# Aevral Aevral is built as an alternative to Claude Security: scan the repository, review the findings, hand a fix prompt to Claude Code, Cursor, or Codex. Open-source models, hosted in the US or the EU. Priced by organization, not by seat. No floor to start. By ISMS Copilot. ## Products Two products, two surfaces, two prices. 1. Whole-repo scan (at rest): a security researcher over the default-branch snapshot of a repository. Trigger: the console Scan button or a paid recurring schedule. Output: a GitHub Check on the scanned commit, a console report with evidence, and a copy fix prompt. Today it scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST. GitHub App permissions for this product: Contents read, Metadata, Checks write. 2. PR security review (add-on (the second product)): a reviewer on every pull request (opened, reopened, synchronize). A Check on the head commit plus inline comments grounded on added lines, authorization / IDOR / business-logic only, hard max two findings per review. Needs Pull-requests read and write. PR review is live and opt-in per organization: the owner enables it in the console, and Aevral never reviews a pull request for an organization that has not opted in. Paid PR plans live in the console. ## Status Aevral is self-serve: install the GitHub App (https://github.com/apps/aevral) and log in to the console to claim your install. Claude Security is in public beta for Claude Enterprise. Where the site still shows a waitlist CTA (https://tally.so/r/dWe0kK), joining does not reserve a price, access, or a contract. There is no marketing mailto. Contact form: https://tally.so/r/PdxdbV. Present-tense verbs: scan, report, hand off. Aevral does not validate findings or generate patches today. Copy fix prompt into Claude Code, Cursor, or Codex (equal weight). A finding is a lead with evidence, not a confirmation. MCP agent coming soon. PR review is live and opt-in per organization; paid PR plans live in the console. ## Prices Two products, both priced per organization, never per seat; neither requires the other. Whole-repo scan, EUR per organization per month, HT B2B excluding VAT: Public repositories EUR 0 (1 authorized public-repo scan per calendar month per organization; a second public scan that month is refused), Team EUR 99 (4 default-branch scans, then EUR 29 per extra scan, opt-in), Business EUR 399 (16 then EUR 19), Scale EUR 1,699 (100 then EUR 17). Team, Business and Scale are self-serve in the console. Enterprise by quote: from EUR 3,300 per month equivalent (200 scans and up, EUR 16.50 per scan minimum), annual commitment, invoice billing; not self-serve, Enterprise console features (SSO/SAML, RBAC, audit log, multiple GitHub orgs, invoice/PO tooling) not shipped. A scan counts when newly admitted (re-scanning the same commit in a period returns the existing scan); a scan that ran counts whether or not it found anything; only a never-run scan is refunded. Included scans reset with the billing period (calendar month for Public repositories), no rollover. Extra scans are opt-in under an owner-set monthly cap on extra-scan spend. PR security review, the second product, USD per organization per month excluding VAT, no scan plan required (an organization owner or admin enables it from the console; the App install must have accepted Pull-requests write): public repositories always free and never counted. Enabling starts a 14-day trial with a 500-review cap, starting with the first pull request Aevral processes after opt-in; the trial ends at 14 days or 500 private reviews, whichever comes first. After the trial, 25 private reviews per calendar month (UTC) free (trial-covered reviews do not consume the subsequent Free allowance); at the cap a pull request gets a neutral Check and no review until the next month. No card. Paid plans live in the console: Starter $19 / 100 included private reviews, Pro $99 / 500, Business $249 / 2000, then $0.49 per extra review on every paid tier, opt-in; the free tier has no extra reviews. A review is one pull request head (repository, PR number, head commit); the same head is never counted twice; reviews skipped, oversized or failed before posting are not counted. A review is never one of the included whole-repo scans of a scan plan. Price shapes compared with Claude Security (org units vs Enterprise seats plus tokens; different units, do your own math): https://aevral.com/pricing/compare. ## For agents Customer docs center (how-to corpus): https://docs.aevral.com/docs. Its machine index: https://docs.aevral.com/llms.txt. Agent hub on the docs host: https://docs.aevral.com/docs/for-ai-agents. Agent one-pager (GTM page): https://aevral.com/for-agents. aevr_ API keys exist today (console Developer API page, shown once): they start and read scans for their own organization; billing is console-session-only. The fuller public API contract is coming. No live MCP endpoint today; do not claim one. This file is the durable machine-readable source of truth for products, prices, routes, and status. Full route index: https://aevral.com/llms-full.txt. AI crawler directives: https://aevral.com/ai.txt. Agent manifest: https://aevral.com/.well-known/agent.json. ## Compare Compare hub: https://aevral.com/compare. Claude Security is the one even comparison; of the sixteen other tools, eleven publish security scope that touches the job (their pages carry the split), five do a different stated job. The competitor page is an even table, not a catch-rate boast. The complementary pages state each tool's own published job and never claim what that tool would or would not flag; Aevral adds the authorization / IDOR / business-logic reading alongside it. Aikido's platform (SAST, dependencies, secrets, IaC, pentest) is complementary. Aikido also publishes Code Security Audit and Deep Review for authorization, IDOR, and business-logic reading of source; Aevral is built for that reading. See https://aevral.com/compare/aikido. CodeRabbit also publishes CodeRabbit Security, agentic code security monitoring: scheduled repository scans and security scans of each pull request, per CodeRabbit's site. CodeRabbit Security and Aevral's opt-in pull-request review both read pull requests for security. See https://aevral.com/compare/coderabbit. Greptile publishes security, including a Security Check scope, among its review; that review and Aevral's opt-in pull-request review both read pull requests. See https://aevral.com/compare/greptile. SonarQube runs platform quality and security analysis and its Hunter Agent hunts logic flaws (SonarQube Cloud Enterprise, announced for Server in 2026-08, per Sonar); Aevral's single job is the access reading, at rest and on the pull request. See https://aevral.com/compare/sonarqube. Codex Security is OpenAI's application security agent: workbench, CLI and SDK, and cloud scans, plus Security Review on pull requests, both in research preview as of 2026-09-07; both products read pull requests for security and repositories. See https://aevral.com/compare/codex-security. ZeroPath publishes business-logic and broken-authentication detection with PR reviews and one-click autofix across a broad AppSec stack; Aevral's single job is the access reading, at rest and on the pull request. See https://aevral.com/compare/zeropath. AISLE runs AI-native vulnerability management in cloud, on-prem, or air-gapped deployments, with business-logic and broken-access-control scope in its AI SAST, fix agents, and agentic verification; Aevral's single job is the access reading, at rest and on the pull request. See https://aevral.com/compare/aisle. Tachyon reviews pull requests in full-codebase context and validates findings for exploitability before reporting, with a fix attached; its published examples include broken access control and IDOR, and both products read pull requests for security. See https://aevral.com/compare/tachyon. Gecko Security analyzes code, logic, and infrastructure with a semantic graph across repos and microservices, with a pull-request review bot and one-click autofix; Aevral's single job is the access reading, at rest and on the pull request. See https://aevral.com/compare/gecko-security. Nullify drives product-security findings to merge-ready remediation PRs with exploit validation, with broken access control and IDOR in its published detection scope; Aevral's single job is the access reading, at rest and on the pull request. See https://aevral.com/compare/nullify. - Aevral and Claude Security (competitor, even table): https://aevral.com/compare/claude-security - Semgrep and Aevral (complementary; overlaps the job: AI-powered detection incl. IDOR and broken authorization): https://aevral.com/compare/semgrep - Snyk Code and Aevral (complementary): https://aevral.com/compare/snyk-code - CodeQL and Aevral (complementary): https://aevral.com/compare/codeql - Aikido and Aevral (complementary; platform plus Code Security Audit): https://aevral.com/compare/aikido - GitHub Copilot code review and Aevral (complementary): https://aevral.com/compare/github-copilot - Cursor Bugbot and Aevral (complementary): https://aevral.com/compare/bugbot - CodeRabbit and Aevral (complementary; reviews plus CodeRabbit Security monitoring): https://aevral.com/compare/coderabbit - Greptile and Aevral (complementary; review plus Security Check scope): https://aevral.com/compare/greptile - Socket and Aevral (complementary): https://aevral.com/compare/socket - SonarQube and Aevral (complementary; platform plus Hunter Agent): https://aevral.com/compare/sonarqube - Codex Security and Aevral (complementary; scans plus Security Review): https://aevral.com/compare/codex-security - Nullify and Aevral (complementary; autonomous remediation to merge-ready PRs): https://aevral.com/compare/nullify - Gecko Security and Aevral (complementary; semantic cross-service scanning): https://aevral.com/compare/gecko-security - Tachyon and Aevral (complementary; exploit-validated PR security reviews): https://aevral.com/compare/tachyon - AISLE and Aevral (complementary; AI-native vulnerability management, perimeter-deployed): https://aevral.com/compare/aisle - ZeroPath and Aevral (complementary; AI-native SAST platform plus logic and auth detection): https://aevral.com/compare/zeropath ## Install Install hub: https://aevral.com/install. One GitHub App plus the console. Install https://github.com/apps/aevral; once installed, PR review is opt-in per organization from the console. - GitHub App surface: https://aevral.com/install/github. Install https://github.com/apps/aevral. Scan permissions: Contents read, Metadata, Checks write. PR review adds Pull-requests read and write and is opt-in per organization from the console. - Console surface: https://aevral.com/install/console. Press Scan on the default branch, read findings with evidence, copy a fix prompt. aevr_ keys exist today (Developer API page); billing is console-session-only. No live MCP endpoint today. ## Who it is for Personas hub: https://aevral.com/for. One reading, four audiences: authorization, IDOR, and business-logic access control across the repository, and across every pull request through the opt-in PR review add-on. - Security engineers: https://aevral.com/for/security-engineers - AI security engineers: https://aevral.com/for/ai-security-engineers - Teams shipping agent-written code: https://aevral.com/for/teams-shipping-agent-code - Open-source maintainers (public repos are the free lane): https://aevral.com/for/open-source-maintainers ## Alternatives Alternatives hub: https://aevral.com/alternatives. Field maps with each tool described by its own stated job and linked to a deeper comparison. Aevral is never listed as a like-for-like alternative to a SAST: on the anchored pages it is the authorization / IDOR / business-logic reading you add alongside. The Claude-Security-alternative framing lives on the compare page. - Whole-repo AI security scanners in 2026 (roundup): https://aevral.com/alternatives/best-whole-repo-ai-scanners - IDOR and broken access control scanners in 2026 (field map): https://aevral.com/alternatives/idor-and-access-control-scanners - Semgrep alternatives: https://aevral.com/alternatives/semgrep-alternatives - Snyk Code alternatives: https://aevral.com/alternatives/snyk-code-alternatives - CodeRabbit alternatives: https://aevral.com/alternatives/coderabbit-alternatives ## Guides Guides hub: https://aevral.com/guides. Substance pages with primary sources: the access-control surface vocabulary (OWASP API1:2023 / API5:2023, CWE-639, CWE-284), the pipeline mechanics, the fix-prompt walkthrough, the PR access-review checklist, and the launch-updates list explainer. - What a whole-repo authorization scan reads (OWASP API1/API5, CWE-639, CWE-284 cited): https://aevral.com/guides/whole-repo-authorization-scan - PR security review and SAST are different questions: https://aevral.com/guides/pr-security-review-vs-sast - Handing a security finding to your coding agent: https://aevral.com/guides/handing-a-fix-prompt - Reviewing a pull request for access control (the diff review checklist): https://aevral.com/guides/reviewing-a-pr-for-access-control - The Aevral launch-updates list, explained: https://aevral.com/guides/waitlist-and-opening ## Works alongside Tools Aevral runs beside, each doing its stated job while Aevral adds the authorization / IDOR / business-logic reading: https://aevral.com/checks. Each page states the tool's focuses and what Aevral adds alongside it, and links to the fuller comparison. Never a claim about what the other tool would or would not flag. - Semgrep and Aevral, at a glance (overlaps the job): https://aevral.com/checks/semgrep - Snyk Code and Aevral, at a glance: https://aevral.com/checks/snyk-code - CodeQL and Aevral, at a glance: https://aevral.com/checks/codeql - Aikido and Aevral, at a glance (platform plus Code Security Audit): https://aevral.com/checks/aikido - GitHub Copilot code review and Aevral, at a glance: https://aevral.com/checks/github-copilot - Cursor Bugbot and Aevral, at a glance: https://aevral.com/checks/bugbot - CodeRabbit and Aevral, at a glance (reviews plus CodeRabbit Security monitoring): https://aevral.com/checks/coderabbit - Greptile and Aevral, at a glance (review plus Security Check scope): https://aevral.com/checks/greptile - Socket and Aevral, at a glance: https://aevral.com/checks/socket - SonarQube and Aevral, at a glance (platform plus Hunter Agent): https://aevral.com/checks/sonarqube - Codex Security and Aevral, at a glance (scans plus Security Review): https://aevral.com/checks/codex-security - Nullify and Aevral, at a glance (remediation agents): https://aevral.com/checks/nullify - Gecko Security and Aevral, at a glance (semantic scanning): https://aevral.com/checks/gecko-security - Tachyon and Aevral, at a glance (PR security reviews): https://aevral.com/checks/tachyon - AISLE and Aevral, at a glance (vulnerability management): https://aevral.com/checks/aisle - ZeroPath and Aevral, at a glance (AI-native SAST platform): https://aevral.com/checks/zeropath ## Pages Home https://aevral.com. Products hub https://aevral.com/products. Scan product https://aevral.com/products/scan. PR review product https://aevral.com/products/pr-review. Pricing (both products) https://aevral.com/pricing. Compare hub https://aevral.com/compare, last verified 2026-08-31 against https://claude.com/product/claude-security and https://support.claude.com/en/articles/14661296-use-claude-security for the Claude Security rows. Works-alongside hub https://aevral.com/checks. FAQ https://aevral.com/faq. About https://aevral.com/about. For agents https://aevral.com/for-agents. Trust: https://trust.ismscopilot.com. ISO 27001 programme (not certified today; intended company scope includes Aevral): https://trust.ismscopilot.com/en/iso-27001. Privacy: https://trust.ismscopilot.com/privacy-policy. Legal entity: Better ISMS / ISMS Copilot, Better ISMS EURL, 60 rue François 1er, 75008 Paris. Transparency report (scope, method, full frozen eval matrix, corpus digest, reproduction protocol) https://aevral.com/transparency. Aevral is not affiliated with Anthropic. ## Setup and ongoing coverage Claiming a new organization starts PR reviews on. Installing the App without claiming does not enable processing, and existing opt-outs stay off. Setup Complete can turn reviews off and starts the chosen first repository scan, with an option to skip. One private baseline per free organization when available; paid organizations use included scan quota. No setup overage. Team EUR 99 / 4, Business EUR 399 / 16 and Scale EUR 1,699 / 100 share their included allowance between manual and recurring scans. Each configured repository gets up to four checkpoints per billing month (start plus 0/7/14/21 days), not permanent free weekly scans. Unchanged commits reuse the existing result within the billing period; quota exhaustion waits for renewal. Automatic scans never incur overage. PR plans: Free 25 private reviews per calendar month after the existing 14-day/500-review trial; Starter USD 19 / 100, Pro USD 99 / 500, Business USD 249 / 2000. Paid excess private reviews cost USD 0.49 each only after explicit owner authorization. Scan and PR review allowances are separate.