For an opted-in organization, Aevral reads the diff of every pull request, plus up to 40 changed files at head, hunting authorization, IDOR, and business-logic flaws. It posts a Check on the head commit and inline comments pinned to the exact added lines. Silence when there is nothing to publish.
PR review is live and opt-in: claiming a new organization starts PR reviews on (the same default as Setup). Installing the App without claiming never authorizes reviews. Setup Complete can still turn them off. Existing opt-outs stay off, and reviews can be disabled at any time. Paid PR plans are live in the console.
How it runs
What it costs today
Public repositories are always free. Enabling PR review starts a 14-day trial with the first pull request Aevral processes after opt-in: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first. After the trial, 25 private reviews a month are free (trial-covered reviews do not consume the subsequent Free allowance); past that, a pull request gets a neutral Check and no review until the next month. No card. Paid plans are purchasable in the console.
| Plan | Price | Included private reviews | Extra review | Availability |
|---|---|---|---|---|
| Free | $0per org / month | 25 private pull-request reviews per month. | Subscribe in the console, or wait for the next month. | Live |
| Starter | $19per org / month | 100 included private reviews, then $0.49 per review. | $0.49 per extra review, opt-in only. | Live |
| Pro | $99per org / month | 500 included private reviews, then $0.49 per review. | $0.49 per extra review, opt-in only. | Live |
| Business | $249per org / month | 2000 included private reviews, then $0.49 per review. | $0.49 per extra review, opt-in only. | Live |
The paid tiers are volume allowances of the same review; they differ by included reviews, not by features. PR security review is Aevral's second product, priced on its own in USD per organization. It needs no scan plan: an organization owner or admin enables it from the console, on an organization whose App install has accepted Pull-requests write. Reviews are never counted as scans, and scans are never counted as reviews. Paid plans stop at the included allowance unless an owner explicitly enables $0.49 excess reviews. No automatic excess-review billing by default.
Grounding, not spray
Every inline comment is pinned to a line the pull request actually added, on a file the pull request actually touched. If the evidence cannot be grounded, the comment does not post. Oversized pull requests get a neutral note, not a partial review sold as complete.
The same reading at rest is a separate product: the whole-repo scan, manual or recurring on a paid scan plan, with its own allowance. See the scan product.
One GitHub App. A Check on each pull request it reviews, with inline comments when there is a grounded finding, opt-in per organization. Free tier live: public repos free, 25 private reviews a month. Paid plans are live in the console.