Buying Aevral from the US.

Aevral is built by a French company, and it is sold to US teams. If your purchase process asks who the vendor is, who holds your data, or how US state privacy laws apply, this page gathers the answers. Every item links to its source, so your legal review does not wait on a call with us.

The three questions that stall a purchase

A security tool bought by a US company gets the same three questions whether the vendor sits in San Francisco or Paris: who exactly am I contracting with, where does our code and our people's data go, and which clauses does my lawyer point at. The difference is that a foreign vendor triggers a short extra check that most US teams have done before.

None of it needs a demo. The contract is click-accepted when you install the GitHub App, and each item below links to where it lives; the security questionnaire comes on request.

Who you are buying from

  • The vendor is Better ISMS EURL, a French company based in Paris, also behind ISMS Copilot and heyGRC. The legal notice has the registration details.
  • Everything is self-serve and in English: install the GitHub App, sign in to the console, pick a plan. Pull request review is billed in US dollars and whole-repo scans in euros, both per organization per month, and all prices exclude VAT and other taxes.
  • Installing the GitHub App accepts the Terms and the Data Processing Agreement for your organization, so the data-protection paperwork is in place before the first pull request is reviewed.

The paperwork your process asks for

Data Processing Agreement

The DPA covers Aevral in section 1.7. It carries the Standard Contractual Clauses for international transfers and section 10, United States State Privacy Laws, with the service-provider terms US buyers' lawyers look for.

Read the DPA
Sub-processor list

The current Aevral sub-processor list and its change-notification process. Where your data is stored and processed lives on that list, not on this page.

Sub-processor list
Privacy policy

Covers your team's account data across Better ISMS products, including a California Privacy Rights section (CCPA/CPRA) and the equivalent for other US state privacy laws.

Privacy policy
Security page

What Aevral can and cannot do today, in its own words: what is live, what is announced, and what does not exist yet. No marketing version, the same page your engineers will read.

Security page
Security questionnaire

A security questionnaire in the CAIQ and SIG Lite format, available on request for your vendor review at contact@ismscopilot.com.

Request it
Vulnerability disclosure

A public disclosure policy and a security.txt file, so your security team knows where responsible disclosure goes.

Disclosure policy
Service status

A live status page your on-call team can watch.

Status page

California and other US state privacy laws

For the repositories and content your organization authorizes Aevral to process, Better ISMS acts as a service provider under the CCPA/CPRA (California) and as a processor under the comparable laws of other US states. That means: processing only on your documented instructions, no sale or sharing of personal information, no use of your content for any purpose other than providing the service, including no development, training or improvement of AI models.

Because there is no sale or sharing, no opt-out signal changes anything about the processing. Your team's own account data is covered by the privacy policy, which extends California rights to account holders regardless of legal thresholds. The binding clauses are DPA section 10 (United States State Privacy Laws) and section 1.7 (Aevral).

What we do not have

  • No SOC 2 report exists today, and none is claimed. If your process requires one, Aevral is not the right tool yet.
  • No ISO 27001 certificate exists yet: certification is in progress, with Aevral in the intended scope, and the company says plainly it is not certified. The audit-evidence page shows what you can already show an ISO auditor from Aevral's review records.
  • No SSO and no demos today. If your buying process cannot start without a demo call, Aevral will feel slow. What exists is the paperwork above, the Enterprise plan with its custom DPA, a countersigned DPA copy on request, and email.

If something is missing

If your review needs something not on this page, ask. A custom DPA is available on the Enterprise plan, and the security questionnaire is available on request.

DPASub-processorsPrivacy policyTermsSecurity pageAudit evidencePricingContact form


Security review, handled.

One GitHub App. Reviews start when the App is installed. A Check on each pull request it reviews, with inline comments when there is a grounded finding. Free tier live: public repos free, 500/org/month, 25 private reviews a month. Paid plans are live in the console.

Install the GitHub AppLog inSign up

For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.