Semgrep scans code against security and correctness rules, including custom rules teams write themselves, in the editor, CLI, and CI, and publishes AI-powered detection that includes IDOR and broken authorization, per Semgrep's site.
Semgrep is built to scan code against rules: the published security rules and your own custom ones, at line level, and it publishes AI-powered detection that includes IDOR and broken authorization, per Semgrep's site. Aevral is built for a reading of its own: it goes through the repository snapshot looking for authorization, IDOR, and business-logic access control, with cross-file context, and its opt-in PR review rides the same App as an add-on. The scopes overlap, and each page states the split in plain words.
Semgrep focuses on
Aevral adds alongside
Let Semgrep run the rule-based scans wherever you build; let Aevral read who has access to what across the repository.
Also alongside
One GitHub App. A report with evidence. A prompt for the agent you already use.