What the Aevral GitHub App can do, what code it reads, where that code goes, what is stored and for how long, and what we do not have yet.
This page is an operational summary. The binding terms are the Data Processing Agreement, section 1.7 (opens in a new tab), and the Aevral sub-processor page (opens in a new tab). Where they differ from this page, they win.
Verified against the running worker 0c47cd225 on . Each statement says how it is backed: verified in code, reported by the running service, or policy.
The Aevral GitHub App holds these permissions: Contents read and write, Issues read, Metadata read, Checks write, and Pull requests read and write. It receives pull request and issue comment events. It has no administration, secrets, workflows or deployments permission. Contents write and Issues read were added on 2026-10-01 for the announced features below; no code uses them yet.
Reported by the running service
Every token Aevral mints is capped below what the App holds: Contents read, Metadata read and Checks write, plus Pull requests write for pull request reviews. No token Aevral mints carries Contents write or Issues access.
Verified in code
Each scan or pull request review gets its own GitHub token, minted for that job, limited to one repository and capped as described above. Tokens live in memory only, expire after GitHub's default of one hour, and are never stored.
Verified in code
One stated exception: refreshing the list of repositories you selected uses an installation-wide token with the same capped permissions. No other part of Aevral can obtain an installation-wide token.
Verified in code
Aevral writes to your repositories only as advisory check runs and pull request review comments submitted as comments. It never commits, pushes, creates branches, merges or approves. Suggested fixes are text only.
Verified in code
Every GitHub webhook is verified with an HMAC-SHA256 signature over the raw body, compared in constant time, and its size is capped before it is read. Aevral acts on installation, repository selection and pull request events. The App also receives issue comment events for the announced review command; the handler ignores them unless that command is switched on, and it ships switched off.
Verified in code
Scans read one archive of your repository at a single fixed commit. Pull request reviews read the diff, plus full files at the head commit for some changed files. Both have size limits. Code is processed in memory on a server in Paris. No customer code is executed, and the model has no tools or shell.
Verified in code
The worker runs in the Deno sandbox with outbound network limited to a list of hosts and environment access. It has no permission to write files, run subprocesses, load native code or read system information, and it loads no code at run time beyond what the image cached when it was built.
Verified in code
Outbound network from the worker is limited to an exact list of hosts in these categories: GitHub, the model providers, the EU database, error monitoring, payments and alerting. A call to any other host is refused by the sandbox.
Verified in code
The worker has no write access to disk at all, not even to a temporary folder. Repository archives are read in memory.
Verified in code
Scans leave out files whose paths look like secrets and redact credential patterns in the code they send. Pull request reviews hold back sensitive files and name them in the Check as not sent. Detection is pattern-based.
Verified in code
Code excerpts in findings are shown in the Aevral console and, when you connect an AI tool through MCP, returned to that tool. Where that tool processes them is set by the tool you choose.
Policy
Aevral data is stored in a Supabase database in the EU (Frankfurt). Row level security is on for every Aevral table exposed through the database API and limits access to members of your organization; internal tables sit in a schema the API does not expose. The worker uses its own database role without row level security bypass, which may only call a fixed list of functions and holds no direct table access, and it refuses to start with any other role's key.
Verified in code
Data is encrypted in transit with TLS and encrypted at rest in the database, as committed in the security measures of the Data Processing Agreement (section 2.3). The worker is served over HTTPS only; plain HTTP is redirected.
Policy
Automatic deletion runs today for these records: findings in the worklist are deleted 24 months after they were last seen, and disconnected AI tool connections are deleted 90 days after they were disconnected.
Verified in code
Customer data is kept while Aevral is installed and for up to 12 months after uninstall, and deleted on request within 30 days. The Data Processing Agreement, section 1.7, is binding.
Policy
Aevral API keys are stored only as SHA-256 hashes and looked up by hash.
Verified in code
An append-only audit log records the scan lifecycle and team changes.
Policy
New capabilities ship switched off: the MCP connection, MCP scans, the review command and EU-only processing are off unless turned on for the running worker. The running worker reports each switch publicly.
Verified in code
The current state of the MCP connection, MCP scans, the review command, standards sync writes and EU-only processing is read from the running worker.
Reported by the running service
When Aevral uses OpenRouter, every request is restricted to a closed list of hosting providers, with data collection denied and zero data retention required. The list is never widened without a sub-processor notice.
Verified in code
Scans and pull request reviews run on GLM-5.3 or GLM-5.3 Flash through OpenRouter, depending on the job and plan, pinned to three hosting providers listed on the Aevral sub-processor page: Together AI (US), Fireworks AI (US) and Inceptron (Sweden). Inceptron does not currently serve these models, so in practice requests are processed in the US. The running worker reports its rail and model ids publicly.
Reported by the running service
Repository content is treated as untrusted data in prompts. Model output is neutralized before it is posted, and every finding must match the code verbatim.
Verified in code
Your code is not used to train models. Each model request asks the provider not to collect or retain data; the account-level setting is attested by the provider.
Policy
No single sign-on (SSO or SAML) for the console yet.
No multi-factor authentication in the Aevral console yet.
No automatic deletion after uninstall yet. Deletion is honored on request.
Scan reports and pull request review records have no automatic time limit yet.
The audit log has no automatic purge yet.
No independent penetration test of Aevral yet.
No certification yet.
EU-only processing is announced, not live.
Secret detection is pattern-based and can miss secrets that do not match a known pattern.
Small team, with documented continuity. Details on request.
Changes we will make, listed before they ship. None of these is live yet.
A pull request that keeps a security standard file in your repository current. Aevral writes only to the branch aevral/standard-sync, never to the default branch, never merges the pull request, and each repository can opt out. The App already holds Contents write for this; until it ships, every token Aevral mints stays capped to Contents read.
Policy · Announced 2026-10-01
Commenting @aevral review on a pull request asks for a full review. The App already holds Issues read and receives issue comment events for this; the command is switched off.
Policy · Announced 2026-10-01
An organization setting, changed only by an owner or admin, to process your code in the EU only. Scans and pull request reviews of that organization started after the change go only to a model provider in the EU. When EU processing is unavailable, jobs wait and retry in the EU for up to 6 hours, then end not reviewed at no charge: a neutral Check on pull requests, a failed scan that is not counted. They never fall back to the US. The setting covers Aevral's own processing; findings returned through an AI tool you connect follow that tool's own processing.
Policy · Announced 2026-10-01
On the EU path, the model is GLM-5.3 served by Mistral in the EU. The EU-only option itself is not live yet.
Policy · Announced 2026-10-01
· 0c47cd225
· 9bf2ea237
· fdf00723b
· 6cdeb1040
Page published from the posture manifest with 23 live statements.
We notify affected customers of a personal data breach within 48 hours of confirming it, as set out in the Data Processing Agreement.
Policy
Aevral is made by Better ISMS EURL. ISO 27001 certification is in progress with Aevral in the intended scope; we are not certified yet and do not have a SOC 2 report.
Policy
Small team, with a documented continuity and backup arrangement. Details on request.
Policy