Explainer

Security review priced per pull request, explained

Aevral prices its PR security review per organization, as a monthly allowance of pull-request reviews. On paid plans one pull request counts once per billing period, however often it is re-pushed. The free tier needs no card.

Tristan Roth,

Aevral prices its PR security review per organization, not per seat, as a monthly allowance of pull-request reviews. Free covers 25 private reviews a month. Starter is $19 for 100 reviews a month, Pro is $99 for 500 reviews a month, Business is $249 for 2000 reviews a month. On paid plans, a pull request counts as one review per billing period, however often it is re-pushed. Public repositories are free, 500 reviews per organization per month. Prices exclude VAT and other taxes.

The rest of this page is the plain version of that paragraph: what a review is, what each plan includes, what happens when the allowance runs out, and why the unit is the pull request and not the person.

What you are paying for

Picture a team of three where most pull requests are opened by coding agents. Nobody on the team is a security specialist. Per-seat pricing would charge for the three people, and the agents that open most of the pull requests would not count at all. Aevral charges for the work instead: one security review of one pull request.

A review is what happens after the Aevral GitHub App is installed on a repository, live on install. When a pull request is opened, reopened, or updated, Aevral reads the diff plus up to 40 changed files at head, then posts an advisory Check on the head commit and, when there is a grounded finding, inline comments pinned to the added lines. At most two findings per review, each with a suggested fix. It never blocks a merge.

What each plan includes

Free: $0 per org / month. 25 private pull-request reviews per month. Public repositories are free, 500 reviews per organization per month.

Starter: $19 per org / month for 100 PR reviews. Past the plan: $0.49 per extra PR review, only if the owner chose extras.

Pro: $99 per org / month for 500 PR reviews. Past the plan: $0.49 per extra PR review, only if the owner chose extras.

Business: $249 per org / month for 2000 PR reviews. Past the plan: $0.49 per extra PR review, only if the owner chose extras.

The paid plans are monthly allowances of the same review and differ by volume, not by features. Prices exclude VAT and other taxes.

What counts once, and what does not count

On paid plans, a PR review is one pull request per billing period. An agent that pushes to the same pull request ten times gets each push reviewed, and the pull request still counts once. On Free and during the trial, a review is one pull request head (repository, pull request number, head commit): a new push is a new head, and the same head is never counted twice.

A review that is skipped or fails before posting is not counted. A posted review counts whether or not it found anything, because the work was done. Public repositories do not consume the private allowance. Reviews are never counted as scans, and the whole-repo scan is a separate product with its own EUR price list.

When the allowance runs out

The first time a paid organization goes past its plan, it gets 25% more PR reviews free, once. After that, reviews pause at the plan's limit unless the owner turned extras on: $0.49 per extra PR review, only if the owner chose extras. At checkout the cap on extras defaults to the plan's monthly price, and it can be changed in the console. A paused pull request gets a neutral Check saying why, so nothing fails silently.

On the free tier there are no extras: past 25 private reviews a month, a pull request gets a neutral Check and no review until the next month. No card is asked for on the free tier.

From install to the first comment

One: install the Aevral GitHub App on the repositories you choose; a GitHub owner or admin approves the install. PR review is live on install: installing the App starts reviews on the next pull request, even before anyone signs in, and the owner can turn them off in Setup.

Two: sign in to the console with GitHub. That connects the install and starts a 14-day trial for private repositories: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first.

Three: open a pull request, or let your coding agent open one. Aevral reads the diff plus up to 40 changed files at head.

Four: read the result on the pull request. An advisory Check sits on the head commit, and when there is a grounded finding, inline comments sit on the added lines, at most two findings per review. Each finding carries the evidence, a suggested fix, and a Fix with your agent prompt a human can paste into Claude Code, Cursor, or Codex. Aevral never pushes, applies, or merges anything, and it never blocks a merge. You decide what ships.

Sources

Pricing; Pricing compared; The PR review product.

Read next

PR security review and SAST are different questions; Reviewing pull requests for IDOR with a GitHub app; Install the GitHub App.

More guides


Security review, handled.

Install the GitHub App and PR review starts on. Sign in with GitHub to connect it, then press Scan for the repository you already have.

Install the GitHub AppLog in

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.