[Product / Whole-repo scan]

A security researcher on your whole repo.

Press Scan in the Aevral console and a researcher goes through the default-branch snapshot of your repository the way a human would: cross-file context, authorization rules, the business logic behind who has access to what. You get a GitHub Check, a console report with evidence for every finding, and a fix prompt to hand to the coding agent you already use.

How it runs

Install
Install the Aevral GitHub App. Contents read, Metadata, Checks write. Nothing more for this product.
Scan
Complete Setup to start the selected first scan, press Scan for a manual run, or configure recurring scans on a paid scan plan. Aevral reads the default-branch snapshot.
Read
A GitHub Check on the scanned commit, plus the full report in the console. Each finding carries its evidence. A finding is a lead, not a confirmation.
Hand off
Copy the fix prompt into Claude Code, Cursor, or Codex. A human reviews before merge. We do not generate patches today.

Today Aevral scans authorization, IDOR, and business-logic access control. Not memory corruption, not injection, not a general SAST.

What it costs

Live today, self-serve. Team, Business and Scale can be bought in the console. Public repositories is free. Enterprise is by quote.

EUR per organization per month, excluding VAT.
PlanPriceIncludedExtra scanAvailability
Public repositories€0per org / month1 authorized public-repo scan per calendar monthNone. A second public scan that month is refused; the paid plans are the path.Free
Team€99per org / month4 default-branch scans€29 per scan, opt-inSelf-serve
Business€399per org / month16 default-branch scans€19 per scan, opt-inSelf-serve
Scale€1,699per org / month100 default-branch scans€17 per scan, opt-inSelf-serve
EnterpriseBy quotefrom €3,300 / month equivalent200 scans and up€16.50 per scan minimumBy quote: request one
Public repositories.
1 authorized public-repo scan per calendar month. Aevral itself is not open source. Authorization is required, and findings are not auto-published.
Team.
Private repositories start here, at €99 per organization per month.
Enterprise.
Quoted from €3,300 per month equivalent for 200 scans, annual commitment, invoice billing. Not self-serve: a quote is a conversation with us. The Enterprise console features (SSO / SAML, RBAC, audit log, multiple GitHub organizations, invoice / PO tooling) are not shipped yet.

B2B. All prices excluding VAT. Extra scans are opt-in: the per-scan price and the billable-scan definition are shown before purchase, and an owner-set monthly cap on extra-scan spend applies in the console. No extra spend without explicit authorization.

What Aevral does not do

  • No patch generation. The fix prompt is yours to hand to the agent you already use.
  • No confirmation pass on findings. A scan is not a clean bill of health.
  • Not a general SAST. Today Aevral scans authorization, IDOR, and business-logic access control, not memory corruption or injection.
  • Does not replace SAST, SCA, secrets detection, or a pentest.

The same reading on the diff is a separate product: PR security review, live as an opt-in add-on per organization with no scan plan required; paid PR plans are live in the console. See the PR review product.


Scan your whole repo for access bugs.

One GitHub App. A report with evidence. A prompt for the agent you already use.