Aevral docs
Aevral is a security agent for your code: scan the repository, review pull requests, suggested fixes. Open-source models, hosted in the US or the EU.
Aevral is an application security agent from the Better ISMS family. Same jobs as Claude Security and Codex Security:
- Scan the repository. Start with a selected first scan during Setup, press Scan later, or configure recurring scans on a paid scan plan. You get a GitHub Check, a report with evidence, and a suggested fix.
- Review pull requests. Claiming a new organization starts PR reviews on. Setup Complete can turn them off. Free and paid review allowances are separate from scan plans.
- Suggested fixes. Apply them in Claude Code, Cursor, or Codex. Nothing merges without you.
Open-source models, hosted in the US or the EU. That is the brand difference. Not a lab.
Aevral is self-serve: install the GitHub App and log in to the console to claim your install. Complete Setup to connect the install and turn reviews off if you want. Free organizations get two private scans in 14 days; paid organizations use their included scan allowance.
Start here
- Set up with your agent: the setup steps in order, install to first report.
- What a scan looks like: console trigger, GitHub Check, report, suggested fix.
- The findings worklist: remembered findings across scans, human archive, suggested fix on a SHA.
- What a PR review looks like: opt-in PR review, Check plus comments, max two findings, on added lines. Free tier live; paid plans live in the console.
- Pricing and plans: both SKUs, EUR scan ladder and USD PR review add-on.
- Works alongside: SAST, SCA, and general review tools Aevral does not replace. Claude Security and Codex Security are named competitors on aevral.com/compare.
- For AI agents: machine-readable hub.
How Aevral runs
- Open-source models, hosted in the US or the EU. Details on Security and data.
- The GitHub App is public. Install it on any account or organization: https://github.com/apps/aevral.
Questions: contact form. Security and legal corpus: trust center.