For security engineers outnumbered by repositories and pull requests. Aevral reads the whole repo for authorization, IDOR, and business-logic access control, and every pull request through its opt-in PR review, handing you leads with evidence.
Security engineers are outnumbered. There are more repositories, more pull requests, and more merge buttons than there are hours, and the changes that matter most are the quiet ones: a dropped ownership check, a tenant binding that moves, a scope that widens to make a deploy pass. None of those look alarming in a diff view at midnight.
The leverage you need is a second reader that never tires and that reads for exactly the thing you would read for if you had the time: who has access to what.
Aevral goes through the default-branch snapshot of a repository the way a security researcher does: cross-file context, the authorization rules behind each route, the business logic that decides who may access what. It reads authorization, IDOR, and business-logic access control; it is not a general SAST and does not pretend memory corruption or injection are its lane.
Every finding is a lead with evidence: the file, the lines, and the reason a human should look. You stay the judge. The goal is not to replace your judgment, it is to point your judgment at the changes that need it instead of at everything that arrives.
The kind of change it reads
A tenant selector moves off the session
IDOR
An admin gate goes from a role to a login
Widened gate
A client token lands with org-wide scope
Over-grant
Today Aevral scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST. A finding is a lead with evidence, and a human decides. PR review is live as an opt-in add-on per organization; paid PR plans are coming soon.
Read next
The scan product; The PR security review product; How Aevral compares.
Also for
One GitHub App. A report with evidence. A prompt for the agent you already use.