Introduction
Aevral: AI code security scanner for repos and PRs.
What is Aevral?
Aevral is a security review tool built as an alternative to Claude Security. It scans an entire repository at rest, reviews every pull request, and creates a Check plus a report with evidence. Rather than acting as a general SAST platform, Aevral concentrates on authorization, IDOR, and business-logic access control flaws. After a finding appears, users can copy a fix prompt into Claude Code, Cursor, or Codex. Aevral does not generate patches today, so the developer remains in control. The product is from ISMS Copilot and uses open-source models hosted in the United States or the EU. It is designed for teams that need a focused repository security scan and pull request review workflow.
Key Features of Aevral
Whole-Repository Security Scanning
Aevral scans the whole repository at rest. Press Scan to get a Check and a report with evidence across files, not just pattern-only matching.
Pull Request Review
Aevral reviews every pull request with a Check and inline comments on added lines. It looks for authorization and business-logic flaws in new code.
Authorization and IDOR Scans
Aevral scans for broken access control, IDOR, and business-logic access control issues. It is not built for memory corruption, injection, or general SAST coverage.
Evidence-Based Findings
Each Aevral finding is a lead with evidence, not a confirmation. The report shows the code, the class, the explanation, and a fix-prompt link.
Fix Prompt Handoff
Aevral hands off a fix prompt to the coding agent already in use, such as Claude Code, Cursor, or Codex. Nothing merges without human review.
Open-Source Model Hosting
Aevral uses open-source models hosted in the United States or the EU. This gives teams a clearer deployment region for security review.
GitHub App Integration
Aevral uses one GitHub App. Claiming a new organization starts PR reviews by default, while installing the App without claiming never authorizes reviews.
Use Cases for Aevral
Whole-Repo Access Control Audit
Aevral is useful for a repository security scan before a release or after a major refactor. It helps surface authorization gaps that may be hard to see file by file.
Pull Request Security Review
Aevral can add a pull request review layer for authorization and business-logic flaws. Inline comments point directly to added lines.
IDOR Scanning for APIs
Aevral can scan API routes for IDOR and broken access control patterns. An example finding shows an order endpoint returning any order by ID without an owner check.
Business-Logic Access Control Checks
Aevral focuses on access control that depends on business rules, not only technical patterns. This helps teams review workflows where permissions may be missing.
AI-Assisted Remediation Workflow
Aevral creates a fix prompt for Claude Code, Cursor, or Codex. Developers can review the finding, decide on the fix, and keep merge control.
How to Use Aevral
- Install the Aevral GitHub App.
- Claim the organization to start pull request reviews by default. Existing opt-outs stay off, and reviews can be disabled at any time.
- Run a whole-repo scan with Aevral to get a Check and a report with evidence.
- Review each finding as a lead, checking the code, class, and explanation.
- Copy the fix prompt into Claude Code, Cursor, or Codex. Aevral does not generate patches today, so the final fix remains a human decision.
Target Audience for Aevral
- Development teams that want a focused AI code security scanner
- Security engineers who review authorization and IDOR issues
- SaaS companies with multi-tenant access control needs
- Platform teams that use Claude Code, Cursor, or Codex
- Engineering leads who want pull request review on every change
- Small teams that prefer per-organization pricing over per-seat pricing
Is Aevral Free?
Aevral does not list a free plan in the reference information. Pricing is per organization and usage, never per seat. The Team plan is €99 per month and includes 4 default-branch scans, then €29 per scan, excluding VAT. Paid PR plans are live in the console. A waitlist is also mentioned for whole-repo scans. For current details, check the official Aevral pricing page.
| Plan | Price | Features |
|---|---|---|
| Team | €99/month | 4 default-branch scans, then €29 per scan; per organization and usage, not per seat |
| PR Review | Paid plans in console | Pull request Checks and inline comments for authorization and business-logic flaws |
| Free | Not listed | No free tier is mentioned; waitlist may be available for scans |
Aevral's Pros and Cons
| Aspect | Pros | Cons |
|---|---|---|
| Pricing | Per organization and usage, not per seat; predictable for teams | €99/month plus €29 per extra scan may be high for individuals; no free tier listed |
| Features | Whole-repo and PR access control scans; evidence-based findings; fix prompt handoff | Focused only on authorization, IDOR, and business-logic; not a general SAST tool |
| Integration | Works with Claude Code, Cursor, and Codex; one GitHub App | Does not generate patches today; findings need human review |
| Hosting | Open-source models hosted in the United States or the EU | Model names and full hosting details are limited in the reference |
| Setup | Live and self-serve; PR review is opt-in and can be disabled | Claiming a new organization starts PR reviews by default, which may surprise some users |
Frequently Asked Questions about Aevral
What is Aevral?
Aevral is an AI code security scanner and pull request review tool. It scans a whole repository, reviews findings with evidence, and hands a fix prompt to Claude Code, Cursor, or Codex.
What types of security issues does Aevral scan for?
Aevral scans for authorization, IDOR, and business-logic access control issues. It does not cover memory corruption, injection, or act as a general SAST platform.
Does Aevral work with Claude Code, Cursor, and Codex?
Yes. Aevral creates a fix prompt that can be copied into Claude Code, Cursor, or Codex. Aevral does not generate patches today, so the coding agent and developer handle the actual fix.
Is Aevral a general SAST tool?
No. Aevral is a focused repository security scan and pull request review tool for access control. It is not positioned as a general SAST solution.
Is Aevral free?
No free plan is listed in the reference information. Aevral uses per-organization and usage pricing, with a Team plan at €99 per month that includes 4 default-branch scans, then €29 per scan, excluding VAT.
Is PR review enabled by default?
Claiming a new organization starts PR reviews by default, similar to Setup. Installing the App without claiming never authorizes reviews. Setup Complete can turn them off, existing opt-outs stay off, and reviews can be disabled at any time.
Does Aevral automatically fix code?
No. Aevral provides a finding, evidence, and a fix prompt. The user still decides what to change, and nothing merges without human review.
Aevral Tags
Aevral, AI code security scanner, repository security scan, pull request review, authorization scan, IDOR scanner, broken access control, business-logic security, Claude Code security, Cursor security, Codex security, open-source security models, fix prompt, GitHub App security





