Compliance platform

Vanta's GitHub approval test checks the approval rule. Aevral reads what the pull request changes.

Vanta's Application Changes Reviewed test for GitHub looks at whether pull requests need an approval before merging. Aevral adds a security reading of the diff.

There is no native integration between Aevral and this platform today, and Aevral has no findings file to hand over. What exists is the pull request itself. Aevral is not affiliated with or endorsed by this platform.

This page covers one documented GitHub test or data feed of Vanta. Vanta offers other products and integrations not described here.

What Vanta reads or records

Vanta documents a GitHub test called Application Changes Reviewed. In its words, the test ensures that pull requests are reviewed prior to getting merged into the branch used for your application, and the setup asks for the required number of approvals before merging to be 1 or greater. That is a rule about who approves. What the change does is a separate question.

What Aevral reads

Aevral reads the diff and looks for security flaws in it, for example a dropped ownership check, a caller-controlled ID passed to a query, a shell command built from input, or a fetch of a URL the user controls. The approval and the reading answer different questions, and a pull request can carry both.

Vanta looks at, per its docs

  • Whether GitHub requires a pull request before merging on the branch it tests.
  • Whether the required number of approvals is at least one.
  • Which branch it looks at: the branch named in a custom property, if one is set, or the default branch when there is none.

Aevral on the same pull request

  • Aevral is an AI security reviewer for GitHub pull requests, live on install: installing the App starts reviews, and the owner can turn them off.
  • On each supported pull request it posts a GitHub Check named Aevral review. The Check is advisory: it always concludes neutral and never blocks a merge.
  • At most two findings per review, as inline comments on the added lines. A finding is a lead with evidence (the file, the lines, the reason to look), not a verdict. A human decides.
  • Those comments stay on the pull request, in your own GitHub history, next to the approval.

Run them together

Keep Vanta's approval test on your production branch; let Aevral add a security reading of the same pull requests.

Aevral PR security review; everything Aevral works alongside.

Sources

Quoted from Vanta's public documentation. Vanta may change its product; check the page for the current wording.

  1. This test ensures that pull requests are reviewed prior to getting merged into the branch used for your application help.vanta.com, retrieved 2026-09-29.
  2. Application Changes Reviewed Test (GitHub) help.vanta.com, retrieved 2026-09-29.
  3. Ensure the Required number of approvals before merging is set to 1 or greater help.vanta.com, retrieved 2026-09-29.
  4. If a custom property is set, Vanta will look exclusively at that branch for the required approvals help.vanta.com, retrieved 2026-09-29.
  5. you can delete the Custom property entirely, and Vanta will look at the Default branch help.vanta.com, retrieved 2026-09-29.

Other compliance platforms


Security review, handled.

Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.