one documented GitHub test or data feed of Secureframe. Secureframe offers other products and integrations not described here.
Secureframe's GitHub docs say it pulls PR required approval counts from rulesets, and when a repository has both rulesets and branch protection it follows GitHub in using the stricter of the two. The number is about the process: how many people must say yes before a merge.
Aevral looks at the content of the change for security flaws, for example an admin-only handler that now accepts any signed-in user, a file path joined from a request parameter, or a model output passed straight into a tool call. The findings arrive as comments on the added lines of the same pull request the approvals are given on.
Secureframe looks at, per its docs
Aevral on the same pull request
Keep Secureframe reading your approval settings; let Aevral add a security reading of the same pull requests.
Aevral PR security review; everything Aevral works alongside.
Quoted from Secureframe's public documentation. Secureframe may change its product; check the page for the current wording.
Secureframe pulls PR required approval counts from rulesets.support.secureframe.com, retrieved 2026-09-29.
If a repository has both rulesets and regular branch protection rules set, Secureframe follows GitHub’s policy of using the stricter of the two rulessupport.secureframe.com, retrieved 2026-09-29.
Repo scoping (GitHub app repository access) determines which repositories Secureframe can pull data fromsupport.secureframe.com, retrieved 2026-09-29.
Other compliance platforms
Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.
For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.