Press Scan in the Aevral console and a researcher goes through the default-branch snapshot of your repository the way a human would: cross-file context, authorization rules, the business logic behind who has access to what. You get a GitHub Check, a console report with evidence for every finding, and a fix prompt to hand to the coding agent you already use.
How it runs
Today Aevral scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST.
What it costs
Live today, self-serve. Team, Business and Scale can be bought in the console. Public repositories is free. Enterprise is by quote.
| Plan | Price | Included | Extra scan | Availability |
|---|---|---|---|---|
| Public repositories | €0per org / month | 1 authorized public-repo scan per calendar month | None. A second public scan that month is refused; the paid plans are the path. | Free |
| Team | €99per org / month | 4 default-branch scans | €29 per scan, opt-in | Self-serve |
| Business | €399per org / month | 16 default-branch scans | €19 per scan, opt-in | Self-serve |
| Scale | €1,699per org / month | 100 default-branch scans | €17 per scan, opt-in | Self-serve |
| Enterprise | By quotefrom €3,300 / month equivalent | 200 scans and up | €16.50 per scan minimum | By quote: request one |
B2B. All prices excluding VAT. Extra scans are opt-in: the per-scan price and the billable-scan definition are shown before purchase, and an owner-set monthly cap on extra-scan spend applies in the console. No extra spend without explicit authorization.
What Aevral does not do
The same reading on the diff is a separate product: PR security review, live as an opt-in add-on per organization with no scan plan required; paid PR plans are live in the console. See the PR review product.
One GitHub App. A report with evidence. A prompt for the agent you already use.