One App carries both products: the whole-repo scan at rest, and the PR security review as an opt-in add-on.
Self-serve. Install the App.
Install the GitHub App (https://github.com/apps/aevral) when your repositories live on GitHub. It is the only install: the console account you claim after is where you trigger scans and read reports.
The App is public: install it on the repositories you pick (https://github.com/apps/aevral). The waitlist form is for launch updates only; joining does not reserve a price, access, or a contract.
For the whole-repo scan, the App asks for Contents read, Metadata, and Checks write. Nothing more for this product. You pick the repositories, the same way any GitHub App install works, and scans run from the console or an enabled recurring schedule on a paid scan plan, not on every push.
PR review rides the same App as an opt-in add-on: your organization accepts Pull-requests read and write, and claiming a new organization starts reviews on. Setup Complete can turn them off. Existing opt-outs are preserved. Then Aevral posts an advisory Check plus inline comments grounded on the added lines. It never blocks a merge. Paid PR plans are live in the console.
What the scan reads
A tenant selector moves off the session
IDOR
An admin gate goes from a role to a login
Widened gate
A client token lands with org-wide scope
Over-grant
Aevral scans authorization, IDOR, and business-logic access control, and the console claims your install. Not memory corruption, not injection, not a general SAST.
Read next
The scan product; The PR security review product; Pricing (both SKUs); How Aevral compares; FAQ.
The other surface
One GitHub App. A report with evidence. A prompt for the agent you already use.