Pricing / Terms

Pricing terms

Every rule behind the prices, in full. Plans and prices are on the pricing page.

PR security review

USD per organization per month, excluding VAT. Paid plans are live in the console, billed monthly. Existing subscriptions keep their plan. Upgrading an existing subscription keeps its current price list.
PlanPriceIncluded private reviewsExtra reviewAvailability
Free$0per org / month25 private pull-request reviews per month.Subscribe in the console, or wait for the next month.Live
Starter$49per org / month100 PR reviews a month. A re-push does not count again.$0.99 per extra PR review, only if the owner chose extras.Live
Pro$199per org / month500 PR reviews a month. A re-push does not count again.$0.99 per extra PR review, only if the owner chose extras.Live
Business$999per org / month3,000 PR reviews a month. A re-push does not count again.Plus a monthly export of the security reviews Aevral ran on your pull requests, with coverage and results, that may serve as supporting evidence for automated security testing in audits (for example ISO 27001 A.8.29, SOC 2 CC8.1), and EU-only processing when it is available (not live yet).$0.99 per extra PR review, only if the owner chose extras.Live

Need more? Scale: $1,999 a month for 6,500 PR reviews, with everything in Business. Enterprise: from $4,000 a month, not self-serve, with a custom DPA (SSO when available). Talk to us. A standard DPA is available on every paid plan; a custom DPA is Enterprise. Read the DPA.

Pay from your own card. No meeting, no procurement.

What it is
  • A reviewer for the pull requests of an organization live on install: a Check on the head commit of each pull request it reviews, with inline comments pinned to the added lines when there is a grounded finding, looking for access control, business logic, injection, XSS, SSRF, path traversal, and LLM-integration flaws.
  • On a large pull request, Aevral reviews the most security-relevant files first, and the review says which files it covered.
  • Pull requests past the allowance get a neutral Check and no review; a run that fails before posting is not counted.
How it starts
  • PR review is live on install: installing the App starts PR reviews on the next pull request.
  • Installing the App starts reviews, even before anyone signs in.
  • Signing in to the console with GitHub later connects that install.
  • Setup Complete can still turn them off.
  • Reviews can be disabled at any time; reinstalling the App turns them back on.
  • Paid PR plans are live in the console.
Free tier and trial
  • Public repositories are free, 500 reviews per organization per month.
  • Reviews start at install: before anyone signs in, 25 private reviews a month are free.
  • Signing in with GitHub connects the install and starts a 14-day trial: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first.
  • After the trial, 25 private reviews a month are free (trial-covered reviews do not consume the subsequent Free allowance); past that, a pull request gets a neutral Check and no review until the next month.
  • No card.
  • Paid plans are purchasable in the console.
How the paid tiers differ
  • The paid tiers are volume allowances of the same review; they differ by included reviews.
  • Business adds the extras listed in its row.
  • Scale is Business with more included reviews.
Billing and going over
  • PR security review is priced on its own in USD per organization.
  • It needs no scan plan.
  • New organizations start with reviews on when the App install has accepted Pull-requests write.
  • The owner can turn reviews off.
  • Reviews are never counted as scans, and scans are never counted as reviews.
  • The first time a paid organization goes past its plan, it gets 25% more PR reviews free, once.
  • After that, reviews pause at the plan's limit unless the owner turned extras on, at checkout or later in the console: $0.99 per extra PR review, on every paid plan.
  • No automatic excess-review billing by default.
What counts as a review
  • On paid plans, a PR review is one pull request per billing period: a re-push is reviewed and does not count again.
  • On Free and during the trial, a review is one pull request head: repository, pull request number, head commit.
  • A new push is a new head and, if it is processed, a new review; the same head is never counted twice.
  • A pending review for an older head is skipped without charge when a newer push arrives.
  • A review holds its slot while it is pending or running and releases it if it is skipped or fails before posting; a posted review counts whether or not it found anything.
  • Public repositories do not consume the private allowance.
  • They are free, 500 reviews per organization per month.
  • Fair use: hourly and daily review limits apply per organization, higher on paid plans.
Extra reviews
  • Only on the paid PR tiers.
  • The first time an organization goes past its plan, it gets 25% more PR reviews free, once.
  • After that, $0.99 per extra PR review if the owner turned extras on (they are off by default; the owner can turn them on at checkout or later in the console); otherwise reviews pause until the next billing period, with a Check on the pull request saying why.
  • Extras stop at a monthly spend cap the owner can change in the console.
  • Scale is the top self-serve plan: at its limit, the path is extras or Enterprise.
  • The free tier has no extra reviews; private reviews pause until the next month.
Scale, Enterprise, DPA
  • Need more?
  • Scale: $1,999 a month for 6,500 PR reviews, with everything in Business.
  • Enterprise: from $4,000 a month, not self-serve, with a custom DPA (SSO when available).
  • A standard DPA is available on every paid plan; a custom DPA is Enterprise.

Whole-repo scans

USD per organization per month, excluding VAT.
PlanPriceIncludedExtra scanAvailability
Public repositories$0per org / month1 authorized public-repo scan per calendar monthNone. A second public scan that month is refused; the paid plans are the path.Free
Team$99per org / month4 default-branch scans$29 per scan, opt-inSelf-serve
Business$399per org / month16 default-branch scans$19 per scan, opt-inSelf-serve
Scale$1,699per org / month100 default-branch scans$17 per scan, opt-inSelf-serve
EnterpriseBy quotefrom $3,300 / month equivalent200 scans and up$16.50 per scan minimumBy quote: request one
Public repositories.
1 authorized public-repo scan per calendar month. Aevral itself is not open source. Authorization is required, and findings are not auto-published.
Team.
Private repositories start here, at $99 per organization per month.
Enterprise.
Quoted from $3,300 per month equivalent for 200 scans, annual commitment, invoice billing. Not self-serve: a quote is a conversation with us. The Enterprise console features (SSO / SAML, RBAC, audit log, multiple GitHub organizations, invoice / PO tooling) are not shipped yet.
What it is
  • A security researcher over the default-branch snapshot of a repository you authorized, started manually or on a paid recurring schedule.
  • You get a GitHub Check, a console report with evidence, and a fix prompt for your coding agent.
Availability
  • Live today, self-serve.
  • Team, Business and Scale can be bought in the console.
  • Public repositories is free.
  • Enterprise is by quote.
What every plan carries
  • Every scan plan carries the same product: whole-repo authorization / IDOR / business-logic scan on a default branch, GitHub Check and console report, fix prompt, open-source models, processed in the US today, with an EU-only option announced.
  • Team, Business and Scale differ by included volume and by the price of an extra scan.
  • Extras coming soon on Business and Scale: directory scope, Slack or webhook, CSV / Markdown export, documented dismissals.
  • Team, Business and Scale include recurring scans using your included allowance.
Recurring scans
  • Team, Business and Scale support up to four checkpoints per configured repository per billing month (period start plus 0, 7, 14 and 21 days).
  • They share your included allowance with manual scans.
  • Enabling picks the next future checkpoint, without replaying missed ones.
  • Unchanged commits reuse their report within the billing period.
  • Automatic scans never add charges or consume the private-scan trial.
  • If your allowance is used up, recurring scans wait for renewal.
Private-scan trial
  • New free organizations get two private whole-repo scans in 14 days.
  • Failed scans count.
  • This is not free weekly scanning.
  • After the trial, Team is the paid path.
  • A paid organization's first scan uses its included allowance.
  • You press Scan; Setup does not start a scan for you.
What counts as a scan
  • A scan counts when it is newly admitted: a manual or scheduled scan of a commit that has not been scanned in the period is accepted.
  • Pressing Scan again on the same commit in the same period returns the existing scan and counts nothing.
  • A scan that ran counts whether or not it found anything and whether or not it completed; only a scan that never ran is refunded.
Extra scans and the spend cap
  • Extra scans are opt-in: the per-scan price and the billable-scan definition are shown before purchase, and an owner-set monthly cap on extra-scan spend applies in the console.
  • No extra spend without explicit authorization.

Both products

Two products, one currency
  • Whole-repo scans and PR security review both bill in USD.
  • Both are priced per organization, never per seat.
  • Neither product requires the other, and the free PR review tier needs no subscription at all.
Resets
  • Included scans reset with the plan's billing period on Team, Business and Scale, and with the calendar month on Public repositories.
  • The free PR review allowance resets on the first day of each calendar month (UTC); paid PR tiers reset with their billing period.
  • No rollover.
VAT
  • All prices exclude VAT.
  • B2B.