- Is Aevral generally available?
- Aevral is self-serve: install the GitHub App and log in to the console to claim your install. The waitlist form is a launch-updates channel; joining reserves nothing. Hosted Claude Security scans are in public beta for Claude Enterprise. The Claude Security plugin is in beta for Claude Code users.
- How does this compare to Claude Security?
- Aevral is built as an alternative to Claude Security: same job (scan the repo, review findings, hand off a fix), org-priced, open-source models hosted in the US or the EU, no floor to start. See https://aevral.com/compare/claude-security. The compare table was last verified 2026-08-31 against Anthropic's product page and help article.
- What vulnerability classes does Aevral cover?
- Today Aevral scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST. Languages are whatever the GitHub App can read on the default branch snapshot. This site does not claim all languages.
- What if the scope on this page ever narrows?
- The class list above is what the scan covers today. Broader classes are not sold. If that list shrinks further, customers are told and must opt in again.
- Does joining the waitlist reserve a price?
- No. Two products, both priced per organization, excluding VAT. Whole-repo scans, EUR: Public repositories EUR 0 (1 authorized public-repo scan a month), Team EUR 99 (4 scans, then EUR 29), Business EUR 399 (16, then EUR 19), Scale EUR 1,699 (100, then EUR 17), Enterprise by quote from EUR 3,300 per month equivalent. PR security review, USD: the free tier is live (public repos free, 25 private reviews a month, a 14-day trial from the first pull request after opt-in); paid plans from $19 are live in the console. Joining the waitlist does not reserve a price, access, or a contract. The billable-scan definition, overage opt-in and the spend cap are shown before purchase. See https://aevral.com/pricing.
- What does the Public repositories plan mean?
- The Public repositories plan includes 1 scan of an authorized public repo per calendar month. Aevral itself is not open source. You must have authorization to scan, and findings are not auto-published.
- Does Aevral generate patches?
- No. Present-tense product verbs are scan, report, and hand off. Each finding includes evidence plus a prompt you copy into Claude Code, Cursor, or Codex. Copy fix prompt. We do not validate findings or generate patches today. A human reviews before merge.
- Is a finding a verification of a vulnerability?
- No. A finding is a lead with evidence. You decide. There is no confirmation pass until one exists.
- Can Aevral make mistakes?
- Yes. Scans can be wrong. Review every finding and every fix prompt before you change production code, especially on critical systems.
- Will two scans of the same repo look the same?
- Not necessarily. Scans are stochastic. Re-runs can differ. That is a property of this kind of analysis, not a clean-bill ritual.
- If Aevral reports no finding, is the repo secure?
- No. No finding does not mean secure. An incomplete scan is not a clean bill of health.
- Does this replace SAST, SCA, secrets detection, or a pentest?
- No. Aevral does not replace SAST, SCA, secrets detection, or a pentest. It is a whole-repo security scan aimed at the classes above.
- What does whole-repo mean?
- Whole-repo means the eligible files in the snapshot we scan, starting on the default branch. It is not a promise that every file, generated artifact, or submodule is in scope.
- Where does trust evidence live?
- The family trust center is https://trust.ismscopilot.com. Better ISMS is getting ISO 27001 certified. The intended scope includes how we build and run Aevral, ISMS Copilot, and heyGRC. We are not certified today. Aevral is not product-certified. Read the intended scope at https://trust.ismscopilot.com/en/iso-27001.
- What is the PR security review product?
- PR security review is Aevral's second product: a reviewer on every pull request that posts a Check plus inline comments grounded on the added lines, for authorization, IDOR, and business-logic flaws. Public repositories are always free. Enabling PR review starts a 14-day trial with the first pull request Aevral processes after opt-in: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first. After the trial, 25 private reviews a month are free (trial-covered reviews do not consume the subsequent Free allowance); past that, a pull request gets a neutral Check and no review until the next month. No card. Paid plans are purchasable in the console. Paid plans: Starter $19 / 100 included private reviews, Pro $99 / 500, Business $249 / 2000, then $0.49 per extra review on every paid tier, opt-in, USD per organization. A review is never one of the included whole-repo scans of a scan plan, and no scan plan is required. PR review is live and opt-in per organization: claiming a new organization starts reviews on, the owner can turn them off in Setup, and Aevral never reviews a pull request for an unclaimed install. Paid PR plans are live in the console. See https://aevral.com/products/pr-review.
- Is there an MCP agent? A PR reviewer?
- MCP agent coming soon. PR security review is the second product above, live and opt-in per organization. The scan fix path today is evidence plus a prompt you copy in the console. The GitHub Check on the scanned commit is a count plus a link to that report, not a PR comment.
- Are you affiliated with Anthropic?
- No. Aevral is not affiliated with, endorsed by, or sponsored by Anthropic. Claude and Claude Security are used nominatively to identify the product we compete with.