Compliance platform

Secureframe's GitHub app reads how many approvals a pull request needs. Aevral reads what it changes.

Secureframe pulls the required approval count for pull requests from GitHub rulesets and branch protection. Aevral adds a security reading of the diff.

There is no native integration between Aevral and this platform today, and Aevral has no findings file to hand over. What exists is the pull request itself. Aevral is not affiliated with or endorsed by this platform.

This page covers one documented GitHub test or data feed of Secureframe. Secureframe offers other products and integrations not described here.

What Secureframe reads or records

Secureframe's GitHub docs say it pulls PR required approval counts from rulesets, and when a repository has both rulesets and branch protection it follows GitHub in using the stricter of the two. The number is about the process: how many people must say yes before a merge.

What Aevral reads

Aevral looks at the content of the change for security flaws, for example an admin-only handler that now accepts any signed-in user, a file path joined from a request parameter, or a model output passed straight into a tool call. The findings arrive as comments on the added lines of the same pull request the approvals are given on.

Secureframe looks at, per its docs

  • The required approval count on GitHub rulesets.
  • Branch protection rules, using the stricter of the two when both are set.
  • Pull requests in the repositories you put in scope.

Aevral on the same pull request

  • Aevral is an AI security reviewer for GitHub pull requests, live on install: installing the App starts reviews, and the owner can turn them off.
  • On each supported pull request it posts a GitHub Check named Aevral review. The Check is advisory: it always concludes neutral and never blocks a merge.
  • At most two findings per review, as inline comments on the added lines. A finding is a lead with evidence (the file, the lines, the reason to look), not a verdict. A human decides.
  • Those comments stay on the pull request, in your own GitHub history, next to the approval.

Run them together

Keep Secureframe reading your approval settings; let Aevral add a security reading of the same pull requests.

Aevral PR security review; everything Aevral works alongside.

Sources

Quoted from Secureframe's public documentation. Secureframe may change its product; check the page for the current wording.

  1. Secureframe pulls PR required approval counts from rulesets. support.secureframe.com, retrieved 2026-09-29.
  2. If a repository has both rulesets and regular branch protection rules set, Secureframe follows GitHub’s policy of using the stricter of the two rules support.secureframe.com, retrieved 2026-09-29.
  3. Repo scoping (GitHub app repository access) determines which repositories Secureframe can pull data from support.secureframe.com, retrieved 2026-09-29.

Other compliance platforms


Security review, handled.

Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.