[Pricing]

Two products. Priced per organization, never per seat.

Whole-repo scans are priced in EUR with included scans per month. PR security review is priced in USD with included private reviews per month. One GitHub App and one console for both; neither product requires the other, and the free PR review tier needs no subscription at all.

Whole-repo scan plansPR security review plans

Product 1

Whole-repo scans

A security researcher over the default-branch snapshot of a repository you authorized, started manually or on a paid recurring schedule. You get a GitHub Check, a console report with evidence, and a fix prompt for your coding agent.

Live today, self-serve. Team, Business and Scale can be bought in the console. Public repositories is free. Enterprise is by quote.

EUR per organization per month, excluding VAT.
PlanPriceIncludedExtra scanAvailability
Public repositories€0per org / month1 authorized public-repo scan per calendar monthNone. A second public scan that month is refused; the paid plans are the path.Free
Team€99per org / month4 default-branch scans€29 per scan, opt-inSelf-serve
Business€399per org / month16 default-branch scans€19 per scan, opt-inSelf-serve
Scale€1,699per org / month100 default-branch scans€17 per scan, opt-inSelf-serve
EnterpriseBy quotefrom €3,300 / month equivalent200 scans and up€16.50 per scan minimumBy quote: request one
Public repositories.
1 authorized public-repo scan per calendar month. Aevral itself is not open source. Authorization is required, and findings are not auto-published.
Team.
Private repositories start here, at €99 per organization per month.
Enterprise.
Quoted from €3,300 per month equivalent for 200 scans, annual commitment, invoice billing. Not self-serve: a quote is a conversation with us. The Enterprise console features (SSO / SAML, RBAC, audit log, multiple GitHub organizations, invoice / PO tooling) are not shipped yet.

Every scan plan carries the same product: whole-repo authorization / IDOR / business-logic scan on a default branch, GitHub Check and console report, fix prompt, open-source models hosted in the US or the EU. Team, Business and Scale differ by included volume and by the price of an extra scan. Extras coming soon on Business and Scale: directory scope, Slack or webhook, CSV / Markdown export, documented dismissals. Team, Business and Scale include recurring scans using your included allowance.

This button joins the launch-updates list, which does not reserve a price or access. To use Aevral today: install the GitHub App, then log in to the console, claim your organization, and press Scan.

Product 2, opt-in per organization

PR security review

A reviewer for the pull requests of an organization that opted in: a Check on the head commit of each pull request it reviews, with inline comments pinned to the added lines when there is a grounded finding, for authorization, IDOR and business-logic flaws. Pull requests past the allowance and oversized ones get a neutral Check and no review; a run that fails before posting is not counted.

PR review is live and opt-in: claiming a new organization starts PR reviews on (the same default as Setup). Installing the App without claiming never authorizes reviews. Setup Complete can still turn them off. Existing opt-outs stay off, and reviews can be disabled at any time. Paid PR plans are live in the console.

Public repositories are always free. Enabling PR review starts a 14-day trial with the first pull request Aevral processes after opt-in: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first. After the trial, 25 private reviews a month are free (trial-covered reviews do not consume the subsequent Free allowance); past that, a pull request gets a neutral Check and no review until the next month. No card. Paid plans are purchasable in the console.

USD per organization per month, excluding VAT. Paid plans are live in the console.
PlanPriceIncluded private reviewsExtra reviewAvailability
Free$0per org / month25 private pull-request reviews per month.Subscribe in the console, or wait for the next month.Live
Starter$19per org / month100 included private reviews, then $0.49 per review.$0.49 per extra review, opt-in only.Live
Pro$99per org / month500 included private reviews, then $0.49 per review.$0.49 per extra review, opt-in only.Live
Business$249per org / month2000 included private reviews, then $0.49 per review.$0.49 per extra review, opt-in only.Live

The paid tiers are volume allowances of the same review; they differ by included reviews, not by features. PR security review is Aevral's second product, priced on its own in USD per organization. It needs no scan plan: an organization owner or admin enables it from the console, on an organization whose App install has accepted Pull-requests write. Reviews are never counted as scans, and scans are never counted as reviews. Paid plans stop at the included allowance unless an owner explicitly enables $0.49 excess reviews. No automatic excess-review billing by default.

This button joins the launch-updates list, which does not reserve a price or access. To use Aevral today: install the GitHub App, then log in to the console, enable PR review from the Reviews page.

Common terms

What counts, and when it resets.

Recurring scans
Team, Business and Scale support up to four checkpoints per configured repository per billing month (period start plus 0, 7, 14 and 21 days). They share your included allowance with manual scans. Enabling picks the next future checkpoint, without replaying missed ones. Unchanged commits reuse their report within the billing period. Automatic scans never add charges or consume the free private baseline. If your allowance is used up, recurring scans wait for renewal.
First private scan
New free organizations can start with one lifetime private baseline scan when available. This is not free weekly scanning. A paid organization's first scan uses its included allowance. Setup selects an eligible repository, with an option to skip.
Two products, two currencies
Whole-repo scans bill in EUR. PR security review bills in USD on its paid plans. Both are priced per organization, never per seat. Neither product requires the other, and the free PR review tier needs no subscription at all.
VAT
All prices exclude VAT. B2B.
What counts as a scan
A scan counts when it is newly admitted: a manual or scheduled scan of a commit that has not been scanned in the period is accepted. Pressing Scan again on the same commit in the same period returns the existing scan and counts nothing. A scan that ran counts whether or not it found anything and whether or not it completed; only a scan that never ran is refunded.
What counts as a review
A review is one pull request head: repository, pull request number, head commit. A new push is a new head and, if it is processed, a new review; the same head is never counted twice. A pending review for an older head is skipped without charge when a newer push arrives. A review holds its slot while it is pending or running and releases it if it is skipped, oversized or fails before posting; a posted review counts whether or not it found anything. Public repositories are never counted.
Resets
Included scans reset with the plan's billing period on Team, Business and Scale, and with the calendar month on Public repositories. The free PR review allowance resets on the first day of each calendar month (UTC); paid PR tiers, when they open, reset with their billing period. No rollover.
Extra scans and the spend cap
Extra scans are opt-in: the per-scan price and the billable-scan definition are shown before purchase, and an owner-set monthly cap on extra-scan spend applies in the console. No extra spend without explicit authorization.
Extra reviews
Only on the paid PR tiers, when they open: $0.49 per review past the included allowance, opt-in. The free tier has no extra reviews; private reviews pause until the next month.

Joining the waitlist does not reserve a price, access, or a contract.


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.