[Explainer]

The Aevral launch-updates list, explained

The honest mechanics: the product is self-serve today, and the email list is an optional launch-updates channel that reserves nothing.

Aevral,

This page used to be a waitlist explainer; today it is the launch-updates explainer. What the list is, what the product already does, and what you are and are not committing to. Short version: you are joining an email list, and that is all. The product is self-serve without it.

What you are joining

An email list, collected through a hosted form, used for one thing: product updates by email, like new scan classes and new surfaces. Joining does not reserve a price, access, or a contract. The product itself is self-serve without the list: install https://github.com/apps/aevral and log in to the console whenever you want. If you would rather talk to a human first, the contact form exists for exactly that, and nothing on this site requires an account to read.

What is live today, in order of signup

Install the GitHub App on any account, log in to the console, claim your install, and run self-serve scans per the published pricing: authorization, IDOR, and business-logic access control on the default branch, per organization, EUR 0 for authorized public repos, then the paid org tiers.

Today there is also an aevr_ API key from the console Developer API page and a start-scan request, so the console is one client among possible others. The PR security review is the add-on SKU beside it: live and opt-in per organization. An MCP server is planned after that, and there is no live MCP endpoint today.

What stays true

Findings are leads with evidence, not confirmations. No validation pass runs on findings, no patches are generated, and a scan is not a clean bill of health. Priced by organization, not by seat, self-serve from EUR 0. Public repositories keep their free lane: one authorized scan per calendar month, and always-free PR review through the opt-in add-on.

If you need us

The contact form reaches a human at the company behind Aevral, Better ISMS, the same people behind ISMS Copilot. Waitlist or not, the door is the same.

Sources

Pricing (both SKUs); Install (self-serve: install, claim, scan); For AI agents (the API facts).

Read next

About Aevral; FAQ.

More guides


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.