Security review for the age of agents
Coding agents made writing code almost free. Reading it stayed expensive. Security is the part of shipping that depended on careful reading, and that just stopped being a process anyone can actually run.
The security read stopped happening.
A team shipping with agents can produce pull requests faster than anyone reads them. Feature review still gets its sampling, because broken code complains loudly. The security read is the one nobody schedules, so it is the one that quietly disappears. Sampling is a decision, it is just never made on purpose.
Sampling doesn't work for security.
Quality problems announce themselves. A broken feature gets reported, reproduced, fixed. Security problems stay quiet. An authorization hole does not file a ticket; it waits until someone finds it, and nobody schedules that day.
So security review cannot be something someone remembers to ask for. It has to run on its own, on the new pull requests, whether or not anyone thought about security that day. The old habit was to review what felt risky. Risk does not say which files it is in.
And security review cannot be a feature of your agent vendor.
You will switch agents. This year's Claude Code is next year's Cursor, or Codex, or something that does not exist yet, and your security review has to survive that switch. A review that is a feature of your agent vendor moves every time you move, and quietly becomes a reason not to move at all.
Independence on its own is not the point. Open models are the only version of that promise you can verify.
Security findings you can check against a model anyone can inspect.
A reviewer that answers to no vendor and no roadmap has no reputation to lean on either. So its findings have to carry their own evidence: the problem in plain words, the line it lives on, a suggested fix. And it stays advisory, because a security reviewer that gets the last word stops being read.
Put together, the argument has a shape. It reads new pull requests in the repositories where it is installed, as they open, because risk does not say which files it is in. It takes any agent's work, because you will switch agents. It shows its evidence, because nothing vouches for it. It runs on open-source models, so the review does not live or die with one lab's product roadmap. Priced per organization, never per seat, because agents were supposed to decouple code from headcount, and per-seat pricing would bill you for the change you bought.
A suggestion, not a blocker. You decide what ships.
That is Aevral.