Same job: scan the repository, review findings, hand off a fix. Different access, price shape, models, and fix path. This table is even. It is not a catch-rate boast and not a complementary pairing.
Last verified 2026-08-31. Primary sources: Claude Security product page; Use Claude Security (help). Review monthly and on known Anthropic changes.
| Row | Aevral | Claude Security |
|---|---|---|
| Job | Scan the repository, review the findings, hand a fix prompt to the coding agent you already use. | Scan the codebase, validate findings, and suggest patches for human review. |
| Target coverage | Today Aevral scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST. Broader classes are coming soon. MCP agent coming soon. PR review is live as an opt-in add-on; paid PR plans are live in the console. | memory corruption, injection, authentication bypasses, complex logic / authz / IDOR, and cross-file issues. Published as the hosted product focus. |
| Models | Open-source models. Hosted in the US or the EU. | Hosted scans run on Claude Mythos 5. Users receive findings without direct model access. |
| Price shape | Public repositories €0 (1 authorized public-repo scan / month), Team €99 / org / month (4 then €29), Business €399 (16 then €19), Scale €1,699 (100 then €17). Enterprise by quote from €3,300 per month equivalent (200 scans and up, €16.50 per scan minimum, annual, invoice billing; not self-serve, console features not shipped). HT, B2B, excluding VAT. Waitlist does not reserve price. | Claude Enterprise plan plus token usage. No additional platform fee for Claude Security. |
| Seats | No per-seat. Priced by organization. No floor to start. | Hosted Mythos 5 scans: Claude Enterprise. Plugin: any Claude Code user on a paid plan, using that account's models, not Mythos. |
| Where it runs | GitHub Check and console. MCP agent coming soon. PR review is live as an opt-in add-on; paid PR plans are live in the console. | Hosted: claude.ai/security after an admin enable, GitHub you own. Plugin: local Claude Code session, including GitLab and Bitbucket. |
| Fix path | Evidence plus a prompt you copy into Claude Code, Cursor, or Codex. Copy fix prompt. We do not generate patches today. | Integrated suggested patch. Review and apply in Claude Code. Every patch needs a human. |
| Data / trust | Family trust center at trust.ismscopilot.com. Better ISMS is getting ISO 27001 certified. Intended scope includes Aevral. We are not certified today. Aevral is not a product certificate. | Anthropic's published help: no Zero Data Retention for Claude Security. Review their trust materials for the binding text. |
| Availability | Self-serve for authorization / IDOR scans: install https://github.com/apps/aevral and log in to claim. PR review is live as an opt-in add-on; paid PR plans are live in the console. | Hosted scans: public beta for Claude Enterprise. Plugin: beta for Claude Code users. |
Aevral is not affiliated with, endorsed by, or sponsored by Anthropic. Claude and Claude Security are used nominatively to identify the product we compete with. No Anthropic logo or trade dress appears on this site.
One GitHub App. A report with evidence. A prompt for the agent you already use.